LOLBAS icon indicating copy to clipboard operation
LOLBAS copied to clipboard

Add tag to INetCache downloaders

Open wietze opened this issue 1 year ago • 0 comments

A significant number of download LOLBAS entries will download the payload to a random folder under %LOCALAPPDATA%\Microsoft\Windows\INetCache. Because the location is hard (if not impossible) to predict, obtaining the payload requires extra steps, such as iterating the contents of this folder, and possibly renaming or moving the payload to a more persistent folder. As such, these downloaders are generally less convenient in use and inferior to other downloaders (e.g. certutil).

The tagging or otherwise marking LOLBAS downloader entries that rely on INetCache should be considered, so that it is clearer how the downloaders work, and so they can be filtered on.

wietze avatar Aug 05 '23 14:08 wietze