mirror of
https://github.com/nganhkhoa/malware.git
synced 2024-06-10 21:32:07 +07:00
Update malware-tech_ref_and_memo.md
This commit is contained in:
parent
793fe8f96b
commit
6a69893760
@ -224,9 +224,7 @@ New-Object System.IO.Compression.DeflateStream([iO.mEmoRySTream] [sysTEM.ConVert
|
|||||||
- UAC Bypass,AppLocker Bypass,Dumping process memory,Credential theft,Log evasion/modification,Persistence,File operations,etc.
|
- UAC Bypass,AppLocker Bypass,Dumping process memory,Credential theft,Log evasion/modification,Persistence,File operations,etc.
|
||||||
- よく利用されるLOLBins
|
- よく利用されるLOLBins
|
||||||
- [Certutil.exe](https://lolbas-project.github.io/lolbas/Binaries/Certutil/)
|
- [Certutil.exe](https://lolbas-project.github.io/lolbas/Binaries/Certutil/)
|
||||||
- エンコードされたバイナリを,Certutil.exeでダウンロード
|
- エンコードされたバイナリを,Certutil.exeでダウンロード->ダウンロードしたバイナリを,Certutil.exeでデコード->デコードしたバイナリを,[Forfiles.exe](https://lolbas-project.github.io/lolbas/Binaries/Forfiles/)で実行
|
||||||
- ダウンロードしたバイナリを,Certutil.exeでデコード
|
|
||||||
- デコードしたバイナリを,Forfiles.exeで実行
|
|
||||||
- [eventvwr.exe](https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/)
|
- [eventvwr.exe](https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/)
|
||||||
- [Msbuild.exe](https://lolbas-project.github.io/lolbas/Binaries/Msbuild/)
|
- [Msbuild.exe](https://lolbas-project.github.io/lolbas/Binaries/Msbuild/)
|
||||||
- [Mshta.exe](https://lolbas-project.github.io/lolbas/Binaries/Mshta/)
|
- [Mshta.exe](https://lolbas-project.github.io/lolbas/Binaries/Mshta/)
|
||||||
|
Loading…
Reference in New Issue
Block a user