LOLBAS
LOLBAS copied to clipboard
Add tag to INetCache downloaders
A significant number of download LOLBAS entries will download the payload to a random folder under %LOCALAPPDATA%\Microsoft\Windows\INetCache
. Because the location is hard (if not impossible) to predict, obtaining the payload requires extra steps, such as iterating the contents of this folder, and possibly renaming or moving the payload to a more persistent folder. As such, these downloaders are generally less convenient in use and inferior to other downloaders (e.g. certutil
).
The tagging or otherwise marking LOLBAS downloader entries that rely on INetCache should be considered, so that it is clearer how the downloaders work, and so they can be filtered on.