LOLBAS icon indicating copy to clipboard operation
LOLBAS copied to clipboard

Add slui.yml, fodhelper.yml, regedit.yml

Open havoc3-3 opened this issue 1 year ago • 1 comments

Similar to my past submission (ComputerDefaults), hijacking the registry key "HKEY_CURRENT_USER\Software\Classes\exefile" allows the proxied execution of scripts/binaries via these three native binaries (slui, fodhelper, regedit).

image

havoc3-3 avatar Sep 26 '24 21:09 havoc3-3

Looks like all 3 use ms-settings\shell\open\command and exefile\shell\open\command, probably depends on the version of Windows. https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_event/registry_event_shell_open_keys_manipulation.yml

tyler-mcadam avatar Nov 04 '24 18:11 tyler-mcadam