LOLBAS
LOLBAS copied to clipboard
Update Tar.yml
Hello I wanted to make this but then I saw it was already made so I added some updates to it hope it helps
I can also change the file example to a file with zip or office extension as its important and not mentioned that tar can do this on windows.
The reason I want this to be added is because I have seen malware being delivered via MS docs and the Macro calls tar to extract the tools inside the file it self by unzipping it and then running it
@Avesta-FA, @wietze and @LOLBAS-Project/lolbas-team this one may be useful if it's changed to an ADS ability. Compressing and extracting files isn't special on it's own but the ability to do that with ADS is. I have tested this on Win 10 22H2.
My recommendation would be to change this up to an ADS ability and proceed if others agree to merge.
That's also nice, the top section aside I would really appreciate if everyone could also use lines 28-34 because the documents do not tell you that tar on windows also can handle zip files.
My recommendation would be to change this up to an ADS ability and proceed if others agree to merge.
Sounds good @xenoscr, I agree with your assessment.
Agree with your assessment as well @xenoscr
Hello Folks, @api0cradle @wietze
Sorry for the delay, I made the changes to show it can be used for zip files and office documents and it can be used for alternative data streams