Skip to content

Commit

Permalink
7 new dlls, x64 tested only (wietze#50)
Browse files Browse the repository at this point in the history
Co-authored-by: Gary Lobermier <[email protected]>
Co-authored-by: Wietze <[email protected]>
  • Loading branch information
3 people authored May 31, 2023
1 parent c0fc1f9 commit 99ec39c
Show file tree
Hide file tree
Showing 7 changed files with 116 additions and 0 deletions.
18 changes: 18 additions & 0 deletions yml/microsoft/built-in/dbgmodel.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
Name: dbgmodel.dll
Author: Gary Lobermier
Created: 2023-05-22
Vendor: Microsoft
ExpectedLocations:
- '%SYSTEM32%'
- '%SYSWOW64%'
- '%PROGRAMFILES%\Windows Kits\10\Debuggers\%VERSION%'
ExpectedSignatureInformation:
- Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Issuer: CN=Microsoft Windows Production PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Type: Catalog
VulnerableExecutables:
- Path: '%PROGRAMFILES%\Windows Kits\10\Debuggers\%VERSION%\ntsd.exe'
Type: Sideloading
Resources:
- https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
19 changes: 19 additions & 0 deletions yml/microsoft/built-in/textshaping.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
Name: textshaping.dll
Author: Gary Lobermier
Created: 2023-05-22
Vendor: Microsoft
ExpectedLocations:
- '%SYSTEM32%'
- '%SYSWOW64%'
ExpectedSignatureInformation:
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Type: Catalog
VulnerableExecutables:
- Path: '%PROGRAMFILES%\Windows Kits\10\Debuggers\x64\logger.exe'
Type: Sideloading
- Path: '%PROGRAMFILES%\Windows Kits\10\Debuggers\x64\logviewer.exe'
Type: Sideloading
Resources:
- https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
13 changes: 13 additions & 0 deletions yml/microsoft/built-in/wsdapi.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
Name: wsdapi.dll
Author: Gary Lobermier
Created: 2023-05-22
Vendor: Microsoft
ExpectedLocations:
- '%SYSTEM32%'
- '%SYSWOW64%'
VulnerableExecutables:
- Path: '%PROGRAMFILES%\Windows Kits\10\bin\%VERSION%\x64\wsddebug_host.exe'
Type: Sideloading
Resources:
- https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
17 changes: 17 additions & 0 deletions yml/microsoft/external/gflagsui.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
Name: gflagsui.dll
Author: Gary Lobermier
Created: 2023-05-22
Vendor: Microsoft
ExpectedLocations:
- '%PROGRAMFILES%\Windows Kits\10\Debuggers\%VERSION%'
ExpectedSignatureInformation:
- Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Issuer: CN=Microsoft Windows Production PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Type: Catalog
VulnerableExecutables:
- Path: '%PROGRAMFILES%\Windows Kits\10\Debuggers\%VERSION%\gflags.exe'
Type: Sideloading
AutoElevate: true
Resources:
- https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
16 changes: 16 additions & 0 deletions yml/microsoft/external/rcdll.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
Name: rcdll.dll
Author: Gary Lobermier
Created: 2023-05-22
Vendor: Microsoft
ExpectedLocations:
- '%PROGRAMFILES%\Windows Kits\10\bin\%VERSION%\%VERSION%'
ExpectedSignatureInformation:
- Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Issuer: CN=Microsoft Windows Production PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Type: Catalog
VulnerableExecutables:
- Path: '%PROGRAMFILES%\Windows Kits\10\bin\%VERSION%\%VERSION%\rc.exe'
Type: Sideloading
Resources:
- https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
16 changes: 16 additions & 0 deletions yml/microsoft/external/symsrv.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
Name: symsrv.dll
Author: Gary Lobermier
Created: 2023-05-22
Vendor: Microsoft
ExpectedLocations:
- '%PROGRAMFILES%\Windows Kits\10\Debuggers\%VERSION%'
ExpectedSignatureInformation:
- Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Issuer: CN=Microsoft Windows Production PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Type: Catalog
VulnerableExecutables:
- Path: '%PROGRAMFILES%\Windows Kits\10\Debuggers\%VERSION%\symstore.exe'
Type: Sideloading
Resources:
- https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
17 changes: 17 additions & 0 deletions yml/microsoft/external/windowsperformancerecorderui.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
Name: windowsperformancerecorderui.dll
Author: Gary Lobermier
Created: 2023-05-22
Vendor: Microsoft
ExpectedLocations:
- '%PROGRAMFILES%\Windows Kits\10\Windows Performance Toolkit'
ExpectedSignatureInformation:
- Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Issuer: CN=Microsoft Windows Production PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Type: Catalog
VulnerableExecutables:
- Path: '%PROGRAMFILES%\Windows Kits\10\Windows Performance Toolkit\WPRUI.exe'
Type: Sideloading
AutoElevate: true
Resources:
- https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/

0 comments on commit 99ec39c

Please sign in to comment.