Remove dist directory from tracking

This commit is contained in:
Bhavin Patel
2024-07-02 11:47:20 -07:00
parent f383de0f99
commit 168cc2ef34
223 changed files with 0 additions and 214191 deletions
-7
View File
@@ -1,7 +0,0 @@
# Splunk ES Content Update
This subscription service delivers pre-packaged Security Content for use with Splunk Enterprise Security. Subscribers get regular updates to help security practitioners more quickly address ongoing and time-sensitive customer problems and threats.
Requires Splunk Enterprise Security version 4.5 or greater.
For more information please visit the [Splunk ES Content Update user documentation](https://docs.splunk.com/Documentation/ESSOC).
-15
View File
@@ -1,15 +0,0 @@
The Analytic Story Details dashboard renders all the details of the content related to a specific analytic story which
can be chose via the drop down
Each analytic story has attributes associated with it and the following:
______________________________________________________________________
Analytic Story: name of the analytic story
Description ; description of the analytic story
Search Name : The name of the searches belonging to the chosen analytic story
Search : The search query which looks for an attack pattern corresponding to the analytic story
Search Description: The description of the search query
Asset Type: The analytic story specifies what asset in the infrastructure may be compromised
Category: The category that the search belongs to (malware, vulnerabilities, best practices, abuse)
Kill Chain Phase: The kill chain phase of the attack that the search is after.
-24
View File
@@ -1,24 +0,0 @@
The ES_SOC Summary Dashboard provides you a summarized view of the analytic story contents of the ES-SOC app.
The dashboard has the following panels gives you following details
1) Analytic story Summary
- Total Analytic Stories : The total number of Analytic stories in the ES-SOC application
- Total Searches: The total number of searches in ES-SOC
- Searches added last week: Number of searches added to ES-SOC in the last week.
2) Analytic story Category: This dashboard panel summarizes the categories of the searches that the ES-SOC app contains. The categories of the analytic stories are as follow
-Malware: These searches detect specific malware behavior for a particular phase of the attack kill chain. E.g. a malwares delivery method via email or a malwares installation behavior via registry key changes
-Vulnerability: These searches detect behavior or a signature of a vulnerable software in use. These searches are not designed to replace vulnerability management or scanning systems. The purpose of these searches is to discover a vulnerability through side effects or behaviors.
-Abuse: Some actions can be deemed malicious because they are unexpected, violate corporate policy or are significantly different than the actions of other users. E.g. A USB disk that is seen on multiple systems or a user that uploads excessive files to a cloud service or a database query that dumps an entire table
-Best Practices: Searches that correspond to specific guidelines from organizations like SANS or OWASP
3) Kill Chain phases: Every analytic story has one or more searches which look for a certain kind of attack pattern/behavior. These searches have an attribute which essentially tells you what Kill chain phase does the search correspond to.
The numbers on the dashboard represents the number of searches correponding to each kill chain phase
4) Analytic story table: This table gives the user a comprehensive view of some of the details of the analytic story. Some of the listed attributes are:
- Analytic Story : The name of the analytic story
- Description: The description of the analyttic story
- Search names: The name of the searches in each analytic story
- Datamodels: The name of the datamodel that the search is querying against.
- Technology Examples: This field represent some examples related to the technologies required to populate the datamodels(Nessues, Cisco Firewall,etc)
- Kill chain phase: The name of the kill chain phase that the search belongs to
@@ -1,51 +0,0 @@
######################
ESSOC Usage Dashboard#
######################
The ESSOC Usage dashboard is designed to provide high-level insight into the usage of the ES-SOC app. It is suitable for display when providing feedback to the Splunk team or for identifying how the ES-SOC app is being used. This dashboard has two time selectors that work independently - the top time selector determines the search time range for all the single-value. And the lower time selector, determines the time range for the usage table.
IMPORTANT: The user loading this dashboard must have permission to search the _audit index
##################
#Dashboard panels#
##################
Searches Ran
The total number of searches in ES-SOC that were executed. This number includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> syntax
Unique Searches
The unique/distinct searches executed on the deployment. This is equivalent to the distinct count of searches run in the ES-SOC app.
Most Run
The total number of searches in ES-SOC that were executed. This number includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> syntax.
Ad hoc Searches
The total number of searches run from the search bar using the '| savedsearch <ESSOC search_name> syntax.
Scheduled
The total number of ESSOC searches run that were scheduled.
Most Active User
The user who executed the highest number/count of searches. This calculation includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> syntax.
Search Run Time (seconds)
Total run time of all searches executed in seconds. This calculation includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> syntax.
Average Run Time (seconds)
Average run time of all searches executed in seconds. This calculation includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> syntax.
Max Run Time (seconds)
The run time of the longest running search. This calculation includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> syntax.
Search summary
This table provides details on each search that was executed in the ESSOC app.
-46
View File
@@ -1,46 +0,0 @@
{
"schemaVersion": "1.0.0",
"info": {
"title": "ES Content Updates",
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "4.35.0"
},
"author": [
{
"name": "Splunk Threat Research Team",
"email": "research@splunk.com",
"company": "Splunk"
}
],
"releaseDate": "2024-07-01",
"description": "Explore the Analytic Stories included with ES Content Updates.",
"classification": {
"intendedAudience": null,
"categories": [],
"developmentStatus": null
},
"commonInformationModels": null,
"license": {
"name": null,
"text": null,
"uri": null
},
"privacyPolicy": {
"name": null,
"text": null,
"uri": null
},
"releaseNotes": {
"name": null,
"text": "./README.md",
"uri": null
}
},
"dependencies": null,
"tasks": null,
"inputGroups": null,
"incompatibleApps": null,
"platformRequirements": null
}
@@ -1,2 +0,0 @@
### Deprecated since ESCU UI was deprecated and this conf file is no longer in use
### Using one single file analyticstories.conf that will be used both by ES and ESCU
File diff suppressed because one or more lines are too long
-41
View File
@@ -1,41 +0,0 @@
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
## Splunk app configuration file
[install]
is_configured = false
state = enabled
state_change_requires_restart = false
build = 20240701174052
[triggers]
reload.analytic_stories = simple
reload.usage_searches = simple
reload.use_case_library = simple
reload.correlationsearches = simple
reload.analyticstories = simple
reload.governance = simple
reload.managed_configurations = simple
reload.postprocess = simple
reload.content-version = simple
reload.es_investigations = simple
[launcher]
author = Splunk
version = 4.35.0
description = Explore the Analytic Stories included with ES Content Updates.
[ui]
is_visible = true
label = ES Content Updates
[package]
id = DA-ESS-ContentUpdate
-100
View File
@@ -1,100 +0,0 @@
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
[api_call_by_user_baseline]
enforceTypes = false
replicate = false
[cloud_instances_enough_data]
enforceTypes = false
replicate = false
[k8s_container_network_io_baseline]
enforceTypes = false
replicate = false
[k8s_container_network_io_ratio_baseline]
enforceTypes = false
replicate = false
[k8s_process_resource_baseline]
enforceTypes = false
replicate = false
[k8s_process_resource_ratio_baseline]
enforceTypes = false
replicate = false
[previously_seen_api_calls_from_user_roles]
enforceTypes = false
replicate = false
[previously_seen_aws_cross_account_activity]
enforceTypes = false
replicate = false
[previously_seen_aws_regions]
enforceTypes = false
replicate = false
[previously_seen_cloud_api_calls_per_user_role]
enforceTypes = false
replicate = false
[previously_seen_cloud_compute_creations_by_user]
enforceTypes = false
replicate = false
[previously_seen_cloud_compute_images]
enforceTypes = false
replicate = false
[previously_seen_cloud_compute_instance_types]
enforceTypes = false
replicate = false
[previously_seen_cloud_instance_modifications_by_user]
enforceTypes = false
replicate = false
[previously_seen_cloud_provisioning_activity_sources]
enforceTypes = false
replicate = false
[previously_seen_cloud_regions]
enforceTypes = false
replicate = false
[previously_seen_gcp_storage_access_from_remote_ip]
enforceTypes = false
replicate = false
[previously_seen_running_windows_services]
enforceTypes = false
replicate = false
[previously_seen_S3_access_from_remote_ip]
enforceTypes = false
replicate = false
[previously_seen_users_console_logins]
enforceTypes = false
replicate = false
[s3_deletion_baseline]
enforceTypes = false
replicate = false
[security_group_activity_baseline]
enforceTypes = false
replicate = false
[zoom_first_time_child_process]
enforceTypes = false
replicate = false
-11
View File
@@ -1,11 +0,0 @@
# deprecated please see gist: https://gist.github.com/d1vious/c4c2aae7fa7d5cbb1f24adc5f6303ac1
#[dnstwist]
#filename = dnstwist.py
#chunked = true
# run story functionality has been moved to: https://github.com/splunk/analytic_story_execution'
# [runstory]
# filename = runstory.py
# chunked = true
# is_risky = true
@@ -1,9 +0,0 @@
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
[content-version]
version = 4.35.0
@@ -1,7 +0,0 @@
<nav search_view="search" color="#65A637">
<view name="escu_summary" default="true"/>
<view name="feedback"/>
<view name="search"/>
<view name="dashboards"/>
<a href="http://docs.splunk.com/Documentation/ESSOC">Docs</a>
</nav>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| search `netbackup` dest=$dest$</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`aws_cloudwatchlogs_eks` |rename sourceIPs{} as src_ip |search src_ip=$src_ip$ | stats count min(_time) as firstTime max(_time) as lastTime values(user.username) values(requestURI) values(verb) values(userAgent) by source annotations.authorization.k8s.io/decision src_ip</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`aws_securityhub_firehose` "findings{}.Resources{}.Type"=AWSEC2Instance | rex field=findings{}.Resources{}.Id .*instance/(?&lt;instance&gt;.*)| rename instance as dest| search dest = $dest$ |rename findings{}.* as * | rename Remediation.Recommendation.Text as Remediation | table dest Title ProductArn Description FirstObservedAt RecordState Remediation</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`cloudtrail` | rename userIdentity.accessKeyId as accessKeyId| search accessKeyId=$accessKeyId$ | spath output=user path=userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, awsRegion, eventName, errorCode, errorMessage</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`cloudtrail` | search user=$user$| table _time userIdentity.type userIdentity.userName userIdentity.arn aws_account_id src awsRegion eventName eventType</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`aws_description` | rename id as networkAclId | search networkAclId=$networkAclId$ | table id account_id vpc_id network_acl_entries{}.*</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`aws_config` resourceId=$resourceId$ | table _time ARN relationships{}.resourceType relationships{}.name relationships{}.resourceId configuration.privateIpAddresses{}.privateIpAddress configuration.privateIpAddresses{}.association.publicIp</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`aws_config` | rename resourceId as bucketName |search bucketName=$bucketName$ | table resourceCreationTime bucketName vendor_region action aws_account_id supplementaryConfiguration.AccessControlList</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`google_gcp_pubsub_message` | rename data.protoPayload.requestMetadata.callerIp as src_ip | search src_ip =$src_ip$ | stats count min(_time) as firstTime max(_time) as lastTime values(data.protoPayload.methodName) as method_names values(data.protoPayload.resourceName) as resource_name values(data.protoPayload.requestMetadata.callerSuppliedUserAgent) as http_user_agent values(data.protoPayload.authenticationInfo.principalEmail) as user values(data.protoPayload.status.message) by src_ip data.resource.labels.cluster_name data.resource.type</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`cloudtrail` | iplocation sourceIPAddress | search City=$City$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, City, user, userName, userType, src_ip, awsRegion, eventName, errorCode</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`cloudtrail` | iplocation sourceIPAddress | search Country=$Country$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, Country, user, userName, userType, src_ip, awsRegion, eventName, errorCode</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`cloudtrail` | iplocation sourceIPAddress | search src_ip=$src_ip$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, user, userName, userType, src_ip, awsRegion, eventName, errorCode</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`cloudtrail` | iplocation sourceIPAddress | search Region=$Region$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, Region, user, userName, userType, src_ip, awsRegion, eventName, errorCode</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`netbackup` COMPUTERNAME=$dest$ | rename COMPUTERNAME as dest, MESSAGE as signature | table _time, dest, signature</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Certificates.All_Certificates where All_Certificates.SSL.ssl_subject_common_name=*$domain$ by All_Certificates.dest All_Certificates.src All_Certificates.SSL.ssl_issuer_common_name All_Certificates.SSL.ssl_subject_common_name All_Certificates.SSL.ssl_hash | `drop_dm_object_name(All_Certificates)` | `drop_dm_object_name(SSL)` | rename ssl_subject_common_name as domain | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| search tag=dns src_ip=$src_ip$ dest_port=53 | streamstats time_window=1d count values(dest_ip) as dcip by src_ip | table date_mday src_ip dcip count | sort -count</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats allow_old_summaries=true sum(All_Traffic.bytes_out) as "bytes_out" sum(All_Traffic.bytes_in) as "bytes_in" from datamodel=Network_Traffic where nodename=All_Traffic All_Traffic.dest_port=53 by All_Traffic.src All_Traffic.dest| `drop_dm_object_name(All_Traffic)` | rename src as src_ip | rename dest as dest_ip | search src_ip=$src_ip$ | search dest_ip = $dest_ip | eval ratio = (bytes_out/bytes_in) | table ratio</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`aws_description` | dedup id sortby -_time |rename id as instanceId| search instanceId=$instanceId$ | spath output=tags path=tags | eval tags=mvzip(key,value," = "), ip_address=if((ip_address == "null"),private_ip_address,ip_address) | table id, tags.Name, aws_account_id, placement, instance_type, key_name, ip_address, launch_time, state, vpc_id, subnet_id, tags | rename aws_account_id as "Account ID", id as ID, instance_type as Type, ip_address as "IP Address", key_name as "Key Pair", launch_time as "Launch Time", placement as "Availability Zone", state as State, subnet_id as Subnet, "tags.Name" as Name, vpc_id as VPC</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`cloudtrail` dest=$dest$ |rename userIdentity.arn as arn, responseElements.instancesSet.items{}.instanceId as dest, responseElements.instancesSet.items{}.privateIpAddress as privateIpAddress, responseElements.instancesSet.items{}.imageId as amiID, responseElements.instancesSet.items{}.architecture as architecture, responseElements.instancesSet.items{}.keyName as keyName | table arn, awsRegion, dest, architecture, privateIpAddress, amiID, keyName</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| from datamodel Email.All_Email | search message_id=$message_id$</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| from datamodel Email.All_Email | search src_user=$src_user$</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Sessions where nodename=All_Sessions.DHCP All_Sessions.signature=DHCPREQUEST All_Sessions.src_mac= $src_mac$ by All_Sessions.src_ip All_Sessions.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>|tstats `security_content_summariesonly` values(All_Email.dest) as dest values(All_Email.recipient) as recepient min(_time) as firstTime max(_time) as lastTime count from datamodel=Email.All_Email by All_Email.src |`drop_dm_object_name(All_Email)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search src=$src$</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`wineventlog_security` (signature_id=4718 OR signature_id=4717) dest=$dest$ | rename user as "Account Modified" | table _time, dest, "Account Modified", Access_Right, signature</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`wineventlog_security` (signature_id=4718 OR signature_id=4717) user=$user$ | rename user as "Account Modified" | table _time, dest, "Account Modified", Access_Right, signature</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| search `notable` | search dest=$dest$ | table _time, dest, rule_name, owner, priority, severity, status_description</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name("Processes")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats `security_content_summariesonly` values(Filesystem.file_name) as file_name values(Filesystem.dest) as dest, values(Filesystem.process_name) as process_name from datamodel=Endpoint.Filesystem by Filesystem.dest Filesystem.process_name Filesystem.file_path, Filesystem.action, _time | `drop_dm_object_name(Filesystem)` | search dest=$dest$ | search process_name=$process_name$ | table _time, process_name, dest, action, file_name, file_path</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name("Processes")` | search process_name= $process_name$ | search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats `security_content_summariesonly` count min(_time) max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.process_name Processes.user Processes.dest Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search dest=$dest$ | join dest type=inner [| tstats `security_content_summariesonly` count from datamodel=Endpoint.Ports by Ports.process_id Ports.src Ports.dest_port | `drop_dm_object_name(Ports)` | search dest_port=$dest_port$ | rename src as dest]</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats `security_content_summariesonly` count min(_time) max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.parent_process Processes.process_name Processes.user Processes.dest Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search dest = $dest$ | join dest type=inner [| tstats `security_content_summariesonly` count from datamodel=Endpoint.Ports where Ports.dest_port=53 by Ports.process_id Ports.src | `drop_dm_object_name(Ports)` | rename src as dest]</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`sysmon` EventCode&gt;18 EventCode&lt;22 | rename host as dest | search dest=$dest$| table _time, dest, user, Name, Operation, EventType, Type, Query, Consumer, Filter</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`stream_http` session_id = $session_id$ | stats values(url) values(http_user_agent) by src_ip status</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`cloudtrail` vendor_region=$vendor_region$| rename requestParameters.instancesSet.items{}.instanceId as instanceId | stats values(eventName) by user instanceId vendor_region</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`cloudtrail` user=$user$ | table _time userIdentity.type userIdentity.userName userIdentity.arn aws_account_id src awsRegion eventName eventType </query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats count `security_content_summariesonly` earliest(_time) as first_login latest(_time) as last_login dc(Authentication.dest) AS distinct_count_dest values(Authentication.dest) AS Authentication.dest values(Authentication.app) AS Authentication.app from datamodel=Authentication where Authentication.action=failure by Authentication.user | where distinct_count_dest &gt; 1 | `security_content_ctime(first_login)` | `security_content_ctime(last_login)` | `drop_dm_object_name("Authentication")` | search user=$user$</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| from datamodel Network_Traffic.All_Traffic | search src_ip=$src_ip$</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`okta` app=$app$ | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city | table _time, user, displayMessage, app, src_ip, state, city, result, outcome.reason</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`wineventlog_security` EventCode=4624 Logon_Type=9 AuthenticationPackageName=Negotiate | stats count earliest(_time) as first_login latest(_time) as last_login by src_user dest | `security_content_ctime(first_login)` | `security_content_ctime(last_login)` | search dest=$dest$</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`wineventlog_security` EventCode=4768 OR EventCode=4769 | rex field=user "(?&lt;new_user&gt;[^\@]+)" | stats count BY new_user, dest, EventCode | stats max(count) AS max_count sum(count) AS sum_count BY new_user, dest| search dest=$dest$ | where sum_count/max_count!=2 | rename new_user AS user </query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats count `security_content_summariesonly` earliest(_time) as first_login latest(_time) as last_login values(Authentication.dest) AS Authentication.dest values(Authentication.app) AS Authentication.app values(Authentication.action) AS Authentication.action from datamodel=Authentication where Authentication.action=success by _time, Authentication.user | bucket _time span=30d | stats count min(first_login) as first_login max(last_login) as last_login values(Authentication.dest) AS Authentication.dest by Authentication.user | where count=1 | where first_login &gt;= relative_time(now(), "-30d") | `security_content_ctime(first_login)` | `security_content_ctime(last_login)` | `drop_dm_object_name("Authentication")` | search dest=$dest$</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication where Authentication.signature_id=4624 Authentication.app=win:remote by Authentication.src Authentication.dest Authentication.app Authentication.user Authentication.signature Authentication.src_nt_domain | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name("Authentication")` | search dest=$dest$ | table firstTime lastTime src src_nt_domain dest user app count | sort count</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`stream_http` | search src_ip=$src_ip$ | search dest_ip=$dest_ip$ | eval cs_content_type_length = len(cs_content_type) | search cs_content_type_length &gt; 100 | rex field="cs_content_type" (?&lt;suspicious_strings&gt;cmd.exe) | eval suspicious_strings_found=if(match(cs_content_type, "application"), "True", "False") | rename suspicious_strings_found AS "Suspicious Content-Type Found" | fields "Suspicious Content-Type Found", dest_ip, src_ip, suspicious_strings, cs_content_type, cs_content_type_length, url</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>`okta` user=$user$ | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city | table _time, user, displayMessage, app, src_ip, state, city, result, outcome.reason</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,18 +0,0 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
<query>| tstats `security_content_summariesonly` values(Web.url) as url from datamodel=Web by Web.src,Web.http_user_agent,Web.http_method | `drop_dm_object_name("Web")`| search http_method, "POST" | search src=$src$</query>
</search>
<option name="drilldown">cell</option>
<option name="wrap">false</option>
</table>
</panel>
@@ -1,401 +0,0 @@
<dashboard version="2" theme="light">
<label>ESCU - AppLocker</label>
<description></description>
<definition><![CDATA[
{
"dataSources": {
"ds_search_1_new_new": {
"type": "ds.search",
"options": {
"query": "`applocker` \n| spath input=UserData_Xml path=RuleAndFileData.PolicyName output=PolicyName\n| spath input=UserData_Xml path=RuleAndFileData.RuleId output=RuleId\n| spath input=UserData_Xml path=RuleAndFileData.RuleName output=RuleName\n| spath input=UserData_Xml path=RuleAndFileData.RuleSddl output=RuleSddl\n| spath input=UserData_Xml path=RuleAndFileData.TargetUser output=TargetUser\n| spath input=UserData_Xml path=RuleAndFileData.TargetProcessId output=TargetProcessId\n| spath input=UserData_Xml path=RuleAndFileData.FilePath output=FilePath\n| spath input=UserData_Xml path=RuleAndFileData.Fqbn output=Fqbn\n| spath input=UserData_Xml path=RuleAndFileData.TargetLogonId output=TargetLogonId\n| spath input=UserData_Xml path=RuleAndFileData.FullFilePath output=FullFilePath\n| search PolicyName=*\n| table PolicyName, RuleId, RuleName, RuleSddl, TargetUser, TargetProcessId, FilePath, Fqbn, TargetLogonId, FullFilePath _time",
"queryParameters": {
"earliest": "$global_time.earliest$",
"latest": "$global_time.latest$"
}
}
},
"ds_search_1_new": {
"type": "ds.search",
"options": {
"query": "`applocker`\n\n| eval EventType=case(\n EventCode==8000, \"PolicyApplicationFailure\",\n EventCode==8001, \"PolicyApplicationSuccess\",\n EventCode==8002, \"AllowedFileExecution\",\n EventCode==8003, \"AuditedFileExecution\",\n EventCode==8004, \"BlockedFileExecution\",\n EventCode==8005, \"AllowedScriptOrMSIExecution\",\n EventCode==8006, \"AuditedScriptOrMSIExecution\",\n EventCode==8007, \"BlockedScriptOrMSIExecution\",\n EventCode==8020, \"AllowedPackagedApp\",\n EventCode==8021, \"AuditedPackagedApp\",\n EventCode==8022, \"DisabledPackagedApp\",\n EventCode==8023, \"AllowedPackagedAppInstallation\",\n EventCode==8024, \"AuditedPackagedAppInstallation\",\n EventCode==8025, \"DisabledPackagedAppInstallation\",\n EventCode==8027, \"NoPackagedAppRule\"\n)\n| table _time, host, EventCode, EventType\n| stats values(EventType) values(EventCode) count by host",
"queryParameters": {
"earliest": "$global_time.earliest$",
"latest": "$global_time.latest$"
}
},
"name": "eventcodereview"
},
"ds_search_1": {
"type": "ds.search",
"options": {
"query": "`applocker`\n| spath input=UserData_Xml | rename RuleAndFileData.* as *\n| lookup applockereventcodes EventCode OUTPUT Description\n| search PolicyName=$policyname$ EventCode=$eventcode$\n| stats values(host) AS dest by PolicyName, EventCode, Description, RuleId, RuleName, RuleSddl, TargetUser, TargetProcessId, FilePath, Fqbn, TargetLogonId, FullFilePath _time",
"queryParameters": {
"earliest": "$global_time.earliest$",
"latest": "$global_time.latest$"
}
},
"name": "policy_review"
},
"ds_YbLTfvcS": {
"type": "ds.search",
"options": {
"query": "`applocker` EventCode IN (8007, 8004, 8022, 8025, 8029, 8040)\n| spath input=UserData_Xml | rename RuleAndFileData.* as *\n| lookup applockereventcodes EventCode OUTPUT Description\n| stats count",
"queryParameters": {
"earliest": "$global_time.earliest$",
"latest": "$global_time.latest$"
}
},
"name": "blocks"
},
"ds_h2Fcom6o": {
"type": "ds.search",
"options": {
"query": "`applocker` EventCode IN (8003, 8006, 8021, 8024, 8039)\n| spath input=UserData_Xml | rename RuleAndFileData.* as *\n| lookup applockereventcodes EventCode OUTPUT Description\n| stats count"
},
"name": "Audit"
},
"ds_CAVvUpZ1": {
"type": "ds.search",
"options": {
"query": "`applocker` EventCode IN (8002, 8005, 8020, 8023, 8033, 8037)\n| spath input=UserData_Xml | rename RuleAndFileData.* as *\n| lookup applockereventcodes EventCode OUTPUT Description\n| stats count",
"queryParameters": {
"earliest": "$global_time.earliest$",
"latest": "$global_time.latest$"
}
},
"name": "allowed"
}
},
"visualizations": {
"viz_table_1_new": {
"type": "splunk.table",
"options": {
"count": 20,
"dataOverlayMode": "none",
"drilldown": "none",
"percentagesRow": false,
"rowNumbers": false,
"totalsRow": false,
"wrap": true
},
"dataSources": {
"primary": "ds_search_1_new"
},
"title": "EventCode Analysis"
},
"viz_table_1": {
"type": "splunk.table",
"options": {
"count": 20,
"dataOverlayMode": "none",
"drilldown": "none",
"percentagesRow": false,
"rowNumbers": false,
"totalsRow": false,
"wrap": true
},
"dataSources": {
"primary": "ds_search_1"
},
"title": "Policy Review"
},
"viz_oDemj4wG": {
"type": "splunk.markdown",
"options": {
"markdown": "## AppLocker Event Code Reference\n- `8000` - Policy Application Failure: Indicates a problem with applying the policy.\n- `8001` - Policy Application Success: The policy has been applied successfully.\n- `8002` - Allowed File Execution: A file was allowed to run.\n- `8003` - Audited File Execution: A file was executed and logged for audit purposes.\n- `8004` - Blocked File Execution: A file was blocked from running.\n- `8005` - Allowed Script Or MSI Execution: A script or MSI was allowed to run.\n- `8006` - Audited Script Or MSI Execution: A script or MSI was executed and logged for audit purposes.\n- `8007` - Blocked Script Or MSI Execution: A script or MSI was blocked from running.\n- `8020` - Allowed Packaged App: A packaged app was allowed to run.\n- `8021` - Audited Packaged App: A packaged app was executed and logged for audit purposes.\n- `8022` - Disabled Packaged App: A packaged app was disabled from running.\n- `8023` - Allowed Packaged App Installation: Installation of a packaged app was permitted.\n- `8024` - Audited Packaged App Installation: Installation of a packaged app was audited.\n- `8025` - Disabled Packaged App Installation: Installation of a packaged app was disabled.\n- `8027` - No Packaged App Rule: No applicable rule was found for a packaged app.\n"
}
},
"viz_7L8xsZTg": {
"type": "splunk.singlevalue",
"title": "Blocks",
"dataSources": {
"primary": "ds_YbLTfvcS"
}
},
"viz_hAZfweZe": {
"type": "splunk.singlevalue",
"dataSources": {
"primary": "ds_h2Fcom6o"
},
"title": "Audit"
},
"viz_xEjz65IP": {
"type": "splunk.singlevalue",
"title": "Allowed",
"dataSources": {
"primary": "ds_CAVvUpZ1"
}
}
},
"inputs": {
"input_global_trp": {
"type": "input.timerange",
"options": {
"token": "global_time",
"defaultValue": "-24h@h,now"
},
"title": "Global Time Range"
},
"input_7M6KtkjS": {
"options": {
"items": [
{
"label": "All",
"value": "*"
},
{
"label": "APPX",
"value": "appx"
},
{
"label": "SCRIPT",
"value": "script"
},
{
"label": "EXE",
"value": "exe"
},
{
"label": "DLL",
"value": "dll"
},
{
"label": "MSI",
"value": "msi"
}
],
"token": "policyname",
"defaultValue": "*"
},
"title": "Select Policy Name",
"type": "input.dropdown"
},
"input_q9ZwkL2y": {
"options": {
"items": [
{
"label": "All",
"value": "*"
},
{
"label": "8000",
"value": "8000"
},
{
"label": "8001",
"value": "8001"
},
{
"label": "8002",
"value": "8002"
},
{
"label": "8003",
"value": "8003"
},
{
"label": "8004",
"value": "8004"
},
{
"label": "8005",
"value": "8005"
},
{
"label": "8006",
"value": "8006"
},
{
"label": "8007",
"value": "8007"
},
{
"label": "8008",
"value": "8008"
},
{
"label": "8020",
"value": "8020"
},
{
"label": "8021",
"value": "8021"
},
{
"label": "8022",
"value": "8022"
},
{
"label": "8023",
"value": "8023"
},
{
"label": "8024",
"value": "8024"
},
{
"label": "8025",
"value": "8025"
},
{
"label": "8027",
"value": "8027"
},
{
"label": "8028",
"value": "8028"
},
{
"label": "8029",
"value": "8029"
},
{
"label": "8030",
"value": "8030"
},
{
"label": "8031",
"value": "8031"
},
{
"label": "8032",
"value": "8032"
},
{
"label": "8033",
"value": "8033"
},
{
"label": "8034",
"value": "8034"
},
{
"label": "8035",
"value": "8035"
},
{
"label": "8036",
"value": "8036"
},
{
"label": "8037",
"value": "8037"
},
{
"label": "8038",
"value": "8038"
},
{
"label": "8039",
"value": "8039"
},
{
"label": "8040",
"value": "8040"
}
],
"defaultValue": "*",
"token": "eventcode"
},
"title": "Select EventCode",
"type": "input.dropdown"
}
},
"layout": {
"type": "grid",
"options": {
"submitButton": true,
"submitOnDashboardLoad": true
},
"structure": [
{
"item": "viz_oDemj4wG",
"type": "block",
"position": {
"x": 0,
"y": 0,
"w": 1200,
"h": 179
}
},
{
"item": "viz_7L8xsZTg",
"type": "block",
"position": {
"x": 0,
"y": 179,
"w": 300,
"h": 168
}
},
{
"item": "viz_table_1",
"type": "block",
"position": {
"x": 0,
"y": 347,
"w": 1200,
"h": 682
}
},
{
"item": "viz_table_1_new",
"type": "block",
"position": {
"x": 0,
"y": 1029,
"w": 1200,
"h": 736
}
},
{
"item": "viz_hAZfweZe",
"type": "block",
"position": {
"x": 300,
"y": 179,
"w": 300,
"h": 168
}
},
{
"item": "viz_xEjz65IP",
"type": "block",
"position": {
"x": 600,
"y": 179,
"w": 600,
"h": 168
}
}
],
"globalInputs": [
"input_global_trp",
"input_7M6KtkjS",
"input_q9ZwkL2y"
]
},
"title": "ESCU - AppLocker",
"defaults": {
"dataSources": {
"ds.search": {
"options": {
"queryParameters": {
"latest": "$global_time.latest$",
"earliest": "$global_time.earliest$"
}
}
}
}
},
"description": "Utilize this dashboard to assist with auditing and monitoring Windows AppLocker events for your endpoints. Configure the applocker macro to use the AppLocker data source for populating the dashboard."
}
]]></definition>
<meta type="hiddenElements"><![CDATA[
{
"hideEdit": false,
"hideOpenInSearch": false,
"hideExport": false
}
]]></meta>
</dashboard>
@@ -1,199 +0,0 @@
<form theme="dark" version="1.1">
<label>Content Library</label>
<!-- Example uses stats transforming command -->
<!-- This limits evnts passed to post-process search -->
<title>Splunk Security Content</title>
<search id="baseSS">
<query>| rest /services/saved/searches splunk_server=local count=0 | search title="ESCU - *"</query>
</search>
<search id="baseAS">
<query>| rest /services/configs/conf-analyticstories splunk_server=local count=0 |search eai:acl.app = "DA-ESS-ContentUpdate"</query>
</search>
<init>
<set token="form.as_category">*</set>
<set token="form.detection">*</set>
<set token="form.as_story">*</set>
<set token="form.as_attack_id">*</set>
</init>
<!-- Rows for Analytic Story Stats -->
<!-- Rows for Analytic Story Table -->
<!-- Rows for Search Stats -->
<fieldset submitButton="false"></fieldset>
<row>
<panel>
<html>
<div style="background-color: #f8d7da; border: 1px solid #f5c6cb; border-radius: 5px; padding: 15px; margin-bottom: 20px;">
<h2 style="color: #721c24; margin: 0;">
<i class="icon-info-circle" style="margin-right: 10px;"></i>
Explore Splunk Security Content using
<a href="/app/SplunkEnterpriseSecuritySuite/ess_use_case_library" style="color: #721c24; text-decoration: underline;">Splunk Enterprise Security</a>
</h2>
</div>
</html>
</panel>
</row>
<row id="analytic_stories_header_stats">
<panel>
<single>
<title>Total Analytic Stories</title>
<search base="baseAS">
<query> search title="analytic_story://*" |stats count</query>
</search>
<!-- post-process search -->
<option name="colorBy">value</option>
<option name="colorMode">block</option>
<option name="drilldown">none</option>
<option name="numberPrecision">0</option>
<option name="showSparkline">1</option>
<option name="showTrendIndicator">1</option>
<option name="trendColorInterpretation">standard</option>
<option name="trendDisplayMode">absolute</option>
<option name="unitPosition">after</option>
<option name="useColors">1</option>
<option name="useThousandSeparators">1</option>
<option name="rangeColors">["0x555","0x65a637"]</option>
<option name="rangeValues">[0]</option>
</single>
</panel>
<panel>
<single>
<title>Total Detections</title>
<search base="baseSS">
<query>stats count by action.correlationsearch.label| eventstats sum(count) as total_detection_count| fields total_detection_count</query>
</search>
<!-- post-process search -->
<option name="colorBy">value</option>
<option name="colorMode">block</option>
<option name="drilldown">none</option>
<option name="numberPrecision">0</option>
<option name="showSparkline">1</option>
<option name="showTrendIndicator">1</option>
<option name="trendColorInterpretation">standard</option>
<option name="trendDisplayMode">absolute</option>
<option name="unitPosition">after</option>
<option name="useColors">1</option>
<option name="useThousandSeparators">1</option>
<option name="rangeColors">["0x555","0x65a637"]</option>
<option name="rangeValues">[0]</option>
</single>
</panel>
<panel>
<single>
<title>ESCU App Version</title>
<search id="version">
<query>| rest /services/configs/conf-content-version splunk_server=local count=0 | table version</query>
</search>
<option name="colorBy">value</option>
<option name="colorMode">block</option>
<option name="drilldown">none</option>
<option name="numberPrecision">0</option>
<option name="rangeColors">["0x555","0x65a637"]</option>
<option name="rangeValues">[0]</option>
<option name="refresh.display">progressbar</option>
<option name="showSparkline">1</option>
<option name="showTrendIndicator">1</option>
<option name="trendColorInterpretation">standard</option>
<option name="trendDisplayMode">absolute</option>
<option name="unitPosition">after</option>
<option name="useColors">1</option>
<option name="useThousandSeparators">1</option>
</single>
</panel>
</row>
<row id="analytic_stories_viz">
<panel>
<title>Story Categories</title>
<chart>
<search>
<query>| rest /services/configs/conf-analyticstories splunk_server=local count=0 | search eai:acl.app = "DA-ESS-ContentUpdate"| search title="analytic_story://*"| stats count by category</query>
</search>
<drilldown>
<set token="form.as_category">$click.value$</set>
<set token="as_category" prefix="&quot;" suffix="&quot;">$click.value$</set>
</drilldown>
<option name="charting.chart">bar</option>
<option name="charting.drilldown">all</option>
<option name="charting.legend.placement">none</option>
<option name="charting.axisLabelsX.integerUnits">true</option>
<option name="charting.axisTitleX.visibility">collapsed</option>
<option name="charting.axisTitleY.visibility">collapsed</option>
</chart>
</panel>
<panel>
<title>Analytic Stories by MITRE Technique ID</title>
<chart>
<search>
<query>
| rest /services/saved/searches splunk_server=local count=0 | search title="ESCU - *"
| spath input=action.correlationsearch.annotations path=mitre_attack{} output="MITRE Technique ID"
| spath input=action.correlationsearch.annotations path=analytic_story{} output=story_name
| stats dc(story_name) as "Analytic Stories" by "MITRE Technique ID"
</query>
</search>
<drilldown>
<set token="form.as_attack_id">$click.value$</set>
<set token="as_attack_id">$click.value$</set>
</drilldown>
<option name="charting.legend.placement">none</option>
</chart>
</panel>
</row>
<row id="analytic_stories_details_table">
<panel>
<input type="dropdown" token="story">
<label>Analytic Story</label>
<choice value="*">All</choice>
<search>
<latest>now</latest>
<query>| rest /services/configs/conf-savedsearches splunk_server=local count=0
| search action.escu.search_type = detection
| spath input=action.correlationsearch.annotations path=analytic_story{} output="story"
| mvexpand story
| dedup story | fields story</query>
</search>
<fieldForLabel>story</fieldForLabel>
<fieldForValue>story</fieldForValue>
<default>*</default>
<prefix>"</prefix>
<suffix>"</suffix>
<initialValue>*</initialValue>
</input>
<html>
<input id="analytic_filter_clear" class="btn btn-primary" type="button" value="Clear All"/>
</html>
<table>
<title>Analytic Story Details</title>
<search>
<query>| rest /services/configs/conf-savedsearches splunk_server=local count=0
| search action.escu.search_type = detection
| spath input=action.correlationsearch.annotations path=analytic_story{} output="analytic_story"
| spath input=action.correlationsearch.annotations path=mitre_attack{} output="mitre_attack"
| spath input=action.escu.data_models path={} output="Data Models"
| rename title as "Detections"
| join analytic_story
[| rest /services/configs/conf-analyticstories splunk_server=local count=0
| search title="analytic_story://*"
| eval "analytic_story"=replace(title,"analytic_story://","" )
]
| search analytic_story= $story$
|stats values(Detections) as Detections values(mitre_attack) as "MITRE Technique ID" values(last_updated) as "Last Updated" by analytic_story description| rename analytic_story as "Analytic Story"| rename description as Description| table "Analytic Story" Description Detections "MITRE Technique ID" "Last Updated"</query>
<earliest>$earliest$</earliest>
<latest>$latest$</latest>
</search>
<option name="count">5</option>
<option name="dataOverlayMode">none</option>
<option name="drilldown">row</option>
<option name="refresh.display">progressbar</option>
<option name="rowNumbers">true</option>
<option name="wrap">true</option>
<drilldown>
<link target="_blank">
<![CDATA[
/app/SplunkEnterpriseSecuritySuite/ess_analytic_story_details?analytic_story=$row.Analytic Story$
]]>
</link>
</drilldown>
</table>
</panel>
</row>
</form>
@@ -1,13 +0,0 @@
<form isVisible="true" version="1.1">
<label>Feedback Center</label>
<description>Welcome to Splunk Enterprise Security Content Updates Feedback Center.</description>
<row>
<panel>
<html>
<p5>Contact us at <a href = "mailto:research@splunk.com">research@splunk.com</a> to send us support requests, bug reports, or questions directly to the Splunk Security Research Team.
<br>Please specify your request type and/or the title of any related Analytic Stories.</br>
You can also find us in the <b>#security-research</b> room in the <a href = "http://splunk-usergroups.slack.com/">Splunk Slack channel</a></p5>
</html>
</panel>
</row>
</form>
-5
View File
@@ -1,5 +0,0 @@
[replicationSettings:refineConf]
replicate.analytic_stories = false
[replicationDenylist]
excludeESCU = apps[/\\]DA-ESS-ContentUpdate[/\\]lookups[/\\]...
-768
View File
@@ -1,768 +0,0 @@
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
[panel://workbench_panel_all_backup_logs_for_host___response_task]
label = All backup logs for host
description = Retrieve the backup logs for the last 2 weeks for a specific host in order to investigate why backups are not completing successfully.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task]
label = Amazon EKS Kubernetes activity by src ip
description = This search provides investigation data about requests via user agent, authentication request URI, verb and cluster name data against Kubernetes cluster from a specific IP address
disabled = 0
tokens = {\
"src_ip": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src_ip=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task]
label = AWS Investigate Security Hub alerts by dest
description = This search retrieves the all the alerts created by AWS Security Hub for a specific dest(instance_id).
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_aws_investigate_user_activities_by_accesskeyid___response_task]
label = AWS Investigate User Activities By AccessKeyId
description = This search retrieves the times, ARN, source IPs, AWS regions, event names, and the result of the event for specific credentials.
disabled = 0
tokens = {\
"accessKeyId": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR accessKeyId=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task]
label = AWS Investigate User Activities By ARN
description = This search lists all the logged CloudTrail activities by a specific user ARN and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and all the user's identity information.
disabled = 0
tokens = {\
"user": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR user=",\
"valueType": "primitive",\
"value": "identity",\
"default": "null"\
}\
}\
[panel://workbench_panel_aws_network_acl_details_from_id___response_task]
label = AWS Network ACL Details from ID
description = This search queries AWS description logs and returns all the information about a specific network ACL via network ACL ID
disabled = 0
tokens = {\
"networkAclId": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR networkAclId=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task]
label = AWS Network Interface details via resourceId
description = This search queries AWS configuration logs and returns the information about a specific network interface via network interface ID. The information will include the ARN of the network interface, its relationships with other AWS resources, the public and the private IP associated with the network interface.
disabled = 0
tokens = {\
"resourceId": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR resourceId=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_aws_s3_bucket_details_via_bucketname___response_task]
label = AWS S3 Bucket details via bucketName
description = This search queries AWS configuration logs and returns the information about a specific S3 bucket. The information returned includes the time the S3 bucket was created, the resource ID, the region it belongs to, the value of action performed, AWS account ID, and configuration values of the access-control lists associated with the bucket.
disabled = 0
tokens = {\
"bucketName": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR bucketName=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task]
label = GCP Kubernetes activity by src ip
description = This search provides investigation data about requests via user agent, authentication request URI, resource path and cluster name data against Kubernetes cluster from a specific IP address
disabled = 0
tokens = {\
"src_ip": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src_ip=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_all_aws_activity_from_city___response_task]
label = Get All AWS Activity From City
description = This search retrieves all the activity from a specific city and will create a table containing the time, city, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
disabled = 0
tokens = {\
"City": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR City=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_all_aws_activity_from_country___response_task]
label = Get All AWS Activity From Country
description = This search retrieves all the activity from a specific country and will create a table containing the time, country, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
disabled = 0
tokens = {\
"Country": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR Country=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task]
label = Get All AWS Activity From IP Address
description = This search retrieves all the activity from a specific IP address and will create a table containing the time, ARN, username, the type of user, the IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
disabled = 0
tokens = {\
"src_ip": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src_ip=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_all_aws_activity_from_region___response_task]
label = Get All AWS Activity From Region
description = This search retrieves all the activity from a specific geographic region and will create a table containing the time, geographic region, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
disabled = 0
tokens = {\
"Region": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR Region=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_backup_logs_for_endpoint___response_task]
label = Get Backup Logs For Endpoint
description = This search will tell you the backup status from your netbackup_logs of a specific endpoint for the last week.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_certificate_logs_for_a_domain___response_task]
label = Get Certificate logs for a domain
description = This search queries the Certificates datamodel and give you all the information for a specific domain. Please note that the certificates issued by "Let's Encrypt" are widely used by attackers.
disabled = 0
tokens = {\
"domain": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR domain=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_dns_server_history_for_a_host___response_task]
label = Get DNS Server History for a host
description = While investigating any detections it is important to understand which and how many DNS servers a host has connected to in the past. This search uses data that is tagged as DNS and gives you a count and list of DNS servers that a particular host has connected to the previous 24 hours.
disabled = 0
tokens = {\
"src_ip": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src_ip=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_dns_traffic_ratio___response_task]
label = Get DNS traffic ratio
description = This search calculates the ratio of DNS traffic originating and coming from a host to a list of DNS servers over the last 24 hours. A high value of this ratio could be very useful to quickly understand if a src_ip (host) is sending a high volume of data out via port 53, could be an indicator of data exfiltration via DNS.
disabled = 0
tokens = {\
"src_ip": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src_ip=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task]
label = Get EC2 Instance Details by instanceId
description = This search queries AWS description logs and returns all the information about a specific instance via the instanceId field
disabled = 0
tokens = {\
"instanceId": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR instanceId=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_ec2_launch_details___response_task]
label = Get EC2 Launch Details
description = This search returns some of the launch details for a EC2 instance.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_email_info___response_task]
label = Get Email Info
description = This search returns all the information Splunk might have collected a specific email message over the last 2 hours.
disabled = 0
tokens = {\
"message_id": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR message_id=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_emails_from_specific_sender___response_task]
label = Get Emails From Specific Sender
description = This search returns all the emails from a specific sender over the last 24 and next hours.
disabled = 0
tokens = {\
"src_user": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src_user=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_first_occurrence_and_last_occurrence_of_a_mac_address___response_task]
label = Get First Occurrence and Last Occurrence of a MAC Address
description = This search allows you to gather more context around a notable which has detected a new device connecting to your network. Use this search to determine the first and last occurrences of the suspicious device attempting to connect with your network.
disabled = 0
tokens = {\
"src_mac": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src_mac=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_history_of_email_sources___response_task]
label = Get History Of Email Sources
description = This search returns a list of all email sources seen in the 48 hours prior to the notable event to 24 hours after, and the number of emails from each source.
disabled = 0
tokens = {\
"src": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_logon_rights_modifications_for_endpoint___response_task]
label = Get Logon Rights Modifications For Endpoint
description = This search allows you to retrieve any modifications to logon rights associated with a specific host.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_logon_rights_modifications_for_user___response_task]
label = Get Logon Rights Modifications For User
description = This search allows you to retrieve any modifications to logon rights for a specific user account.
disabled = 0
tokens = {\
"user": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR user=",\
"valueType": "primitive",\
"value": "identity",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_notable_history___response_task]
label = Get Notable History
description = This search queries the notable index and returns all the Notable Events for the particular destination host, giving the analyst an overview of the incidents that may have occurred with the host under investigation.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_parent_process_info___response_task]
label = Get Parent Process Info
description = This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest
disabled = 0
tokens = {\
"parent_process_name": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR parent_process_name=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
},\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_process_file_activity___response_task]
label = Get Process File Activity
description = This search returns the file activity for a specific process on a specific endpoint
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
},\
"process_name": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR process_name=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_process_info___response_task]
label = Get Process Info
description = This search queries the Endpoint data model to give you details about the process running on a host which is under investigation. To gather the process info, enter the values for the process name in question and the destination IP address.
disabled = 0
tokens = {\
"process_name": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR process_name=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
},\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_process_information_for_port_activity___response_task]
label = Get Process Information For Port Activity
description = This search will return information about the process associated with observed network traffic to a specific destination port from a specific host.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
},\
"dest_port": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest_port=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task]
label = Get Process Responsible For The DNS Traffic
description = While investigating, an analyst will want to know what process and parent_process is responsible for generating suspicious DNS traffic. Use the following search and enter the value of `dest` in the search to get specific details on the process responsible for creating the DNS traffic.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task]
label = Get Sysmon WMI Activity for Host
description = This search queries Sysmon WMI events for the host of interest.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_get_web_session_information_via_session_id___response_task]
label = Get Web Session Information via session id
description = This search helps an analyst investigate a notable event to find out more about a specific web session. The search looks for a specific web session ID in the HTTP web traffic and outputs the URL and user agents, grouped by source IP address and HTTP status code.
disabled = 0
tokens = {\
"session_id": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR session_id=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_aws_activities_via_region_name___response_task]
label = Investigate AWS activities via region name
description = This search lists all the user activities logged by CloudTrail for a specific region in question and will create a table of the values of parameters requested, the type of the event and the response from the AWS API by each user
disabled = 0
tokens = {\
"vendor_region": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR vendor_region=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_aws_user_activities_by_user_field___response_task]
label = Investigate AWS User Activities by user field
description = This search lists all the logged CloudTrail activities by a specific user and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and the user's identity information.
disabled = 0
tokens = {\
"user": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR user=",\
"valueType": "primitive",\
"value": "identity",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task]
label = Investigate Failed Logins for Multiple Destinations
description = This search returns failed logins to multiple destinations by user.
disabled = 0
tokens = {\
"user": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR user=",\
"valueType": "primitive",\
"value": "identity",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_network_traffic_from_src_ip___response_task]
label = Investigate Network Traffic From src ip
description = This search allows you to find all the network traffic from a specific IP address.
disabled = 0
tokens = {\
"src_ip": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src_ip=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_okta_activity_by_app___response_task]
label = Investigate Okta Activity by app
description = This search returns all okta events associated with a specific app
disabled = 0
tokens = {\
"app": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR app=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_pass_the_hash_attempts___response_task]
label = Investigate Pass the Hash Attempts
description = This search hunts for dumped NTLM hashes used for pass the hash.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_pass_the_ticket_attempts___response_task]
label = Investigate Pass the Ticket Attempts
description = This search hunts for dumped kerberos ticket from LSASS memory.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_previous_unseen_user___response_task]
label = Investigate Previous Unseen User
description = This search returns previous unseen user, which didn't log in for 30 days.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task]
label = Investigate Successful Remote Desktop Authentications
description = This search returns the source, destination, and user for all successful remote-desktop authentications. A successful authentication after a brute-force attack on a destination machine is suspicious behavior.
disabled = 0
tokens = {\
"dest": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest=",\
"valueType": "primitive",\
"value": "asset",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_suspicious_strings_in_http_header___response_task]
label = Investigate Suspicious Strings in HTTP Header
description = This search helps an analyst investigate a notable event related to a potential Apache Struts exploitation. To investigate, we will want to isolate and analyze the "payload" or the commands that were passed to the vulnerable hosts by creating a few regular expressions to carve out the commands focusing on common keywords from the payload, such as cmd.exe, /bin/bash and whois. The search returns these suspicious strings found in the HTTP logs of the system of interest.
disabled = 0
tokens = {\
"src_ip": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src_ip=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
},\
"dest_ip": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR dest_ip=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_user_activities_in_okta___response_task]
label = Investigate User Activities In Okta
description = This search returns all okta events by a specific user
disabled = 0
tokens = {\
"user": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR user=",\
"valueType": "primitive",\
"value": "identity",\
"default": "null"\
}\
}\
[panel://workbench_panel_investigate_web_posts_from_src___response_task]
label = Investigate Web POSTs From src
description = This investigative search retrieves POST requests from a specified source IP or hostname. Identifying the POST requests, as well as their associated destination URLs and user agent(s), may help you scope and characterize the suspicious traffic.
disabled = 0
tokens = {\
"src": {\
"valuePrefix": "\"",\
"valueSuffix": "\"",\
"delimiter": " OR src=",\
"valueType": "primitive",\
"value": "file",\
"default": "null"\
}\
}\
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
-486
View File
@@ -1,486 +0,0 @@
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
[3cx_ioc_domains]
filename = 3cx_ioc_domains.csv
default_match = false
case_sensitive_match = false
# description = A list of domains from the 3CX supply chain attack.
match_type = WILDCARD(domain)
min_matches = 1
[__mlspl_detect_dns_data_exfiltration_using_pretrained_model_in_dsdl]
filename = __mlspl_detect_dns_data_exfiltration_using_pretrained_model_in_dsdl.mlmodel
case_sensitive_match = false
# description = Detect DNS Data Exfiltration using pretrained Model in DSDL
[__mlspl_detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl]
filename = __mlspl_detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl.mlmodel
case_sensitive_match = false
# description = Detect suspicious DNS txt records using Pretrained Model in DSDL
[__mlspl_detect_suspicious_processnames_using_pretrained_model_in_dsdl]
filename = __mlspl_detect_suspicious_processnames_using_pretrained_model_in_dsdl.mlmodel
case_sensitive_match = false
# description = Detect a suspicious processname using Pretrained Model in DSDL
[__mlspl_pretrained_dga_model_dsdl]
filename = __mlspl_pretrained_dga_model_dsdl.mlmodel
case_sensitive_match = false
# description = Detect DGA domains using Pretrained Model in DSDL
[__mlspl_risky_spl_pre_trained_model]
filename = __mlspl_risky_spl_pre_trained_model.mlmodel
default_match = false
case_sensitive_match = false
# description = Detect Risky SPL using Pretrained ML Model
min_matches = 1
[__mlspl_unusual_commandline_detection]
filename = __mlspl_unusual_commandline_detection.mlmodel
default_match = false
case_sensitive_match = false
# description = An MLTK model for detecting malicious commandlines
min_matches = 1
[advanced_audit_policy_guids]
filename = advanced_audit_policy_guids.csv
default_match = false
case_sensitive_match = false
# description = List of GUIDs associated with Windows advanced audit policies
match_type = WILDCARD(GUID)
min_matches = 1
[api_call_by_user_baseline]
collection = api_call_by_user_baseline
external_type = kvstore
# description = A collection that will contain the baseline information for number of AWS API calls per user
fields_list = arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls
[applockereventcodes]
filename = applockereventcodes.csv
default_match = false
case_sensitive_match = false
# description = A csv of the ID and rule name for AppLocker event codes.
match_type = WILDCARD(AppLocker_Event_Code)
min_matches = 1
[asr_rules]
filename = asr_rules.csv
default_match = false
case_sensitive_match = false
# description = A csv of the ID and rule name for ASR, Microsoft Attack Surface Reduction rules.
match_type = WILDCARD(ASR_Rule)
min_matches = 1
[attacker_tools]
filename = attacker_tools.csv
default_match = false
case_sensitive_match = false
# description = A list of tools used by attackers
match_type = WILDCARD(attacker_tool_names)
min_matches = 1
[aws_service_accounts]
filename = aws_service_accounts.csv
# description = A lookup file that will contain AWS Service accounts
[baseline_blocked_outbound_connections]
filename = baseline_blocked_outbound_connections.csv
# description = A lookup file that will contain the baseline information for number of blocked outbound connections
[brandMonitoring_lookup]
filename = brand_monitoring.csv
default_match = false
# description = A file that contains look-a-like domains for brands that you want to monitor
match_type = WILDCARD(domain)
min_matches = 1
[browser_app_list]
filename = browser_app_list.csv
default_match = false
case_sensitive_match = false
# description = A list of known browser application being targeted for credential extraction.
match_type = WILDCARD(browser_process_name), WILDCARD(browser_object_path)
min_matches = 1
[char_conversion_matrix]
filename = char_conversion_matrix.csv
default_match = false
case_sensitive_match = true
# description = A simple conversion matrix for converting to and from UTF8/16 base64/hex/decimal encoding. Created mosty from https://community.splunk.com/t5/Splunk-Search/base64-decoding-in-search/m-p/27572#M177741, with small modifications for UTF16LE parsing for powershell encoding.
match_type = WILDCARD(data)
min_matches = 1
[cloud_instances_enough_data]
collection = cloud_instances_enough_data
external_type = kvstore
default_match = false
# description = A lookup to determine if you have a sufficient amount of time has passed to collect cloud instance data for behavioral searches
match_type = WILDCARD(filter)
fields_list = _key, filter, enough_data
[discovered_dns_records]
filename = discovered_dns_records.csv
default_match = false
# description = A placeholder for a list of discovered DNS records generated by the baseline discover_dns_records
min_matches = 1
[domain_admins]
filename = domain_admins.csv
case_sensitive_match = false
# description = List of domain admins
[domains]
filename = domains.csv
# description = A list of domains that can be ignored
[dynamic_dns_providers_default]
filename = dynamic_dns_providers_default.csv
case_sensitive_match = false
# description = A list of dynammic dns providers that should not be modified
match_type = WILDCARD(dynamic_dns_domains)
[dynamic_dns_providers_local]
filename = dynamic_dns_providers_local.csv
case_sensitive_match = false
# description = A list of dynammic dns providers that can be modified
match_type = WILDCARD(dynamic_dns_domains)
[hijacklibs]
filename = hijacklibs.csv
default_match = false
case_sensitive_match = false
# description = A list of potentially abused libraries in Windows
match_type = WILDCARD(library)
min_matches = 1
[hijacklibs_loaded]
filename = hijacklibs_loaded.csv
default_match = false
case_sensitive_match = false
# description = A list of potentially abused libraries in Windows
match_type = WILDCARD(library),WILDCARD(excludes)
min_matches = 1
[images_to_repository]
filename = images_to_repository.csv
# description = Mapping images to repositories
[is_net_windows_file]
filename = is_net_windows_file20231221.csv
default_match = false
case_sensitive_match = false
# description = A full baseline of executable files in \Windows\, including sub-directories from Server 2016 and Windows 11. Certain .net binaries may not have been captured due to different Windows SDK's or developer utilities not installed during baseline.
min_matches = 1
[is_nirsoft_software]
filename = is_nirsoft_software20231221.csv
default_match = false
case_sensitive_match = false
# description = A subset of utilities provided by NirSoft that may be used by adversaries.
min_matches = 1
[is_suspicious_file_extension_lookup]
filename = is_suspicious_file_extension_lookup.csv
# description = A list of suspicious extensions for email attachments
match_type = WILDCARD(file_name)
[is_windows_system_file]
filename = is_windows_system_file20231221.csv
default_match = false
case_sensitive_match = false
# description = A full baseline of executable files in Windows\System32 and Windows\Syswow64, including sub-directories from Server 2016 and Windows 10.
min_matches = 1
[k8s_container_network_io_baseline]
collection = k8s_container_network_io_baseline
external_type = kvstore
# description = A place holder for a list of used Kuberntes Container Network IO
fields_list = key, avg_outbound_network_io, avg_inbound_network_io, stdev_outbound_network_io, stdev_inbound_network_io, count, last_seen
[k8s_container_network_io_ratio_baseline]
collection = k8s_container_network_io_ratio_baseline
external_type = kvstore
# description = A place holder for a list of used Kuberntes Container Network IO Ratio
fields_list = key, avg_outbound_network_io, avg_inbound_network_io, stdev_outbound_network_io, stdev_inbound_network_io, count, last_seen
[k8s_process_resource_baseline]
collection = k8s_process_resource_baseline
external_type = kvstore
# description = A place holder for a list of used Kuberntes Process Resource
fields_list = host.name, k8s.cluster.name, k8s.node.name, process.executable.name, avg_process.cpu.time, avg_process.cpu.utilization, avg_process.disk.io, avg_process.disk.operations, avg_process.memory.usage, avg_process.memory.utilization, avg_process.memory.virtual, avg_process.threads, stdev_process.cpu.time, stdev_process.cpu.utilization, stdev_process.disk.io, stdev_process.disk.operations, stdev_process.memory.usage, stdev_process.memory.utilization, stdev_process.memory.virtual, stdev_process.threads, key
[k8s_process_resource_ratio_baseline]
collection = k8s_process_resource_ratio_baseline
external_type = kvstore
# description = A place holder for a list of used Kuberntes Process Ratios
fields_list = key, avg_cpu:mem, stdev_cpu:mem, avg_cpu:disk, stdev_cpu:disk, avg_mem:disk, stdev_mem:disk, avg_cpu:threads, stdev_cpu:threads, avg_disk:threads, avg_disk:threads, count, last_seen
[legit_domains]
filename = legit_domains.csv
# description = A list of legit domains to be used as an ignore list for possible phishing sites
[linux_tool_discovery_process]
filename = linux_tool_discovery_process.csv
default_match = false
case_sensitive_match = false
# description = A list of suspicious bash commonly used by attackers via scripts
match_type = WILDCARD(process)
min_matches = 1
[local_file_inclusion_paths]
filename = local_file_inclusion_paths.csv
default_match = false
case_sensitive_match = false
# description = A list of interesting files in a local file inclusion attack
match_type = WILDCARD(local_file_inclusion_paths)
min_matches = 1
[lolbas_file_path]
filename = lolbas_file_path.csv
default_match = false
case_sensitive_match = false
# description = A list of LOLBAS and their file path used in determining if a script or binary is valid on windows
match_type = WILDCARD(lolbas_file_name)
min_matches = 1
[loldrivers]
filename = loldrivers.csv
default_match = false
case_sensitive_match = false
# description = A list of known vulnerable drivers
match_type = WILDCARD(driver_name)
min_matches = 1
[lookup_rare_process_allow_list_default]
filename = rare_process_allow_list_default.csv
default_match = false
case_sensitive_match = false
# description = A list of rare processes that are legitimate that is provided by Splunk
match_type = WILDCARD(process)
min_matches = 1
[lookup_rare_process_allow_list_local]
filename = rare_process_allow_list_local.csv
default_match = false
case_sensitive_match = false
# description = A list of rare processes that are legitimate provided by the end user
match_type = WILDCARD(process)
min_matches = 1
[lookup_uncommon_processes_default]
filename = uncommon_processes_default.csv
case_sensitive_match = false
# description = A list of processes that are not common
match_type = WILDCARD(process)
[lookup_uncommon_processes_local]
filename = uncommon_processes_local.csv
case_sensitive_match = false
# description = A list of processes that are not common
match_type = WILDCARD(process)
[mandatory_job_for_workflow]
filename = mandatory_job_for_workflow.csv
# description = A lookup file that will be used to define the mandatory job for workflow
[mandatory_step_for_job]
filename = mandatory_step_for_job.csv
# description = A lookup file that will be used to define the mandatory step for job
[network_acl_activity_baseline]
filename = network_acl_activity_baseline.csv
# description = A lookup file that will contain the baseline information for number of AWS Network ACL Activity
[previously_seen_api_calls_from_user_roles]
collection = previously_seen_api_calls_from_user_roles
external_type = kvstore
# description = A placeholder for a list of IPs that have access S3
fields_list = _key,earliest,latest,userName,eventName
[previously_seen_aws_cross_account_activity]
collection = previously_seen_aws_cross_account_activity
external_type = kvstore
# description = A placeholder for a list of AWS accounts and assumed roles
fields_list = _key,firstTime,lastTime,requestingAccountId,requestedAccountId
[previously_seen_aws_regions]
collection = previously_seen_aws_regions
external_type = kvstore
# description = A place holder for a list of used AWS regions
fields_list = _key,earliest,latest,awsRegion
[previously_seen_cloud_api_calls_per_user_role]
collection = previously_seen_cloud_api_calls_per_user_role
external_type = kvstore
# description = A table of users, commands, and the first and last time that they have been seen
fields_list = _key, user, command, firstTimeSeen, lastTimeSeen, enough_data
[previously_seen_cloud_compute_creations_by_user]
collection = previously_seen_cloud_compute_creations_by_user
external_type = kvstore
# description = A table of previously seen users creating cloud instances
fields_list = _key, firstTimeSeen, lastTimeSeen, user, enough_data
[previously_seen_cloud_compute_images]
collection = previously_seen_cloud_compute_images
external_type = kvstore
# description = A table of previously seen Cloud image IDs
fields_list = _key, firstTimeSeen, lastTimeSeen, image_id, enough_data
[previously_seen_cloud_compute_instance_types]
collection = previously_seen_cloud_compute_instance_types
external_type = kvstore
# description = A place holder for a list of used cloud compute instance types
fields_list = _key, firstTimeSeen, lastTimeSeen, instance_type, enough_data
[previously_seen_cloud_instance_modifications_by_user]
collection = previously_seen_cloud_instance_modifications_by_user
external_type = kvstore
# description = A table of users seen making instance modifications, and the first and last time that the activity was observed
fields_list = _key, firstTimeSeen, lastTimeSeen, user, enough_data
[previously_seen_cloud_provisioning_activity_sources]
collection = previously_seen_cloud_provisioning_activity_sources
external_type = kvstore
# description = A table of source IPs, geographic locations, and the first and last time that they have that done cloud provisioning activities
fields_list = _key, src, City, Country, Region, firstTimeSeen, lastTimeSeen, enough_data
[previously_seen_cloud_regions]
collection = previously_seen_cloud_regions
external_type = kvstore
# description = A table of vendor_region values and the first and last time that they have been observed in cloud provisioning activities
fields_list = _key, firstTimeSeen, lastTimeSeen, vendor_region, enough_data
[previously_seen_cmd_line_arguments]
filename = previously_seen_cmd_line_arguments.csv
# description = A placeholder for a list of cmd line arugments that been seen before
[previously_seen_ec2_modifications_by_user]
filename = previously_seen_ec2_modifications_by_user.csv
# description = A place holder for a list of AWS EC2 modifications done by each user
[previously_seen_gcp_storage_access_from_remote_ip]
collection = previously_seen_gcp_storage_access_from_remote_ip
external_type = kvstore
# description = A place holder for a list of GCP storage access from remote IPs
fields_list = _key, firstTime, lastTime, bucket_name, remote_ip, operation, request_uri
[previously_seen_running_windows_services]
collection = previously_seen_running_windows_services
external_type = kvstore
# description = A placeholder for the list of Windows Services running
fields_list = _key, service, firstTimeSeen, lastTimeSeen
[previously_seen_S3_access_from_remote_ip]
collection = previously_seen_S3_access_from_remote_ip
external_type = kvstore
# description = A placeholder for a list of IPs that have access S3
fields_list = _key, bucket_name,remote_ip,earliest,latest
[previously_seen_users_console_logins]
collection = previously_seen_users_console_logins
external_type = kvstore
# description = A table of users seen doing console logins, and the first and last time that the activity was observed
fields_list = _key, firstTime, lastTime, user, src, City, Region, Country
[privileged_azure_ad_roles]
filename = privileged_azure_ad_roles.csv
default_match = false
case_sensitive_match = false
# description = A list of privileged Azure Active Directory roles.
match_type = WILDCARD(azureadrole)
min_matches = 1
[prohibited_apps_launching_cmd]
filename = prohibited_apps_launching_cmd20231221.csv
# description = A list of processes that should not be launching cmd.exe
match_type = WILDCARD(prohibited_applications)
[prohibited_processes]
filename = prohibited_processes.csv
# description = A list of processes that have been marked as prohibited
[ransomware_extensions_lookup]
filename = ransomware_extensions_20231219.csv
default_match = false
case_sensitive_match = false
# description = A list of file extensions that are associated with ransomware
match_type = WILDCARD(Extensions)
min_matches = 1
[ransomware_notes_lookup]
filename = ransomware_notes_20231219.csv
default_match = false
case_sensitive_match = false
# description = A list of file names that are ransomware note files
match_type = WILDCARD(ransomware_notes)
min_matches = 1
[remote_access_software]
filename = remote_access_software.csv
default_match = false
case_sensitive_match = false
# description = A list of Remote Access Software
match_type = WILDCARD(remote_utility),WILDCARD(remote_domain),WILDCARD(remote_utility_fileinfo)
min_matches = 1
[s3_deletion_baseline]
collection = s3_deletion_baseline
external_type = kvstore
# description = A placeholder for the baseline information for AWS S3 deletions
fields_list = _key, arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls
[security_group_activity_baseline]
collection = security_group_activity_baseline
external_type = kvstore
# description = A placeholder for the baseline information for AWS security groups
fields_list = _key, arn,latestCount,numDataPoints,avgApiCalls,stdevApiCalls
[security_services_lookup]
filename = security_services.csv
default_match = false
# description = A list of services that deal with security
match_type = WILDCARD(service)
min_matches = 1
[splunk_risky_command]
filename = splunk_risky_command_20240601.csv
default_match = false
case_sensitive_match = false
# description = A list of Risky Splunk Command that are candidates for abuse
match_type = WILDCARD(splunk_risky_command)
min_matches = 1
[suspicious_writes_lookup]
filename = suspicious_files.csv
default_match = false
# description = A list of suspicious file names
match_type = WILDCARD(file)
min_matches = 1
[windows_protocol_handlers]
filename = windows_protocol_handlers.csv
default_match = false
case_sensitive_match = false
# description = A list of Windows Protocol Handlers
match_type = WILDCARD(handler)
min_matches = 1
[zoom_first_time_child_process]
collection = zoom_first_time_child_process
external_type = kvstore
# description = A list of suspicious file names
fields_list = _key, dest, process_name, firstTimeSeen, lastTimeSeen
### Default transforms definitions for the lookup files we ship ###
[mitre_enrichment]
filename = mitre_enrichment.csv
# description = A lookup file that is created by generate.py
-73
View File
@@ -1,73 +0,0 @@
[escu-metrics-usage]
action.email.useNSSubject = 1
alert.digest_mode = True
alert.suppress = 0
alert.track = 0
auto_summarize.dispatch.earliest_time = -1d@h
dispatchAs = user
search = index=_audit sourcetype="audittrail" \
"ESCU - "\
`comment("Find all the search names in the audittrail.")`\
| stats count(search) by search savedsearch_name user\
| eval usage=(if(savedsearch_name=="","Adhoc","Scheduled")) \
`comment("If the savedsearch_name field in the audittrail is empty, the search was run adhoc. Otherwise it was run as a scheduled search")`\
| rex field=search "\"(?<savedsearch_name>.*)\""\
`comment("Extract the name of the search from the search string")`\
| table savedsearch_name count(search) usage user | join savedsearch_name max=0 type=left [search sourcetype="manifests" | spath searches{} | mvexpand searches{} | spath input=searches{} | table category search_name | rename search_name as savedsearch_name | dedup savedsearch_name] | search category=*
[escu-metrics-search]
action.email.useNSSubject = 1
alert.suppress = 0
alert.track = 0
auto_summarize.dispatch.earliest_time = -1d@h
enableSched = 1
cron_schedule = 0 0 * * *
dispatch.earliest_time = -4h@h
dispatch.latest_time = -1h@h
search = index=_audit action=search | transaction search_id maxspan=3m | search ESCU | stats sum(total_run_time) avg(total_run_time) max(total_run_time) sum(result_count)
[escu-metrics-search-events]
action.email.useNSSubject = 1
alert.digest_mode = True
alert.suppress = 0
alert.track = 0
auto_summarize.dispatch.earliest_time = -1d@h
cron_schedule = 0 0 * * *
enableSched = 1
dispatch.earliest_time = -4h@h
dispatch.latest_time = -1h@h
search = [search index=_audit sourcetype="audittrail" \"ESCU NOT "index=_audit" | where search !="" | dedup search_id | rex field=search "\"(?<search_name>.*)\"" | rex field=_raw "user=(?<user>[a-zA-Z0-9_\-]+)" | eval usage=if(savedsearch_name!="", "scheduled", "adhoc") | eval savedsearch_name=if(savedsearch_name != "", savedsearch_name, search_name) | table savedsearch_name search_id user _time usage | outputlookup escu_search_id.csv | table search_id] index=_audit total_run_time event_count result_count NOT "index=_audit" | lookup escu_search_id.csv search_id | stats count(savedsearch_name) AS search_count avg(total_run_time) AS search_avg_run_time sum(total_run_time) AS search_total_run_time sum(result_count) AS search_total_results earliest(_time) AS firsts latest(_time) AS lasts by savedsearch_name user usage| eval first_run=strftime(firsts, "%B %d %Y") | eval last_run=strftime(lasts, "%B %d %Y")
[escu-metrics-search-longest-runtime]
action.email.useNSSubject = 1
alert.digest_mode = True
alert.suppress = 0
alert.track = 0
auto_summarize.dispatch.earliest_time = -1d@h
enableSched = 1
cron_schedule = 0 0 * * *
disabled = 1
dispatch.earliest_time = -4h@h
dispatch.latest_time = -1h@h
search = index=_* ESCU [search index=_* action=search latest=-2h earliest=-1d| transaction search_id maxspan=3m | search ESCU | stats values(total_run_time) AS run by search_id | sort -run | head 1| table search_id] | table search search_id
[escu-metrics-usage-search]
action.email.useNSSubject = 1
alert.digest_mode = True
alert.suppress = 0
alert.track = 0
auto_summarize.dispatch.earliest_time = -1d@h
cron_schedule = 0 0 * * *
dispatch.earliest_time = -4h@h
dispatch.latest_time = -1h@h
enableSched = 1
dispatchAs = user
search = index=_audit sourcetype="audittrail" \
"ESCU - "\
`comment("Find all the search names in the audittrail. Ignore the last few minutes so we can exclude this search's text from the result.")`\
| stats count(search) by search savedsearch_name user\
| eval usage=(if(savedsearch_name=="","Adhoc","Scheduled")) \
`comment("If the savedsearch_name field in the audittrail is empty, the search was run adhoc. Otherwise it was run as a scheduled search")`\
| rex field=search "\"(?<savedsearch_name>.*)\""\
`comment("Extract the name of the search from the search string")`\
| table savedsearch_name count(search) usage user | join savedsearch_name max=0 type=left [search sourcetype="manifests" | spath searches{} | mvexpand searches{} | spath input=searches{} | table category search_name | rename search_name as savedsearch_name | dedup savedsearch_name] | search category=*
@@ -1,2 +0,0 @@
### Deprecated since ESCU UI was deprecated and this conf file is no longer in use
### Using one single file analyticstories.conf that will be used both by ES and ESCU
-373
View File
@@ -1,373 +0,0 @@
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-07-01T17:41:43 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
[workbench_panel_all_backup_logs_for_host___response_task]
label = Workbench - All backup logs for host
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_all_backup_logs_for_host___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task]
label = Workbench - Amazon EKS Kubernetes activity by src ip
type = link
fields = src_ip
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task]
label = Workbench - AWS Investigate Security Hub alerts by dest
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_aws_investigate_user_activities_by_accesskeyid___response_task]
label = Workbench - AWS Investigate User Activities By AccessKeyId
type = link
fields = accessKeyId
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_investigate_user_activities_by_accesskeyid___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_aws_investigate_user_activities_by_arn___response_task]
label = Workbench - AWS Investigate User Activities By ARN
type = link
fields = user
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_aws_investigate_user_activities_by_arn___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_aws_network_acl_details_from_id___response_task]
label = Workbench - AWS Network ACL Details from ID
type = link
fields = networkAclId
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_network_acl_details_from_id___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_aws_network_interface_details_via_resourceid___response_task]
label = Workbench - AWS Network Interface details via resourceId
type = link
fields = resourceId
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_network_interface_details_via_resourceid___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_aws_s3_bucket_details_via_bucketname___response_task]
label = Workbench - AWS S3 Bucket details via bucketName
type = link
fields = bucketName
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_s3_bucket_details_via_bucketname___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task]
label = Workbench - GCP Kubernetes activity by src ip
type = link
fields = src_ip
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_all_aws_activity_from_city___response_task]
label = Workbench - Get All AWS Activity From City
type = link
fields = City
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_all_aws_activity_from_city___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_all_aws_activity_from_country___response_task]
label = Workbench - Get All AWS Activity From Country
type = link
fields = Country
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_all_aws_activity_from_country___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_all_aws_activity_from_ip_address___response_task]
label = Workbench - Get All AWS Activity From IP Address
type = link
fields = src_ip
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_all_aws_activity_from_ip_address___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_all_aws_activity_from_region___response_task]
label = Workbench - Get All AWS Activity From Region
type = link
fields = Region
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_all_aws_activity_from_region___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_backup_logs_for_endpoint___response_task]
label = Workbench - Get Backup Logs For Endpoint
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_backup_logs_for_endpoint___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_certificate_logs_for_a_domain___response_task]
label = Workbench - Get Certificate logs for a domain
type = link
fields = domain
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_certificate_logs_for_a_domain___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_dns_server_history_for_a_host___response_task]
label = Workbench - Get DNS Server History for a host
type = link
fields = src_ip
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_dns_server_history_for_a_host___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_dns_traffic_ratio___response_task]
label = Workbench - Get DNS traffic ratio
type = link
fields = src_ip
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_dns_traffic_ratio___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_ec2_instance_details_by_instanceid___response_task]
label = Workbench - Get EC2 Instance Details by instanceId
type = link
fields = instanceId
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_ec2_instance_details_by_instanceid___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_ec2_launch_details___response_task]
label = Workbench - Get EC2 Launch Details
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_ec2_launch_details___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_email_info___response_task]
label = Workbench - Get Email Info
type = link
fields = message_id
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_email_info___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_emails_from_specific_sender___response_task]
label = Workbench - Get Emails From Specific Sender
type = link
fields = src_user
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_emails_from_specific_sender___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_first_occurrence_and_last_occurrence_of_a_mac_address___response_task]
label = Workbench - Get First Occurrence and Last Occurrence of a MAC Address
type = link
fields = src_mac
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_first_occurrence_and_last_occurrence_of_a_mac_address___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_history_of_email_sources___response_task]
label = Workbench - Get History Of Email Sources
type = link
fields = src
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_history_of_email_sources___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_logon_rights_modifications_for_endpoint___response_task]
label = Workbench - Get Logon Rights Modifications For Endpoint
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_logon_rights_modifications_for_endpoint___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_logon_rights_modifications_for_user___response_task]
label = Workbench - Get Logon Rights Modifications For User
type = link
fields = user
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_get_logon_rights_modifications_for_user___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_notable_history___response_task]
label = Workbench - Get Notable History
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_notable_history___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_process_responsible_for_the_dns_traffic___response_task]
label = Workbench - Get Process Responsible For The DNS Traffic
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_process_responsible_for_the_dns_traffic___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_sysmon_wmi_activity_for_host___response_task]
label = Workbench - Get Sysmon WMI Activity for Host
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_sysmon_wmi_activity_for_host___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_get_web_session_information_via_session_id___response_task]
label = Workbench - Get Web Session Information via session id
type = link
fields = session_id
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_web_session_information_via_session_id___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_aws_activities_via_region_name___response_task]
label = Workbench - Investigate AWS activities via region name
type = link
fields = vendor_region
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_aws_activities_via_region_name___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_aws_user_activities_by_user_field___response_task]
label = Workbench - Investigate AWS User Activities by user field
type = link
fields = user
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_investigate_aws_user_activities_by_user_field___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task]
label = Workbench - Investigate Failed Logins for Multiple Destinations
type = link
fields = user
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_network_traffic_from_src_ip___response_task]
label = Workbench - Investigate Network Traffic From src ip
type = link
fields = src_ip
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_network_traffic_from_src_ip___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_okta_activity_by_app___response_task]
label = Workbench - Investigate Okta Activity by app
type = link
fields = app
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_okta_activity_by_app___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_pass_the_hash_attempts___response_task]
label = Workbench - Investigate Pass the Hash Attempts
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_pass_the_hash_attempts___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_pass_the_ticket_attempts___response_task]
label = Workbench - Investigate Pass the Ticket Attempts
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_pass_the_ticket_attempts___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_previous_unseen_user___response_task]
label = Workbench - Investigate Previous Unseen User
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_previous_unseen_user___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_successful_remote_desktop_authentications___response_task]
label = Workbench - Investigate Successful Remote Desktop Authentications
type = link
fields = dest
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_successful_remote_desktop_authentications___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_user_activities_in_okta___response_task]
label = Workbench - Investigate User Activities In Okta
type = link
fields = user
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_investigate_user_activities_in_okta___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
[workbench_panel_investigate_web_posts_from_src___response_task]
label = Workbench - Investigate Web POSTs From src
type = link
fields = src
display_location = field_menu
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_web_posts_from_src___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
link.target = blank
link.method = get
-39
View File
@@ -1,39 +0,0 @@
domain,isIOC,Description
akamaicontainer.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
akamaitechcloudservices.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
azuredeploystore.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
azureonlinecloud.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
azureonlinestorage.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
dunamistrd.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
glcloudservice.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
journalide.org,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
msedgepackageinfo.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
msstorageazure.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
msstorageboxes.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
officeaddons.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
officestoragebox.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
pbxcloudeservices.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
pbxphonenetwork.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
pbxsources.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
qwepoi123098.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
sbmsa.wiki,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
sourceslabs.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
visualstudiofactory.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
zacharryblogs.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
www.3cx.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
akamaitechcloudservices.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
azureonlinestorage.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
msedgepackageinfo.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
glcloudservice.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
pbxsources.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
msstorageazure.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
officestoragebox.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
visualstudiofactory.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
azuredeploystore.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
msstorageboxes.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
officeaddons.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
sourceslabs.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
zacharryblogs.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
pbxcloudeservices.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
pbxphonenetwork.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
msedgeupdate.net,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
1 domain isIOC Description
2 akamaicontainer.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
3 akamaitechcloudservices.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
4 azuredeploystore.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
5 azureonlinecloud.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
6 azureonlinestorage.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
7 dunamistrd.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
8 glcloudservice.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
9 journalide.org TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
10 msedgepackageinfo.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
11 msstorageazure.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
12 msstorageboxes.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
13 officeaddons.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
14 officestoragebox.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
15 pbxcloudeservices.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
16 pbxphonenetwork.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
17 pbxsources.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
18 qwepoi123098.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
19 sbmsa.wiki TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
20 sourceslabs.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
21 visualstudiofactory.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
22 zacharryblogs.com TRUE https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
23 www.3cx.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
24 akamaitechcloudservices.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
25 azureonlinestorage.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
26 msedgepackageinfo.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
27 glcloudservice.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
28 pbxsources.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
29 msstorageazure.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
30 officestoragebox.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
31 visualstudiofactory.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
32 azuredeploystore.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
33 msstorageboxes.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
34 officeaddons.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
35 sourceslabs.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
36 zacharryblogs.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
37 pbxcloudeservices.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
38 pbxphonenetwork.com TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
39 msedgeupdate.net TRUE https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
@@ -1,2 +0,0 @@
algo,model,options
MLTKContainer,"{""__mlspl_type"": [""mltkc.MLTKContainer"", ""MLTKContainer""], ""dict"": {""endpoint_url"": ""https://localhost:62645"", ""out_params"": {""params"": {""mode"": ""stage"", ""algo"": ""detect_dns_data_exfiltration_using_pretrained_model_in_dsdl""}, ""args"": [""is_exfiltration"", ""src"", ""query"", ""rank""], ""target_variable"": [""is_exfiltration""], ""feature_variables"": [""src"", ""query"", ""rank""], ""model_name"": ""detect_dns_data_exfiltration_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}, ""feature_variables"": [""src"", ""query"", ""rank""], ""target_variable"": ""is_exfiltration""}}","{""params"": {""mode"": ""stage"", ""algo"": ""detect_dns_data_exfiltration_using_pretrained_model_in_dsdl""}, ""args"": [""is_exfiltration"", ""src"", ""query"", ""rank""], ""target_variable"": [""is_exfiltration""], ""feature_variables"": [""src"", ""query"", ""rank""], ""model_name"": ""detect_dns_data_exfiltration_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
@@ -1,2 +0,0 @@
algo,model,options
MLTKContainer,"{""__mlspl_type"": [""mltkc.MLTKContainer"", ""MLTKContainer""], ""dict"": {""endpoint_url"": ""https://localhost:54270"", ""out_params"": {""params"": {""mode"": ""stage"", ""algo"": ""detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl""}, ""args"": [""is_unknown"", ""text""], ""target_variable"": [""is_unknown""], ""feature_variables"": [""text""], ""model_name"": ""detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}, ""feature_variables"": [""text""], ""target_variable"": ""is_unknown""}}","{""params"": {""mode"": ""stage"", ""algo"": ""detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl""}, ""args"": [""is_unknown"", ""text""], ""target_variable"": [""is_unknown""], ""feature_variables"": [""text""], ""model_name"": ""detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
@@ -1,2 +0,0 @@
algo,model,options
MLTKContainer,"{""__mlspl_type"": [""mltkc.MLTKContainer"", ""MLTKContainer""], ""dict"": {""endpoint_url"": ""https://localhost:58216"", ""out_params"": {""params"": {""mode"": ""stage"", ""algo"": ""detect_suspicious_processnames_using_pretrained_model_in_dsdl""}, ""args"": [""label"", ""text""], ""target_variable"": [""label""], ""feature_variables"": [""text""], ""model_name"": ""detect_suspicious_processnames_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}, ""feature_variables"": [""text""], ""target_variable"": ""label""}}","{""params"": {""mode"": ""stage"", ""algo"": ""detect_suspicious_processnames_using_pretrained_model_in_dsdl""}, ""args"": [""label"", ""text""], ""target_variable"": [""label""], ""feature_variables"": [""text""], ""model_name"": ""detect_suspicious_processnames_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
@@ -1,2 +0,0 @@
algo,model,options
MLTKContainer,"{""__mlspl_type"": [""mltkc.MLTKContainer"", ""MLTKContainer""], ""dict"": {""endpoint_url"": ""https://localhost:53378"", ""out_params"": {""params"": {""mode"": ""stage"", ""algo"": ""pretrained_dga_model_dsdl""}, ""args"": [""is_dga"", ""domain""], ""target_variable"": [""is_dga""], ""feature_variables"": [""domain""], ""model_name"": ""pretrained_dga_model_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}, ""feature_variables"": [""domain""], ""target_variable"": ""is_dga""}}","{""params"": {""mode"": ""stage"", ""algo"": ""pretrained_dga_model_dsdl""}, ""args"": [""is_dga"", ""domain""], ""target_variable"": [""is_dga""], ""feature_variables"": [""domain""], ""model_name"": ""pretrained_dga_model_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
@@ -1,2 +0,0 @@
algo,model,options
DetectRiskySPL,"{""__mlspl_type"": [""algos.DetectRiskySPL"", ""DetectRiskySPL""], ""dict"": {""classes"": null, ""target_variable"": [""risk_score""], ""feature_variables"": [""spl_text""], ""columns"": [""spl_text""], ""estimator"": {""__mlspl_type"": [""sklearn.pipeline"", ""Pipeline""], ""dict"": {""steps"": [[""features"", {""__mlspl_type"": [""sklearn.feature_extraction.text"", ""CountVectorizer""], ""dict"": {""input"": ""content"", ""encoding"": ""utf-8"", ""decode_error"": ""strict"", ""strip_accents"": null, ""preprocessor"": null, ""tokenizer"": null, ""analyzer"": ""word"", ""lowercase"": true, ""token_pattern"": "" collect | delete | fit | outputcsv | outputlookup |adhoc| sendalert | sendemail |splunk\\-system\\-user| tscollect | run | script | runshellscript "", ""stop_words"": null, ""max_df"": 1.0, ""min_df"": 1, ""max_features"": null, ""ngram_range"": [1, 1], ""vocabulary"": null, ""binary"": false, ""dtype"": {""__mlspl_type"": [""builtins"", ""type""], ""type"": [""numpy"", ""int64""]}, ""fixed_vocabulary_"": false, ""_stop_words_id"": 94300723879360, ""stop_words_"": {""__mlspl_type"": [""builtins"", ""set""], ""set"": []}, ""vocabulary_"": {""splunk-system-user"": 12, "" delete "": 1, ""adhoc"": 11, "" outputlookup "": 4, "" script "": 7, "" run "": 5, "" collect "": 0, "" sendemail "": 9, "" sendalert "": 8, "" outputcsv "": 3, "" fit "": 2, "" runshellscript "": 6, "" tscollect "": 10}}}], [""predictor"", {""__mlspl_type"": [""sklearn.linear_model._logistic"", ""LogisticRegression""], ""dict"": {""penalty"": ""l2"", ""dual"": false, ""tol"": 0.0001, ""C"": 1.0, ""fit_intercept"": true, ""intercept_scaling"": 1, ""class_weight"": {""0"": 1, ""1"": 10}, ""random_state"": null, ""solver"": ""liblinear"", ""max_iter"": 100, ""multi_class"": ""auto"", ""verbose"": 0, ""warm_start"": false, ""n_jobs"": null, ""l1_ratio"": null, ""n_features_in_"": 13, ""classes_"": {""__mlspl_type"": [""numpy"", ""ndarray""], ""npy"": ""k05VTVBZAQB2AHsnZGVzY3InOiAnPGk4JywgJ2ZvcnRyYW5fb3JkZXInOiBGYWxzZSwgJ3NoYXBlJzogKDIsKSwgfSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAoAAAAAAAAAAAEAAAAAAAAA""}, ""coef_"": {""__mlspl_type"": [""numpy"", ""ndarray""], ""npy"": ""k05VTVBZAQB2AHsnZGVzY3InOiAnPGY4JywgJ2ZvcnRyYW5fb3JkZXInOiBGYWxzZSwgJ3NoYXBlJzogKDEsIDEzKSwgfSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAqulbT8VG8TQJU6VfC9QuY/kCCmapJVFUDQl14TS2ApPw5vYc32jBxAxVuQ3Sv35D8Y+azG/kDmP9vpUE0rTwlALsMVcoUGE0ASjjFaKyMaQA2zZ/yMQRZAQLZHc97OHEAfrzTDBGwSwA==""}, ""intercept_"": {""__mlspl_type"": [""numpy"", ""ndarray""], ""npy"": ""k05VTVBZAQB2AHsnZGVzY3InOiAnPGY4JywgJ2ZvcnRyYW5fb3JkZXInOiBGYWxzZSwgJ3NoYXBlJzogKDEsKSwgfSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAqBnhyKtBckwA==""}, ""n_iter_"": {""__mlspl_type"": [""numpy"", ""ndarray""], ""npy"": ""k05VTVBZAQB2AHsnZGVzY3InOiAnPGk0JywgJ2ZvcnRyYW5fb3JkZXInOiBGYWxzZSwgJ3NoYXBlJzogKDEsKSwgfSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAoLAAAA""}}}]], ""memory"": null, ""verbose"": false}}}}","{""args"": [""risk_score"", ""spl_text""], ""target_variable"": [""risk_score""], ""feature_variables"": [""spl_text""], ""model_name"": ""risky_spl_pre_trained_model"", ""algo_name"": ""LogisticRegression"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""1024"", ""max_model_size_mb"": ""15"", ""max_score_time"": ""600"", ""streaming_apply"": ""false"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
File diff suppressed because one or more lines are too long
@@ -1,69 +0,0 @@
Category,SubCategory,GUID
System,,{69979848-797A-11D9-BED3-505054503030}
System,Security State Change,{0CCE9210-69AE-11D9-BED3-505054503030}
System,Security System Extension,{0CCE9211-69AE-11D9-BED3-505054503030}
System,System Integrity,{0CCE9212-69AE-11D9-BED3-505054503030}
System,IPsec Driver,{0CCE9213-69AE-11D9-BED3-505054503030}
System,Other System Events,{0CCE9214-69AE-11D9-BED3-505054503030}
Logon/Logoff,,{69979849-797A-11D9-BED3-505054503030}
Logon/Logoff,Logon,{0CCE9215-69AE-11D9-BED3-505054503030}
Logon/Logoff,Logoff,{0CCE9216-69AE-11D9-BED3-505054503030}
Logon/Logoff,Account Lockout,{0CCE9217-69AE-11D9-BED3-505054503030}
Logon/Logoff,IPsec Main Mode,{0CCE9218-69AE-11D9-BED3-505054503030}
Logon/Logoff,IPsec Quick Mode,{0CCE9219-69AE-11D9-BED3-505054503030}
Logon/Logoff,IPsec Extended Mode,{0CCE921A-69AE-11D9-BED3-505054503030}
Logon/Logoff,Special Logon,{0CCE921B-69AE-11D9-BED3-505054503030}
Logon/Logoff,Other Logon/Logoff Events,{0CCE921C-69AE-11D9-BED3-505054503030}
Logon/Logoff,Network Policy Server,{0CCE9243-69AE-11D9-BED3-505054503030}
Logon/Logoff,User / Device Claims,{0CCE9247-69AE-11D9-BED3-505054503030}
Logon/Logoff,Group Membership,{0CCE9249-69AE-11D9-BED3-505054503030}
Object Access,,{6997984A-797A-11D9-BED3-505054503030}
Object Access,File System,{0CCE921D-69AE-11D9-BED3-505054503030}
Object Access,Registry,{0CCE921E-69AE-11D9-BED3-505054503030}
Object Access,Kernel Object,{0CCE921F-69AE-11D9-BED3-505054503030}
Object Access,SAM,{0CCE9220-69AE-11D9-BED3-505054503030}
Object Access,Certification Services,{0CCE9221-69AE-11D9-BED3-505054503030}
Object Access,Application Generated,{0CCE9222-69AE-11D9-BED3-505054503030}
Object Access,Handle Manipulation,{0CCE9223-69AE-11D9-BED3-505054503030}
Object Access,File Share,{0CCE9224-69AE-11D9-BED3-505054503030}
Object Access,Filtering Platform Packet Drop,{0CCE9225-69AE-11D9-BED3-505054503030}
Object Access,Filtering Platform Connection,{0CCE9226-69AE-11D9-BED3-505054503030}
Object Access,Other Object Access Events,{0CCE9227-69AE-11D9-BED3-505054503030}
Object Access,Detailed File Share,{0CCE9244-69AE-11D9-BED3-505054503030}
Object Access,Removable Storage,{0CCE9245-69AE-11D9-BED3-505054503030}
Object Access,Central Policy Staging,{0CCE9246-69AE-11D9-BED3-505054503030}
Privilege Use,,{6997984B-797A-11D9-BED3-505054503030}
Privilege Use,Sensitive Privilege Use,{0CCE9228-69AE-11D9-BED3-505054503030}
Privilege Use,Non Sensitive Privilege Use,{0CCE9229-69AE-11D9-BED3-505054503030}
Privilege Use,Other Privilege Use Events,{0CCE922A-69AE-11D9-BED3-505054503030}
Detailed Tracking,,{6997984C-797A-11D9-BED3-505054503030}
Detailed Tracking,Process Creation,{0CCE922B-69AE-11D9-BED3-505054503030}
Detailed Tracking,Process Termination,{0CCE922C-69AE-11D9-BED3-505054503030}
Detailed Tracking,DPAPI Activity,{0CCE922D-69AE-11D9-BED3-505054503030}
Detailed Tracking,RPC Events,{0CCE922E-69AE-11D9-BED3-505054503030}
Detailed Tracking,Plug and Play Events,{0CCE9248-69AE-11D9-BED3-505054503030}
Detailed Tracking,Token Right Adjusted Events,{0CCE924A-69AE-11D9-BED3-505054503030}
Policy Change,,{6997984D-797A-11D9-BED3-505054503030}
Policy Change,Audit Policy Change,{0CCE922F-69AE-11D9-BED3-505054503030}
Policy Change,Authentication Policy Change,{0CCE9230-69AE-11D9-BED3-505054503030}
Policy Change,Authorization Policy Change,{0CCE9231-69AE-11D9-BED3-505054503030}
Policy Change,MPSSVC Rule-Level Policy Change,{0CCE9232-69AE-11D9-BED3-505054503030}
Policy Change,Filtering Platform Policy Change,{0CCE9233-69AE-11D9-BED3-505054503030}
Policy Change,Other Policy Change Events,{0CCE9234-69AE-11D9-BED3-505054503030}
Account Management,,{6997984E-797A-11D9-BED3-505054503030}
Account Management,User Account Management,{0CCE9235-69AE-11D9-BED3-505054503030}
Account Management,Computer Account Management,{0CCE9236-69AE-11D9-BED3-505054503030}
Account Management,Security Group Management,{0CCE9237-69AE-11D9-BED3-505054503030}
Account Management,Distribution Group Management,{0CCE9238-69AE-11D9-BED3-505054503030}
Account Management,Application Group Management,{0CCE9239-69AE-11D9-BED3-505054503030}
Account Management,Other Account Management Events,{0CCE923A-69AE-11D9-BED3-505054503030}
DS Access,,{6997984F-797A-11D9-BED3-505054503030}
DS Access,Directory Service Access,{0CCE923B-69AE-11D9-BED3-505054503030}
DS Access,Directory Service Changes,{0CCE923C-69AE-11D9-BED3-505054503030}
DS Access,Directory Service Replication,{0CCE923D-69AE-11D9-BED3-505054503030}
DS Access,Detailed Directory Service Replication,{0CCE923E-69AE-11D9-BED3-505054503030}
Account Logon,,{69979850-797A-11D9-BED3-505054503030}
Account Logon,Credential Validation,{0CCE923F-69AE-11D9-BED3-505054503030}
Account Logon,Kerberos Service Ticket Operations,{0CCE9240-69AE-11D9-BED3-505054503030}
Account Logon,Other Account Logon Events,{0CCE9241-69AE-11D9-BED3-505054503030}
Account Logon,Kerberos Authentication Service,{0CCE9242-69AE-11D9-BED3-505054503030}
1 Category SubCategory GUID
2 System {69979848-797A-11D9-BED3-505054503030}
3 System Security State Change {0CCE9210-69AE-11D9-BED3-505054503030}
4 System Security System Extension {0CCE9211-69AE-11D9-BED3-505054503030}
5 System System Integrity {0CCE9212-69AE-11D9-BED3-505054503030}
6 System IPsec Driver {0CCE9213-69AE-11D9-BED3-505054503030}
7 System Other System Events {0CCE9214-69AE-11D9-BED3-505054503030}
8 Logon/Logoff {69979849-797A-11D9-BED3-505054503030}
9 Logon/Logoff Logon {0CCE9215-69AE-11D9-BED3-505054503030}
10 Logon/Logoff Logoff {0CCE9216-69AE-11D9-BED3-505054503030}
11 Logon/Logoff Account Lockout {0CCE9217-69AE-11D9-BED3-505054503030}
12 Logon/Logoff IPsec Main Mode {0CCE9218-69AE-11D9-BED3-505054503030}
13 Logon/Logoff IPsec Quick Mode {0CCE9219-69AE-11D9-BED3-505054503030}
14 Logon/Logoff IPsec Extended Mode {0CCE921A-69AE-11D9-BED3-505054503030}
15 Logon/Logoff Special Logon {0CCE921B-69AE-11D9-BED3-505054503030}
16 Logon/Logoff Other Logon/Logoff Events {0CCE921C-69AE-11D9-BED3-505054503030}
17 Logon/Logoff Network Policy Server {0CCE9243-69AE-11D9-BED3-505054503030}
18 Logon/Logoff User / Device Claims {0CCE9247-69AE-11D9-BED3-505054503030}
19 Logon/Logoff Group Membership {0CCE9249-69AE-11D9-BED3-505054503030}
20 Object Access {6997984A-797A-11D9-BED3-505054503030}
21 Object Access File System {0CCE921D-69AE-11D9-BED3-505054503030}
22 Object Access Registry {0CCE921E-69AE-11D9-BED3-505054503030}
23 Object Access Kernel Object {0CCE921F-69AE-11D9-BED3-505054503030}
24 Object Access SAM {0CCE9220-69AE-11D9-BED3-505054503030}
25 Object Access Certification Services {0CCE9221-69AE-11D9-BED3-505054503030}
26 Object Access Application Generated {0CCE9222-69AE-11D9-BED3-505054503030}
27 Object Access Handle Manipulation {0CCE9223-69AE-11D9-BED3-505054503030}
28 Object Access File Share {0CCE9224-69AE-11D9-BED3-505054503030}
29 Object Access Filtering Platform Packet Drop {0CCE9225-69AE-11D9-BED3-505054503030}
30 Object Access Filtering Platform Connection {0CCE9226-69AE-11D9-BED3-505054503030}
31 Object Access Other Object Access Events {0CCE9227-69AE-11D9-BED3-505054503030}
32 Object Access Detailed File Share {0CCE9244-69AE-11D9-BED3-505054503030}
33 Object Access Removable Storage {0CCE9245-69AE-11D9-BED3-505054503030}
34 Object Access Central Policy Staging {0CCE9246-69AE-11D9-BED3-505054503030}
35 Privilege Use {6997984B-797A-11D9-BED3-505054503030}
36 Privilege Use Sensitive Privilege Use {0CCE9228-69AE-11D9-BED3-505054503030}
37 Privilege Use Non Sensitive Privilege Use {0CCE9229-69AE-11D9-BED3-505054503030}
38 Privilege Use Other Privilege Use Events {0CCE922A-69AE-11D9-BED3-505054503030}
39 Detailed Tracking {6997984C-797A-11D9-BED3-505054503030}
40 Detailed Tracking Process Creation {0CCE922B-69AE-11D9-BED3-505054503030}
41 Detailed Tracking Process Termination {0CCE922C-69AE-11D9-BED3-505054503030}
42 Detailed Tracking DPAPI Activity {0CCE922D-69AE-11D9-BED3-505054503030}
43 Detailed Tracking RPC Events {0CCE922E-69AE-11D9-BED3-505054503030}
44 Detailed Tracking Plug and Play Events {0CCE9248-69AE-11D9-BED3-505054503030}
45 Detailed Tracking Token Right Adjusted Events {0CCE924A-69AE-11D9-BED3-505054503030}
46 Policy Change {6997984D-797A-11D9-BED3-505054503030}
47 Policy Change Audit Policy Change {0CCE922F-69AE-11D9-BED3-505054503030}
48 Policy Change Authentication Policy Change {0CCE9230-69AE-11D9-BED3-505054503030}
49 Policy Change Authorization Policy Change {0CCE9231-69AE-11D9-BED3-505054503030}
50 Policy Change MPSSVC Rule-Level Policy Change {0CCE9232-69AE-11D9-BED3-505054503030}
51 Policy Change Filtering Platform Policy Change {0CCE9233-69AE-11D9-BED3-505054503030}
52 Policy Change Other Policy Change Events {0CCE9234-69AE-11D9-BED3-505054503030}
53 Account Management {6997984E-797A-11D9-BED3-505054503030}
54 Account Management User Account Management {0CCE9235-69AE-11D9-BED3-505054503030}
55 Account Management Computer Account Management {0CCE9236-69AE-11D9-BED3-505054503030}
56 Account Management Security Group Management {0CCE9237-69AE-11D9-BED3-505054503030}
57 Account Management Distribution Group Management {0CCE9238-69AE-11D9-BED3-505054503030}
58 Account Management Application Group Management {0CCE9239-69AE-11D9-BED3-505054503030}
59 Account Management Other Account Management Events {0CCE923A-69AE-11D9-BED3-505054503030}
60 DS Access {6997984F-797A-11D9-BED3-505054503030}
61 DS Access Directory Service Access {0CCE923B-69AE-11D9-BED3-505054503030}
62 DS Access Directory Service Changes {0CCE923C-69AE-11D9-BED3-505054503030}
63 DS Access Directory Service Replication {0CCE923D-69AE-11D9-BED3-505054503030}
64 DS Access Detailed Directory Service Replication {0CCE923E-69AE-11D9-BED3-505054503030}
65 Account Logon {69979850-797A-11D9-BED3-505054503030}
66 Account Logon Credential Validation {0CCE923F-69AE-11D9-BED3-505054503030}
67 Account Logon Kerberos Service Ticket Operations {0CCE9240-69AE-11D9-BED3-505054503030}
68 Account Logon Other Account Logon Events {0CCE9241-69AE-11D9-BED3-505054503030}
69 Account Logon Kerberos Authentication Service {0CCE9242-69AE-11D9-BED3-505054503030}
@@ -1,30 +0,0 @@
EventCode, Description
8000, AppID policy conversion failed. Status * <%1> * Indicates that the policy wasn't applied correctly to the computer. The status message is provided for troubleshooting purposes.
8001, The AppLocker policy was applied successfully to this computer. Indicates that the AppLocker policy was successfully applied to the computer.
8002, *<File name> * was allowed to run. Indicates an AppLocker rule allowed the .exe or .dll file.
8003, *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Shown only when the Audit only enforcement mode is enabled. Indicates that the AppLocker policy would block the .exe or .dll file if the enforcement mode setting was Enforce rules.
8004, *<File name> * was prevented from running. AppLocker blocked the named EXE or DLL file. Shown only when the Enforce rules enforcement mode is enabled.
8005, *<File name> * was allowed to run. Indicates an AppLocker rule allowed the script or .msi file.
8006, *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Shown only when the Audit only enforcement mode is enabled. Indicates that the AppLocker policy would block the script or .msi file if the Enforce rules enforcement mode was enabled.
8007, *<File name> * was prevented from running. AppLocker blocked the named Script or MSI. Shown only when the Enforce rules enforcement mode is enabled.
8008, *<File name> *: AppLocker component not available on this SKU. Indicates an edition of Windows that doesn't support AppLocker.
8020, *<File name> * was allowed to run. Added in Windows Server 2012 and Windows 8.
8021, *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Added in Windows Server 2012 and Windows 8.
8022, *<File name> * was prevented from running. Added in Windows Server 2012 and Windows 8.
8023, *<File name> * was allowed to be installed. Added in Windows Server 2012 and Windows 8.
8024, *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Added in Windows Server 2012 and Windows 8.
8025, *<File name> * was prevented from running. Added in Windows Server 2012 and Windows 8.
8027, No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured. Added in Windows Server 2012 and Windows 8.
8028, *<File name> * was allowed to run but would have been prevented if the Config CI policy were enforced. Added in Windows Server 2016 and Windows 10.
8029, *<File name> * was prevented from running due to Config CI policy. Added in Windows Server 2016 and Windows 10.
8030, ManagedInstaller check SUCCEEDED during Appid verification of * Added in Windows Server 2016 and Windows 10.
8031, SmartlockerFilter detected file * being written by process * Added in Windows Server 2016 and Windows 10.
8032, ManagedInstaller check FAILED during Appid verification of * Added in Windows Server 2016 and Windows 10.
8033, ManagedInstaller check FAILED during Appid verification of * . Allowed to run due to Audit AppLocker Policy. Added in Windows Server 2016 and Windows 10.
8034, ManagedInstaller Script check FAILED during Appid verification of * Added in Windows Server 2016 and Windows 10.
8035, ManagedInstaller Script check SUCCEEDED during Appid verification of * Added in Windows Server 2016 and Windows 10.
8036, * was prevented from running due to Config CI policy Added in Windows Server 2016 and Windows 10.
8037, * passed Config CI policy and was allowed to run. Added in Windows Server 2016 and Windows 10.
8038, Publisher info: Subject: * Issuer: * Signature index * (* total) Added in Windows Server 2016 and Windows 10.
8039, Package family name * version * was allowed to install or update but would have been prevented if the Config CI policy Added in Windows Server 2016 and Windows 10.
8040, Package family name * version * was prevented from installing or updating due to Config CI policy Added in Windows Server 2016 and Windows 10.
1 EventCode Description
2 8000 AppID policy conversion failed. Status * <%1> * Indicates that the policy wasn't applied correctly to the computer. The status message is provided for troubleshooting purposes.
3 8001 The AppLocker policy was applied successfully to this computer. Indicates that the AppLocker policy was successfully applied to the computer.
4 8002 *<File name> * was allowed to run. Indicates an AppLocker rule allowed the .exe or .dll file.
5 8003 *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Shown only when the Audit only enforcement mode is enabled. Indicates that the AppLocker policy would block the .exe or .dll file if the enforcement mode setting was Enforce rules.
6 8004 *<File name> * was prevented from running. AppLocker blocked the named EXE or DLL file. Shown only when the Enforce rules enforcement mode is enabled.
7 8005 *<File name> * was allowed to run. Indicates an AppLocker rule allowed the script or .msi file.
8 8006 *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Shown only when the Audit only enforcement mode is enabled. Indicates that the AppLocker policy would block the script or .msi file if the Enforce rules enforcement mode was enabled.
9 8007 *<File name> * was prevented from running. AppLocker blocked the named Script or MSI. Shown only when the Enforce rules enforcement mode is enabled.
10 8008 *<File name> *: AppLocker component not available on this SKU. Indicates an edition of Windows that doesn't support AppLocker.
11 8020 *<File name> * was allowed to run. Added in Windows Server 2012 and Windows 8.
12 8021 *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Added in Windows Server 2012 and Windows 8.
13 8022 *<File name> * was prevented from running. Added in Windows Server 2012 and Windows 8.
14 8023 *<File name> * was allowed to be installed. Added in Windows Server 2012 and Windows 8.
15 8024 *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Added in Windows Server 2012 and Windows 8.
16 8025 *<File name> * was prevented from running. Added in Windows Server 2012 and Windows 8.
17 8027 No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured. Added in Windows Server 2012 and Windows 8.
18 8028 *<File name> * was allowed to run but would have been prevented if the Config CI policy were enforced. Added in Windows Server 2016 and Windows 10.
19 8029 *<File name> * was prevented from running due to Config CI policy. Added in Windows Server 2016 and Windows 10.
20 8030 ManagedInstaller check SUCCEEDED during Appid verification of * Added in Windows Server 2016 and Windows 10.
21 8031 SmartlockerFilter detected file * being written by process * Added in Windows Server 2016 and Windows 10.
22 8032 ManagedInstaller check FAILED during Appid verification of * Added in Windows Server 2016 and Windows 10.
23 8033 ManagedInstaller check FAILED during Appid verification of * . Allowed to run due to Audit AppLocker Policy. Added in Windows Server 2016 and Windows 10.
24 8034 ManagedInstaller Script check FAILED during Appid verification of * Added in Windows Server 2016 and Windows 10.
25 8035 ManagedInstaller Script check SUCCEEDED during Appid verification of * Added in Windows Server 2016 and Windows 10.
26 8036 * was prevented from running due to Config CI policy Added in Windows Server 2016 and Windows 10.
27 8037 * passed Config CI policy and was allowed to run. Added in Windows Server 2016 and Windows 10.
28 8038 Publisher info: Subject: * Issuer: * Signature index * (* total) Added in Windows Server 2016 and Windows 10.
29 8039 Package family name * version * was allowed to install or update but would have been prevented if the Config CI policy Added in Windows Server 2016 and Windows 10.
30 8040 Package family name * version * was prevented from installing or updating due to Config CI policy Added in Windows Server 2016 and Windows 10.
-18
View File
@@ -1,18 +0,0 @@
ID,ASR_Rule
56A863A9-875E-4185-98A7-B882C64B5CE5,Block abuse of exploited vulnerable signed drivers
7674BA52-37EB-4A4F-A9A1-F0F9A1619A2C,Block Adobe Reader from creating child processes
D4F940AB-401B-4EFC-AADC-AD5F3C50688A,Block all Office applications from creating child processes
9E6C4E1F-7D60-472F-BA1A-A39EF669E4B2,Block credential stealing from the Windows local security authority subsystem (lsass.exe)
BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550,Block executable content from email client and webmail
01443614-CD74-433A-B99E-2ECDC07BFC25,Block executable files from running unless they meet a prevalence - age - or trusted list criterion
5BEB7EFE-FD9A-4556-801D-275E5FFC04CC,Block execution of potentially obfuscated scripts
D3E037E1-3EB8-44C8-A917-57927947596D,Block JavaScript or VBScript from launching downloaded executable content
3B576869-A4EC-4529-8536-B80A7769E899,Block Office applications from creating executable content
75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84,Block Office applications from injecting code into other processes
26190899-1602-49E8-8B27-EB1D0A1CE869,Block Office communication application from creating child processes
E6DB77E5-3DF2-4CF1-B95A-636979351E5B,Block persistence through WMI event subscription
D1E49AAC-8F56-4280-B9BA-993A6D77406C,Block process creations originating from PSExec and WMI commands
B2B3F03D-6A65-4F7B-A9C7-1C7EF74A9BA4,Block untrusted and unsigned processes that run from USB
92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B,Block Win32 API calls from Office macros
C1DB55AB-C21A-4637-BB3F-A12568109D35,Use advanced protection against ransomware
A8F5898E-1DC8-49A9-9878-85004B8A61E6,Block Webshell creation for Servers
1 ID ASR_Rule
2 56A863A9-875E-4185-98A7-B882C64B5CE5 Block abuse of exploited vulnerable signed drivers
3 7674BA52-37EB-4A4F-A9A1-F0F9A1619A2C Block Adobe Reader from creating child processes
4 D4F940AB-401B-4EFC-AADC-AD5F3C50688A Block all Office applications from creating child processes
5 9E6C4E1F-7D60-472F-BA1A-A39EF669E4B2 Block credential stealing from the Windows local security authority subsystem (lsass.exe)
6 BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550 Block executable content from email client and webmail
7 01443614-CD74-433A-B99E-2ECDC07BFC25 Block executable files from running unless they meet a prevalence - age - or trusted list criterion
8 5BEB7EFE-FD9A-4556-801D-275E5FFC04CC Block execution of potentially obfuscated scripts
9 D3E037E1-3EB8-44C8-A917-57927947596D Block JavaScript or VBScript from launching downloaded executable content
10 3B576869-A4EC-4529-8536-B80A7769E899 Block Office applications from creating executable content
11 75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84 Block Office applications from injecting code into other processes
12 26190899-1602-49E8-8B27-EB1D0A1CE869 Block Office communication application from creating child processes
13 E6DB77E5-3DF2-4CF1-B95A-636979351E5B Block persistence through WMI event subscription
14 D1E49AAC-8F56-4280-B9BA-993A6D77406C Block process creations originating from PSExec and WMI commands
15 B2B3F03D-6A65-4F7B-A9C7-1C7EF74A9BA4 Block untrusted and unsigned processes that run from USB
16 92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B Block Win32 API calls from Office macros
17 C1DB55AB-C21A-4637-BB3F-A12568109D35 Use advanced protection against ransomware
18 A8F5898E-1DC8-49A9-9878-85004B8A61E6 Block Webshell creation for Servers
-31
View File
@@ -1,31 +0,0 @@
attacker_tool_names,description
remcom.exe,This process is an open source replacement to psexec and is not typically seen in an enterprise environment.
pwdump.exe,This process is associated with a tool used to dump password hashes on a Windows system.
pwdump2.exe,This process is associated with a tool used to dump password hashes on a Windows system.
nc.exe,This process is an open source tool used for network communications.
wce.exe,This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks.
cain.exe,This process is associated with a tool used to collect user credentials and execute attacks.
nmap.exe,This process is an open source network mapping tool used to identify hosts and listening services on a network.
kidlogger.exe,This process is associated with a tool used to collect keyboard input on a host.
isass.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
svch0st.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
at.exe,This process is used to schedule other processes to run. schtasks.exe should be used instead as it provides more flexibility.
getmail.exe,This process is seen to be used by attackers to extract email files from host machines.
ntdll.exe,This process was identified as malicious by DHS Alert TA18-074A.
netpass.exe,This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user.
WebBrowserPassView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers.
OutlookAddressBookView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook.
mailpv.exe,This process was identified by DHS Alert TA18-201A and attackers use this tool is a password-recovery tool that reveals the passwords and other account details from various email clients.
NLBrute.exe,A RDP brute force tool found in botnets for further expansion and and acquisition of targets. This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords.
selfdel.exe,This executable was delivered in the SamSam Ransomware Campain and the attackers levereged this binary to delete its malicilous activities.
masscan.exe,This executable was delivered in the XMRig Crypto Miner
Massscan_GUI.exe,This executable was delivered in the XMRig Crypto Miner
KPortScan3.exe,This executable was delivered in the XMRig Crypto Miner and is commonly used by attackers to scan the internet
NLAChecker.exe,A scanner tool that checks for Windows hosts for Network Level Authentication. This tool allows attackers to detect Windows Servers with RDP without NLA enabled which facilitates the use of brute force non microsoft rdp tools or exploits
ns.exe,A commonly used tool used by attackers to scan and map file shares
SilverBullet.exe,Malware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts.
kportscan3.exe, KPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks.
advanced_port_scanner.exe,Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports.
mimikatz.exe,utility Mimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets.
certify.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS)
certipy.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS)
1 attacker_tool_names description
2 remcom.exe This process is an open source replacement to psexec and is not typically seen in an enterprise environment.
3 pwdump.exe This process is associated with a tool used to dump password hashes on a Windows system.
4 pwdump2.exe This process is associated with a tool used to dump password hashes on a Windows system.
5 nc.exe This process is an open source tool used for network communications.
6 wce.exe This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks.
7 cain.exe This process is associated with a tool used to collect user credentials and execute attacks.
8 nmap.exe This process is an open source network mapping tool used to identify hosts and listening services on a network.
9 kidlogger.exe This process is associated with a tool used to collect keyboard input on a host.
10 isass.exe This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
11 svch0st.exe This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
12 at.exe This process is used to schedule other processes to run. schtasks.exe should be used instead as it provides more flexibility.
13 getmail.exe This process is seen to be used by attackers to extract email files from host machines.
14 ntdll.exe This process was identified as malicious by DHS Alert TA18-074A.
15 netpass.exe This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user.
16 WebBrowserPassView.exe This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers.
17 OutlookAddressBookView.exe This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook.
18 mailpv.exe This process was identified by DHS Alert TA18-201A and attackers use this tool is a password-recovery tool that reveals the passwords and other account details from various email clients.
19 NLBrute.exe A RDP brute force tool found in botnets for further expansion and and acquisition of targets. This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords.
20 selfdel.exe This executable was delivered in the SamSam Ransomware Campain and the attackers levereged this binary to delete its malicilous activities.
21 masscan.exe This executable was delivered in the XMRig Crypto Miner
22 Massscan_GUI.exe This executable was delivered in the XMRig Crypto Miner
23 KPortScan3.exe This executable was delivered in the XMRig Crypto Miner and is commonly used by attackers to scan the internet
24 NLAChecker.exe A scanner tool that checks for Windows hosts for Network Level Authentication. This tool allows attackers to detect Windows Servers with RDP without NLA enabled which facilitates the use of brute force non microsoft rdp tools or exploits
25 ns.exe A commonly used tool used by attackers to scan and map file shares
26 SilverBullet.exe Malware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts.
27 kportscan3.exe KPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks.
28 advanced_port_scanner.exe Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports.
29 mimikatz.exe utility Mimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets.
30 certify.exe A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS)
31 certipy.exe A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS)
@@ -1 +0,0 @@
identity
1 identity
@@ -1 +0,0 @@
src_ip,numDataPoints,latestCount,avgBlockedConnections,stdevBlockedConnections
1 src_ip numDataPoints latestCount avgBlockedConnections stdevBlockedConnections
@@ -1 +0,0 @@
domain,domain_abuse
1 domain domain_abuse
-47
View File
@@ -1,47 +0,0 @@
browser_process_name,browser_object_path,isAllowed
"*Sputnik.exe","*Sputnik\Sputnik\User Data\Default\Login Data*", true
"*ChromePlus.exe","*MapleStudio\ChromePlus\User Data\Default\Login Data*", true
"*QIP Surf.exe","*QIP Surf\User Data\Default\Login Data*", true
"*BlackHawk.exe","*BlackHawk\User Data\Default\Login Data*", true
"*7Star.exe","*7Star\7Star\User Data\Default\Login Data*", true
"*Sleipnir5.exe","*Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data*", true
"*Citrio.exe","*CatalinaGroup\Citrio\User Data\Default\Login Data*", true
"*Chrome SxS.exe","*Google\Chrome SxS\User Data\Default\Login Data*", true
"*Chrome.exe","*Google\Chrome\User Data\Default\Login Data*", true
"*Coowon.exe","*Coowon\Coowon\User Data\Default\Login Data*", true
"*CocCocBrowser.exe","*CocCoc\Browser\User Data\Default\Login Data*", true
"*Uran.exe","*uCozMedia\Uran\User Data\Default\Login Data*", true
"*QQBrowser.exe","*Tencent\QQBrowser\User Data\Default\Login Data*", true
"*Orbitum.exe","*Orbitum\User Data\Default\Login Data*", true
"*Slimjet.exe","*Slimjet\User Data\Default\Login Data*", true
"*Iridium.exe","*Iridium\User Data\Default\Login Data*", true
"*Vivaldi.exe","*Vivaldi\User Data\Default\Login Data*", true
"*Chromium.exe","*Chromium\User Data\Default\Login Data*", true
"*GhostBrowser.exe","*GhostBrowser\User Data\Default\Login Data*", true
"*CentBrowser.exe","*CentBrowser\User Data\Default\Login Data*", true
"*Xvast.exe","*Xvast\User Data\Default\Login Data*", true
"*Chedot.exe","*Chedot\User Data\Default\Login Data*", true
"*SuperBird.exe","*SuperBird\User Data\Default\Login Data*", true
"*360Browser.exe","*360Browser\Browser\User Data\Default\Login Data*", true
"*360Chrome.exe","*360Chrome\Chrome\User Data\Default\Login Data*", true
"*dragon.exe","*Comodo\Dragon\User Data\Default\Login Data*", true
"*brave.exe","*BraveSoftware\Brave-Browser\User Data\Default\Login Data*", true
"*brave.exe","*BraveSoftware\Brave-Browser\User Data\Local State*", true
"*brave.exe","*BraveSoftware\Brave-Browser\User Data\Default*", true
"*torch.exe","*Torch\User Data\Default\Login Data*", true
"*UCBrowser.exe","*UCBrowser\User Data_i18n\Default\UC Login Data.18*", true
"*BliskBrowser.exe","*Blisk\User Data\Default\Login Data*", true
"*Epic Privacy Browser.exe","*Epic Privacy Browser\User Data\Default\Login Data*", true
"*nichrome.exe","*Nichrome\User Data\Default\Login Data*", true
"*AmigoBrowser.exe","*Amigo\User Data\Default\Login Data*", true
"*KometaBrowser.exe","*Kometa\User Data\Default\Login Data*", true
"*XpomBrowser.exe","*Xpom\User Data\Default\Login Data*", true
"*msedge.exe","*Microsoft\Edge\User Data\Default\Login Data*", true
"*LiebaoBrowser.exe","*Liebao7\User Data\Default\EncryptedStorage*", true
"*AvastBrowser.exe","*AVAST Software\Browser\User Data\Default\Login Data*", true
"*Kinza.exe","*Kinza\User Data\Default\Login Data*", true
"*seamonkey.exe","*Mozilla\SeaMonkey\Profiles\logins.json*", true
"*icedragon.exe","*Comodo\IceDragon\Profiles\logins.json*", true
"*cyberfox.exe","*8pecxstudios\Cyberfox\Profiles\logins.json*", true
"*SlimBrowser.exe","*FlashPeak\SlimBrowser\Profiles\logins.json*", true
"*palemoon.exe","*Moonchild Productions\Pale Moon\Profiles\logins.json*", true
1 browser_process_name browser_object_path isAllowed
2 *Sputnik.exe *Sputnik\Sputnik\User Data\Default\Login Data* true
3 *ChromePlus.exe *MapleStudio\ChromePlus\User Data\Default\Login Data* true
4 *QIP Surf.exe *QIP Surf\User Data\Default\Login Data* true
5 *BlackHawk.exe *BlackHawk\User Data\Default\Login Data* true
6 *7Star.exe *7Star\7Star\User Data\Default\Login Data* true
7 *Sleipnir5.exe *Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data* true
8 *Citrio.exe *CatalinaGroup\Citrio\User Data\Default\Login Data* true
9 *Chrome SxS.exe *Google\Chrome SxS\User Data\Default\Login Data* true
10 *Chrome.exe *Google\Chrome\User Data\Default\Login Data* true
11 *Coowon.exe *Coowon\Coowon\User Data\Default\Login Data* true
12 *CocCocBrowser.exe *CocCoc\Browser\User Data\Default\Login Data* true
13 *Uran.exe *uCozMedia\Uran\User Data\Default\Login Data* true
14 *QQBrowser.exe *Tencent\QQBrowser\User Data\Default\Login Data* true
15 *Orbitum.exe *Orbitum\User Data\Default\Login Data* true
16 *Slimjet.exe *Slimjet\User Data\Default\Login Data* true
17 *Iridium.exe *Iridium\User Data\Default\Login Data* true
18 *Vivaldi.exe *Vivaldi\User Data\Default\Login Data* true
19 *Chromium.exe *Chromium\User Data\Default\Login Data* true
20 *GhostBrowser.exe *GhostBrowser\User Data\Default\Login Data* true
21 *CentBrowser.exe *CentBrowser\User Data\Default\Login Data* true
22 *Xvast.exe *Xvast\User Data\Default\Login Data* true
23 *Chedot.exe *Chedot\User Data\Default\Login Data* true
24 *SuperBird.exe *SuperBird\User Data\Default\Login Data* true
25 *360Browser.exe *360Browser\Browser\User Data\Default\Login Data* true
26 *360Chrome.exe *360Chrome\Chrome\User Data\Default\Login Data* true
27 *dragon.exe *Comodo\Dragon\User Data\Default\Login Data* true
28 *brave.exe *BraveSoftware\Brave-Browser\User Data\Default\Login Data* true
29 *brave.exe *BraveSoftware\Brave-Browser\User Data\Local State* true
30 *brave.exe *BraveSoftware\Brave-Browser\User Data\Default* true
31 *torch.exe *Torch\User Data\Default\Login Data* true
32 *UCBrowser.exe *UCBrowser\User Data_i18n\Default\UC Login Data.18* true
33 *BliskBrowser.exe *Blisk\User Data\Default\Login Data* true
34 *Epic Privacy Browser.exe *Epic Privacy Browser\User Data\Default\Login Data* true
35 *nichrome.exe *Nichrome\User Data\Default\Login Data* true
36 *AmigoBrowser.exe *Amigo\User Data\Default\Login Data* true
37 *KometaBrowser.exe *Kometa\User Data\Default\Login Data* true
38 *XpomBrowser.exe *Xpom\User Data\Default\Login Data* true
39 *msedge.exe *Microsoft\Edge\User Data\Default\Login Data* true
40 *LiebaoBrowser.exe *Liebao7\User Data\Default\EncryptedStorage* true
41 *AvastBrowser.exe *AVAST Software\Browser\User Data\Default\Login Data* true
42 *Kinza.exe *Kinza\User Data\Default\Login Data* true
43 *seamonkey.exe *Mozilla\SeaMonkey\Profiles\logins.json* true
44 *icedragon.exe *Comodo\IceDragon\Profiles\logins.json* true
45 *cyberfox.exe *8pecxstudios\Cyberfox\Profiles\logins.json* true
46 *SlimBrowser.exe *FlashPeak\SlimBrowser\Profiles\logins.json* true
47 *palemoon.exe *Moonchild Productions\Pale Moon\Profiles\logins.json* true
@@ -1,259 +0,0 @@
"_mkv_child","_timediff",ascii,base64bin,base64char,bin,dec,hex
0,,":NUL:",000000,A,00000000,0,00
1,,"",000001,B,00000001,1,01
2,,"",000010,C,00000010,2,02
3,,"",000011,D,00000011,3,03
4,,"",000100,E,00000100,4,04
5,,"",000101,F,00000101,5,05
6,,"",000110,G,00000110,6,06
7,,"",000111,H,00000111,7,07
8,,"",001000,I,00001000,8,08
9,," ",001001,J,00001001,9,09
10,,"
",001010,K,00001010,10,0A
11,," ",001011,L,00001011,11,0B
12,," ",001100,M,00001100,12,0C
13,,"",001101,N,00001101,13,0D
14,,"",001110,O,00001110,14,0E
15,,"",001111,P,00001111,15,0F
16,,"",010000,Q,00010000,16,10
17,,"",010001,R,00010001,17,11
18,,"",010010,S,00010010,18,12
19,,"",010011,T,00010011,19,13
20,,"",010100,U,00010100,20,14
21,,"",010101,V,00010101,21,15
22,,"",010110,W,00010110,22,16
23,,"",010111,X,00010111,23,17
24,,"",011000,Y,00011000,24,18
25,,"",011001,Z,00011001,25,19
26,,"",011010,a,00011010,26,1A
27,,"",011011,b,00011011,27,1B
28,,"",011100,c,00011100,28,1C
29,,"",011101,d,00011101,29,1D
30,,"",011110,e,00011110,30,1E
31,,"",011111,f,00011111,31,1F
32,,":SPACE:",100000,g,00100000,32,20
33,,"!",100001,h,00100001,33,21
34,,"""",100010,i,00100010,34,22
35,,"#",100011,j,00100011,35,23
36,,"$",100100,k,00100100,36,24
37,,"%",100101,l,00100101,37,25
38,,"&",100110,m,00100110,38,26
39,,"'",100111,n,00100111,39,27
40,,"(",101000,o,00101000,40,28
41,,")",101001,p,00101001,41,29
42,,"*",101010,q,00101010,42,2A
43,,"+",101011,r,00101011,43,2B
44,,",",101100,s,00101100,44,2C
45,,"-",101101,t,00101101,45,2D
46,,".",101110,u,00101110,46,2E
47,,"/",101111,v,00101111,47,2F
48,,0,110000,w,00110000,48,30
49,,1,110001,x,00110001,49,31
50,,2,110010,y,00110010,50,32
51,,3,110011,z,00110011,51,33
52,,4,110100,0,00110100,52,34
53,,5,110101,1,00110101,53,35
54,,6,110110,2,00110110,54,36
55,,7,110111,3,00110111,55,37
56,,8,111000,4,00111000,56,38
57,,9,111001,5,00111001,57,39
58,,":",111010,6,00111010,58,3A
59,,";",111011,7,00111011,59,3B
60,,"<",111100,8,00111100,60,3C
61,,"=",111101,9,00111101,61,3D
62,,">",111110,"+",00111110,62,3E
63,,"?",111111,"/",00111111,63,3F
64,,"@",,,01000000,64,40
65,,A,,,01000001,65,41
66,,B,,,01000010,66,42
67,,C,,,01000011,67,43
68,,D,,,01000100,68,44
69,,E,,,01000101,69,45
70,,F,,,01000110,70,46
71,,G,,,01000111,71,47
72,,H,,,01001000,72,48
73,,I,,,01001001,73,49
74,,J,,,01001010,74,4A
75,,K,,,01001011,75,4B
76,,L,,,01001100,76,4C
77,,M,,,01001101,77,4D
78,,N,,,01001110,78,4E
79,,O,,,01001111,79,4F
80,,P,,,01010000,80,50
81,,Q,,,01010001,81,51
82,,R,,,01010010,82,52
83,,S,,,01010011,83,53
84,,T,,,01010100,84,54
85,,U,,,01010101,85,55
86,,V,,,01010110,86,56
87,,W,,,01010111,87,57
88,,X,,,01011000,88,58
89,,Y,,,01011001,89,59
90,,Z,,,01011010,90,5A
91,,"[",,,01011011,91,5B
92,,"\",,,01011100,92,5C
93,,"]",,,01011101,93,5D
94,,"^",,,01011110,94,5E
95,,"_",,,01011111,95,5F
96,,"`",,,01100000,96,60
97,,a,,,01100001,97,61
98,,b,,,01100010,98,62
99,,c,,,01100011,99,63
100,,d,,,01100100,100,64
101,,e,,,01100101,101,65
102,,f,,,01100110,102,66
103,,g,,,01100111,103,67
104,,h,,,01101000,104,68
105,,i,,,01101001,105,69
106,,j,,,01101010,106,6A
107,,k,,,01101011,107,6B
108,,l,,,01101100,108,6C
109,,m,,,01101101,109,6D
110,,n,,,01101110,110,6E
111,,o,,,01101111,111,6F
112,,p,,,01110000,112,70
113,,q,,,01110001,113,71
114,,r,,,01110010,114,72
115,,s,,,01110011,115,73
116,,t,,,01110100,116,74
117,,u,,,01110101,117,75
118,,v,,,01110110,118,76
119,,w,,,01110111,119,77
120,,x,,,01111000,120,78
121,,y,,,01111001,121,79
122,,z,,,01111010,122,7A
123,,"{",,,01111011,123,7B
124,,"|",,,01111100,124,7C
125,,"}",,,01111101,125,7D
126,,"~",,,01111110,126,7E
127,,"",,,01111111,127,7F
128,,"€",,,10000000,128,80
129,,"",,,10000001,129,81
130,,"‚",,,10000010,130,82
131,,"ƒ",,,10000011,131,83
132,,"„",,,10000100,132,84
133,,"…",,,10000101,133,85
134,,"†",,,10000110,134,86
135,,"‡",,,10000111,135,87
136,,"ˆ",,,10001000,136,88
137,,"‰",,,10001001,137,89
138,,"Š",,,10001010,138,8A
139,,"‹",,,10001011,139,8B
140,,"Œ",,,10001100,140,8C
141,,"",,,10001101,141,8D
142,,"Ž",,,10001110,142,8E
143,,"",,,10001111,143,8F
144,,"",,,10010000,144,90
145,,"‘",,,10010001,145,91
146,,"’",,,10010010,146,92
147,,"“",,,10010011,147,93
148,,"”",,,10010100,148,94
149,,"•",,,10010101,149,95
150,,"–",,,10010110,150,96
151,,"—",,,10010111,151,97
152,,"˜",,,10011000,152,98
153,,"™",,,10011001,153,99
154,,"š",,,10011010,154,9A
155,,"›",,,10011011,155,9B
156,,"œ",,,10011100,156,9C
157,,"",,,10011101,157,9D
158,,"ž",,,10011110,158,9E
159,,"Ÿ",,,10011111,159,9F
160,," ",,,10100000,160,A0
161,,"¡",,,10100001,161,A1
162,,"¢",,,10100010,162,A2
163,,"£",,,10100011,163,A3
164,,"¤",,,10100100,164,A4
165,,"¥",,,10100101,165,A5
166,,"¦",,,10100110,166,A6
167,,"§",,,10100111,167,A7
168,,"¨",,,10101000,168,A8
169,,"©",,,10101001,169,A9
170,,"ª",,,10101010,170,AA
171,,"«",,,10101011,171,AB
172,,"¬",,,10101100,172,AC
173,,"­",,,10101101,173,AD
174,,"®",,,10101110,174,AE
175,,"¯",,,10101111,175,AF
176,,"°",,,10110000,176,B0
177,,"±",,,10110001,177,B1
178,,"²",,,10110010,178,B2
179,,"³",,,10110011,179,B3
180,,"´",,,10110100,180,B4
181,,"µ",,,10110101,181,B5
182,,"",,,10110110,182,B6
183,,"·",,,10110111,183,B7
184,,"¸",,,10111000,184,B8
185,,"¹",,,10111001,185,B9
186,,"º",,,10111010,186,BA
187,,"»",,,10111011,187,BB
188,,"¼",,,10111100,188,BC
189,,"½",,,10111101,189,BD
190,,"¾",,,10111110,190,BE
191,,"¿",,,10111111,191,BF
192,,"À",,,11000000,192,C0
193,,"Á",,,11000001,193,C1
194,,"Â",,,11000010,194,C2
195,,"Ã",,,11000011,195,C3
196,,"Ä",,,11000100,196,C4
197,,"Å",,,11000101,197,C5
198,,"Æ",,,11000110,198,C6
199,,"Ç",,,11000111,199,C7
200,,"È",,,11001000,200,C8
201,,"É",,,11001001,201,C9
202,,"Ê",,,11001010,202,CA
203,,"Ë",,,11001011,203,CB
204,,"Ì",,,11001100,204,CC
205,,"Í",,,11001101,205,CD
206,,"Î",,,11001110,206,CE
207,,"Ï",,,11001111,207,CF
208,,"Ð",,,11010000,208,D0
209,,"Ñ",,,11010001,209,D1
210,,"Ò",,,11010010,210,D2
211,,"Ó",,,11010011,211,D3
212,,"Ô",,,11010100,212,D4
213,,"Õ",,,11010101,213,D5
214,,"Ö",,,11010110,214,D6
215,,"×",,,11010111,215,D7
216,,"Ø",,,11011000,216,D8
217,,"Ù",,,11011001,217,D9
218,,"Ú",,,11011010,218,DA
219,,"Û",,,11011011,219,DB
220,,"Ü",,,11011100,220,DC
221,,"Ý",,,11011101,221,DD
222,,"Þ",,,11011110,222,DE
223,,"ß",,,11011111,223,DF
224,,"à",,,11100000,224,E0
225,,"á",,,11100001,225,E1
226,,"â",,,11100010,226,E2
227,,"ã",,,11100011,227,E3
228,,"ä",,,11100100,228,E4
229,,"å",,,11100101,229,E5
230,,"æ",,,11100110,230,E6
231,,"ç",,,11100111,231,E7
232,,"è",,,11101000,232,E8
233,,"é",,,11101001,233,E9
234,,"ê",,,11101010,234,EA
235,,"ë",,,11101011,235,EB
236,,"ì",,,11101100,236,EC
237,,"í",,,11101101,237,ED
238,,"î",,,11101110,238,EE
239,,"ï",,,11101111,239,EF
240,,"ð",,,11110000,240,F0
241,,"ñ",,,11110001,241,F1
242,,"ò",,,11110010,242,F2
243,,"ó",,,11110011,243,F3
244,,"ô",,,11110100,244,F4
245,,"õ",,,11110101,245,F5
246,,"ö",,,11110110,246,F6
247,,"÷",,,11110111,247,F7
248,,"ø",,,11111000,248,F8
249,,"ù",,,11111001,249,F9
250,,"ú",,,11111010,250,FA
251,,"û",,,11111011,251,FB
252,,"ü",,,11111100,252,FC
253,,"ý",,,11111101,253,FD
254,,"þ",,,11111110,254,FE
255,,"ÿ",,,11111111,255,FF
,,,000000,"=",,,
1 _mkv_child _timediff ascii base64bin base64char bin dec hex
2 0 :NUL: 000000 A 00000000 0 00
3 1  000001 B 00000001 1 01
4 2  000010 C 00000010 2 02
5 3  000011 D 00000011 3 03
6 4  000100 E 00000100 4 04
7 5  000101 F 00000101 5 05
8 6  000110 G 00000110 6 06
9 7  000111 H 00000111 7 07
10 8  001000 I 00001000 8 08
11 9 001001 J 00001001 9 09
12 10 001010 K 00001010 10 0A
13 11 001011 L 00001011 11 0B
14 12 001100 M 00001100 12 0C
15 13 001101 N 00001101 13 0D
16 14  001110 O 00001110 14 0E
17 15  001111 P 00001111 15 0F
18 16  010000 Q 00010000 16 10
19 17  010001 R 00010001 17 11
20 18  010010 S 00010010 18 12
21 19  010011 T 00010011 19 13
22 20  010100 U 00010100 20 14
23 21  010101 V 00010101 21 15
24 22  010110 W 00010110 22 16
25 23  010111 X 00010111 23 17
26 24  011000 Y 00011000 24 18
27 25  011001 Z 00011001 25 19
28 26  011010 a 00011010 26 1A
29 27  011011 b 00011011 27 1B
30 28  011100 c 00011100 28 1C
31 29  011101 d 00011101 29 1D
32 30  011110 e 00011110 30 1E
33 31  011111 f 00011111 31 1F
34 32 :SPACE: 100000 g 00100000 32 20
35 33 ! 100001 h 00100001 33 21
36 34 " 100010 i 00100010 34 22
37 35 # 100011 j 00100011 35 23
38 36 $ 100100 k 00100100 36 24
39 37 % 100101 l 00100101 37 25
40 38 & 100110 m 00100110 38 26
41 39 ' 100111 n 00100111 39 27
42 40 ( 101000 o 00101000 40 28
43 41 ) 101001 p 00101001 41 29
44 42 * 101010 q 00101010 42 2A
45 43 + 101011 r 00101011 43 2B
46 44 , 101100 s 00101100 44 2C
47 45 - 101101 t 00101101 45 2D
48 46 . 101110 u 00101110 46 2E
49 47 / 101111 v 00101111 47 2F
50 48 0 110000 w 00110000 48 30
51 49 1 110001 x 00110001 49 31
52 50 2 110010 y 00110010 50 32
53 51 3 110011 z 00110011 51 33
54 52 4 110100 0 00110100 52 34
55 53 5 110101 1 00110101 53 35
56 54 6 110110 2 00110110 54 36
57 55 7 110111 3 00110111 55 37
58 56 8 111000 4 00111000 56 38
59 57 9 111001 5 00111001 57 39
60 58 : 111010 6 00111010 58 3A
61 59 ; 111011 7 00111011 59 3B
62 60 < 111100 8 00111100 60 3C
63 61 = 111101 9 00111101 61 3D
64 62 > 111110 + 00111110 62 3E
65 63 ? 111111 / 00111111 63 3F
66 64 @ 01000000 64 40
67 65 A 01000001 65 41
68 66 B 01000010 66 42
69 67 C 01000011 67 43
70 68 D 01000100 68 44
71 69 E 01000101 69 45
72 70 F 01000110 70 46
73 71 G 01000111 71 47
74 72 H 01001000 72 48
75 73 I 01001001 73 49
76 74 J 01001010 74 4A
77 75 K 01001011 75 4B
78 76 L 01001100 76 4C
79 77 M 01001101 77 4D
80 78 N 01001110 78 4E
81 79 O 01001111 79 4F
82 80 P 01010000 80 50
83 81 Q 01010001 81 51
84 82 R 01010010 82 52
85 83 S 01010011 83 53
86 84 T 01010100 84 54
87 85 U 01010101 85 55
88 86 V 01010110 86 56
89 87 W 01010111 87 57
90 88 X 01011000 88 58
91 89 Y 01011001 89 59
92 90 Z 01011010 90 5A
93 91 [ 01011011 91 5B
94 92 \ 01011100 92 5C
95 93 ] 01011101 93 5D
96 94 ^ 01011110 94 5E
97 95 _ 01011111 95 5F
98 96 ` 01100000 96 60
99 97 a 01100001 97 61
100 98 b 01100010 98 62
101 99 c 01100011 99 63
102 100 d 01100100 100 64
103 101 e 01100101 101 65
104 102 f 01100110 102 66
105 103 g 01100111 103 67
106 104 h 01101000 104 68
107 105 i 01101001 105 69
108 106 j 01101010 106 6A
109 107 k 01101011 107 6B
110 108 l 01101100 108 6C
111 109 m 01101101 109 6D
112 110 n 01101110 110 6E
113 111 o 01101111 111 6F
114 112 p 01110000 112 70
115 113 q 01110001 113 71
116 114 r 01110010 114 72
117 115 s 01110011 115 73
118 116 t 01110100 116 74
119 117 u 01110101 117 75
120 118 v 01110110 118 76
121 119 w 01110111 119 77
122 120 x 01111000 120 78
123 121 y 01111001 121 79
124 122 z 01111010 122 7A
125 123 { 01111011 123 7B
126 124 | 01111100 124 7C
127 125 } 01111101 125 7D
128 126 ~ 01111110 126 7E
129 127  01111111 127 7F
130 128 € 10000000 128 80
131 129  10000001 129 81
132 130 ‚ 10000010 130 82
133 131 ƒ 10000011 131 83
134 132 „ 10000100 132 84
135 133 … 10000101 133 85
136 134 † 10000110 134 86
137 135 ‡ 10000111 135 87
138 136 ˆ 10001000 136 88
139 137 ‰ 10001001 137 89
140 138 Š 10001010 138 8A
141 139 ‹ 10001011 139 8B
142 140 Œ 10001100 140 8C
143 141  10001101 141 8D
144 142 Ž 10001110 142 8E
145 143  10001111 143 8F
146 144  10010000 144 90
147 145 ‘ 10010001 145 91
148 146 ’ 10010010 146 92
149 147 “ 10010011 147 93
150 148 ” 10010100 148 94
151 149 • 10010101 149 95
152 150 – 10010110 150 96
153 151 — 10010111 151 97
154 152 ˜ 10011000 152 98
155 153 ™ 10011001 153 99
156 154 š 10011010 154 9A
157 155 › 10011011 155 9B
158 156 œ 10011100 156 9C
159 157  10011101 157 9D
160 158 ž 10011110 158 9E
161 159 Ÿ 10011111 159 9F
162 160   10100000 160 A0
163 161 ¡ 10100001 161 A1
164 162 ¢ 10100010 162 A2
165 163 £ 10100011 163 A3
166 164 ¤ 10100100 164 A4
167 165 ¥ 10100101 165 A5
168 166 ¦ 10100110 166 A6
169 167 § 10100111 167 A7
170 168 ¨ 10101000 168 A8
171 169 © 10101001 169 A9
172 170 ª 10101010 170 AA
173 171 « 10101011 171 AB
174 172 ¬ 10101100 172 AC
175 173 ­ 10101101 173 AD
176 174 ® 10101110 174 AE
177 175 ¯ 10101111 175 AF
178 176 ° 10110000 176 B0
179 177 ± 10110001 177 B1
180 178 ² 10110010 178 B2
181 179 ³ 10110011 179 B3
182 180 ´ 10110100 180 B4
183 181 µ 10110101 181 B5
184 182 10110110 182 B6
185 183 · 10110111 183 B7
186 184 ¸ 10111000 184 B8
187 185 ¹ 10111001 185 B9
188 186 º 10111010 186 BA
189 187 » 10111011 187 BB
190 188 ¼ 10111100 188 BC
191 189 ½ 10111101 189 BD
192 190 ¾ 10111110 190 BE
193 191 ¿ 10111111 191 BF
194 192 À 11000000 192 C0
195 193 Á 11000001 193 C1
196 194 Â 11000010 194 C2
197 195 Ã 11000011 195 C3
198 196 Ä 11000100 196 C4
199 197 Å 11000101 197 C5
200 198 Æ 11000110 198 C6
201 199 Ç 11000111 199 C7
202 200 È 11001000 200 C8
203 201 É 11001001 201 C9
204 202 Ê 11001010 202 CA
205 203 Ë 11001011 203 CB
206 204 Ì 11001100 204 CC
207 205 Í 11001101 205 CD
208 206 Î 11001110 206 CE
209 207 Ï 11001111 207 CF
210 208 Ð 11010000 208 D0
211 209 Ñ 11010001 209 D1
212 210 Ò 11010010 210 D2
213 211 Ó 11010011 211 D3
214 212 Ô 11010100 212 D4
215 213 Õ 11010101 213 D5
216 214 Ö 11010110 214 D6
217 215 × 11010111 215 D7
218 216 Ø 11011000 216 D8
219 217 Ù 11011001 217 D9
220 218 Ú 11011010 218 DA
221 219 Û 11011011 219 DB
222 220 Ü 11011100 220 DC
223 221 Ý 11011101 221 DD
224 222 Þ 11011110 222 DE
225 223 ß 11011111 223 DF
226 224 à 11100000 224 E0
227 225 á 11100001 225 E1
228 226 â 11100010 226 E2
229 227 ã 11100011 227 E3
230 228 ä 11100100 228 E4
231 229 å 11100101 229 E5
232 230 æ 11100110 230 E6
233 231 ç 11100111 231 E7
234 232 è 11101000 232 E8
235 233 é 11101001 233 E9
236 234 ê 11101010 234 EA
237 235 ë 11101011 235 EB
238 236 ì 11101100 236 EC
239 237 í 11101101 237 ED
240 238 î 11101110 238 EE
241 239 ï 11101111 239 EF
242 240 ð 11110000 240 F0
243 241 ñ 11110001 241 F1
244 242 ò 11110010 242 F2
245 243 ó 11110011 243 F3
246 244 ô 11110100 244 F4
247 245 õ 11110101 245 F5
248 246 ö 11110110 246 F6
249 247 ÷ 11110111 247 F7
250 248 ø 11111000 248 F8
251 249 ù 11111001 249 F9
252 250 ú 11111010 250 FA
253 251 û 11111011 251 FB
254 252 ü 11111100 252 FC
255 253 ý 11111101 253 FD
256 254 þ 11111110 254 FE
257 255 ÿ 11111111 255 FF
258 000000 =
@@ -1 +0,0 @@
count,domain,type,query,answer
1 count domain type query answer
-2
View File
@@ -1,2 +0,0 @@
username
Administrator
1 username
2 Administrator
-1
View File
@@ -1 +0,0 @@
domain,isValidDomain
1 domain isValidDomain
File diff suppressed because it is too large Load Diff
@@ -1 +0,0 @@
dynamic_dns_domains, isDynDNS_local
1 dynamic_dns_domains isDynDNS_local
-403
View File
@@ -1,403 +0,0 @@
library,islibrary
outllib.dll,TRUE
iviewers.dll,TRUE
hha.dll,TRUE
aclui.dll,TRUE
xwtpw32.dll,TRUE
xwizards.dll,TRUE
xpsservices.dll,TRUE
xolehlp.dll,TRUE
xmllite.dll,TRUE
wwapi.dll,TRUE
wwancfg.dll,TRUE
wtsapi32.dll,TRUE
wsmsvc.dll,TRUE
wshelper.dll,TRUE
wshbth.dll,TRUE
wscapi.dll,TRUE
wpdshext.dll,TRUE
wofutil.dll,TRUE
wmsgapi.dll,TRUE
wmpdui.dll,TRUE
wmiutils.dll,TRUE
wmidcom.dll,TRUE
wmiclnt.dll,TRUE
wlidprov.dll,TRUE
wldp.dll,TRUE
wlbsctrl.dll,TRUE
wlancfg.dll,TRUE
wlanapi.dll,TRUE
wkscli.dll,TRUE
winsync.dll,TRUE
winsta.dll,TRUE
winsqlite3.dll,TRUE
winscard.dll,TRUE
winrnr.dll,TRUE
winnsi.dll,TRUE
winmm.dll,TRUE
winmde.dll,TRUE
winipsec.dll,TRUE
wininet.dll,TRUE
winhttp.dll,TRUE
windowsudk.shellcommon.dll,TRUE
windowsperformancerecordercontrol.dll,TRUE
windowscodecsext.dll,TRUE
windowscodecs.dll,TRUE
windows.ui.immersive.dll,TRUE
windows.storage.search.dll,TRUE
windows.storage.dll,TRUE
winbrand.dll,TRUE
winbio.dll,TRUE
wimgapi.dll,TRUE
whhelper.dll,TRUE
wevtapi.dll,TRUE
wer.dll,TRUE
wecapi.dll,TRUE
webservices.dll,TRUE
wdscore.dll,TRUE
wdi.dll,TRUE
wcnnetsh.dll,TRUE
wcmapi.dll,TRUE
wbemsvc.dll,TRUE
wbemprox.dll,TRUE
vsstrace.dll,TRUE
vssapi.dll,TRUE
virtdisk.dll,TRUE
version.dll,TRUE
vdsutil.dll,TRUE
vaultcli.dll,TRUE
uxtheme.dll,TRUE
uxinit.dll,TRUE
utildll.dll,TRUE
userenv.dll,TRUE
urlmon.dll,TRUE
upshared.dll,TRUE
updatepolicy.dll,TRUE
unattend.dll,TRUE
umpdc.dll,TRUE
uiribbon.dll,TRUE
uireng.dll,TRUE
uiautomationcore.dll,TRUE
uianimation.dll,TRUE
twinui.appcore.dll,TRUE
twinapi.dll,TRUE
twext.dll,TRUE
ttdrecord.dll,TRUE
tsworkspace.dll,TRUE
tquery.dll,TRUE
tpmcoreprovisioning.dll,TRUE
timesync.dll,TRUE
tdh.dll,TRUE
tbs.dll,TRUE
tapi32.dll,TRUE
systemsettingsthresholdadminflowui.dll,TRUE
sxshared.dll,TRUE
structuredquery.dll,TRUE
staterepository.core.dll,TRUE
ssshim.dll,TRUE
sspicli.dll,TRUE
ssp_isv.exe_rsaenh.dll,TRUE
ssp.exe_rsaenh.dll,TRUE
srvcli.dll,TRUE
srpapi.dll,TRUE
srmtrace.dll,TRUE
srcore.dll,TRUE
srclient.dll,TRUE
sppcext.dll,TRUE
sppc.dll,TRUE
spp.dll,TRUE
spectrumsyncclient.dll,TRUE
snmpapi.dll,TRUE
slc.dll,TRUE
shell32.dll,TRUE
security.dll,TRUE
secur32.dll,TRUE
schedcli.dll,TRUE
scecli.dll,TRUE
scansetting.dll,TRUE
sas.dll,TRUE
sapi_onecore.dll,TRUE
samlib.dll,TRUE
samcli.dll,TRUE
rtworkq.dll,TRUE
rtutils.dll,TRUE
rsaenh.dll,TRUE
rpcnsh.dll,TRUE
rmclient.dll,TRUE
resutils.dll,TRUE
resetengine.dll,TRUE
reseteng.dll,TRUE
regapi.dll,TRUE
reagent.dll,TRUE
rasmontr.dll,TRUE
rasman.dll,TRUE
rasgcw.dll,TRUE
rasdlg.dll,TRUE
rasapi32.dll,TRUE
radcui.dll,TRUE
puiapi.dll,TRUE
prvdmofcomp.dll,TRUE
proximityservicepal.dll,TRUE
proximitycommon.dll,TRUE
propsys.dll,TRUE
profapi.dll,TRUE
prntvpt.dll,TRUE
printui.dll,TRUE
powrprof.dll,TRUE
polstore.dll,TRUE
policymanager.dll,TRUE
pnrpnsp.dll,TRUE
playsndsrv.dll,TRUE
pla.dll,TRUE
pkeyhelper.dll,TRUE
peerdistsh.dll,TRUE
pdh.dll,TRUE
pcaui.dll,TRUE
p9np.dll,TRUE
p2pnetsh.dll,TRUE
p2p.dll,TRUE
osuninst.dll,TRUE
osksupport.dll,TRUE
osbaseln.dll,TRUE
opcservices.dll,TRUE
onex.dll,TRUE
omadmapi.dll,TRUE
oleacc.dll,TRUE
oci.dll,TRUE
ntshrui.dll,TRUE
ntmarta.dll,TRUE
ntlmshared.dll,TRUE
ntlanman.dll,TRUE
ntdsapi.dll,TRUE
nshwfp.dll,TRUE
nshipsec.dll,TRUE
nshhttp.dll,TRUE
npmproxy.dll,TRUE
nlansp_c.dll,TRUE
nlaapi.dll,TRUE
ninput.dll,TRUE
newdev.dll,TRUE
networkexplorer.dll,TRUE
netutils.dll,TRUE
nettrace.dll,TRUE
netshell.dll,TRUE
netsetupapi.dll,TRUE
netprovfw.dll,TRUE
netprofm.dll,TRUE
netplwiz.dll,TRUE
netjoin.dll,TRUE
netiohlp.dll,TRUE
netid.dll,TRUE
netapi32.dll,TRUE
ndfapi.dll,TRUE
ncrypt.dll,TRUE
napinsp.dll,TRUE
mtxclu.dll,TRUE
msxml3.dll,TRUE
mswsock.dll,TRUE
mswb7.dll,TRUE
msvcp110_win.dll,TRUE
msutb.dll,TRUE
mstracer.dll,TRUE
msiso.dll,TRUE
msi.dll,TRUE
msftedit.dll,TRUE
msdtctm.dll,TRUE
msdrm.dll,TRUE
msctfmonitor.dll,TRUE
msctf.dll,TRUE
mscoree.dll,TRUE
mscms.dll,TRUE
msacm32.dll,TRUE
mrmcorer.dll,TRUE
mpsvc.dll,TRUE
mprapi.dll,TRUE
mpr.dll,TRUE
mpclient.dll,TRUE
mobilenetworking.dll,TRUE
mmdevapi.dll,TRUE
mlang.dll,TRUE
miutils.dll,TRUE
mintdh.dll,TRUE
midimap.dll,TRUE
mi.dll,TRUE
mfplat.dll,TRUE
mfcore.dll,TRUE
mfc42u.dll,TRUE
mdmdiagnostics.dll,TRUE
mbaexmlparser.dll,TRUE
mapistub.dll,TRUE
maintenanceui.dll,TRUE
magnification.dll,TRUE
lrwizdll.dll,TRUE
lpksetupproxyserv.dll,TRUE
logoncontroller.dll,TRUE
logoncli.dll,TRUE
lockhostingframework.dll,TRUE
loadperf.dll,TRUE
linkinfo.dll,TRUE
licensingdiagspp.dll,TRUE
licensemanagerapi.dll,TRUE
ktmw32.dll,TRUE
ksuser.dll,TRUE
kdstub.dll,TRUE
joinutil.dll,TRUE
iumsdk.dll,TRUE
iumbase.dll,TRUE
isv.exe_rsaenh.dll,TRUE
iscsium.dll,TRUE
iscsidsc.dll,TRUE
iri.dll,TRUE
iphlpapi.dll,TRUE
inproclogger.dll,TRUE
ifsutil.dll,TRUE
ifmon.dll,TRUE
iertutil.dll,TRUE
iedkcs32.dll,TRUE
ieadvpack.dll,TRUE
idstore.dll,TRUE
icmp.dll,TRUE
httpapi.dll,TRUE
hnetmon.dll,TRUE
hid.dll,TRUE
gpapi.dll,TRUE
getuname.dll,TRUE
fxstiff.dll,TRUE
fxsst.dll,TRUE
fxsapi.dll,TRUE
fwpuclnt.dll,TRUE
fwpolicyiomgr.dll,TRUE
fwcfg.dll,TRUE
fwbase.dll,TRUE
fvewiz.dll,TRUE
fveskybackup.dll,TRUE
fveapi.dll,TRUE
framedynos.dll,TRUE
fltlib.dll,TRUE
flightsettings.dll,TRUE
firewallapi.dll,TRUE
fhsvcctl.dll,TRUE
fhcfg.dll,TRUE
feclient.dll,TRUE
fddevquery.dll,TRUE
faultrep.dll,TRUE
fastprox.dll,TRUE
explorerframe.dll,TRUE
execmodelproxy.dll,TRUE
esent.dll,TRUE
efsutil.dll,TRUE
efsadu.dll,TRUE
edputil.dll,TRUE
edgeiso.dll,TRUE
eappprxy.dll,TRUE
eappcfg.dll,TRUE
dynamoapi.dll,TRUE
dxva2.dll,TRUE
dxgi.dll,TRUE
dxcore.dll,TRUE
dwrite.dll,TRUE
dwmcore.dll,TRUE
dwmapi.dll,TRUE
dusmapi.dll,TRUE
duser.dll,TRUE
dui70.dll,TRUE
dsrole.dll,TRUE
dsreg.dll,TRUE
dsprop.dll,TRUE
dsparse.dll,TRUE
dsclient.dll,TRUE
drvstore.dll,TRUE
drprov.dll,TRUE
dpx.dll,TRUE
dot3cfg.dll,TRUE
dot3api.dll,TRUE
dnsapi.dll,TRUE
dmxmlhelputils.dll,TRUE
dmpushproxy.dll,TRUE
dmprocessxmlfiltered.dll,TRUE
dmoleaututils.dll,TRUE
dmiso8601utils.dll,TRUE
dmenterprisediagnostics.dll,TRUE
dmenrollengine.dll,TRUE
dmcommandlineutils.dll,TRUE
dmcmnutils.dll,TRUE
dmcfgutils.dll,TRUE
dismcore.dll,TRUE
dismapi.dll,TRUE
directmanipulation.dll,TRUE
dhcpcsvc6.dll,TRUE
dhcpcsvc.dll,TRUE
dhcpcmonitor.dll,TRUE
devrtl.dll,TRUE
devobj.dll,TRUE
devicepairing.dll,TRUE
devicecredential.dll,TRUE
deviceassociation.dll,TRUE
desktopshellext.dll,TRUE
defragproxy.dll,TRUE
dcomp.dll,TRUE
dcntel.dll,TRUE
dbghelp.dll,TRUE
dbgcore.dll,TRUE
davclnt.dll,TRUE
dataexchange.dll,TRUE
d3dcompiler_47.dll,TRUE
d3d9.dll,TRUE
d3d12.dll,TRUE
d3d11.dll,TRUE
d3d10warp.dll,TRUE
d3d10core.dll,TRUE
d3d10_1core.dll,TRUE
d3d10_1.dll,TRUE
d3d10.dll,TRUE
d2d1.dll,TRUE
cscui.dll,TRUE
cscobj.dll,TRUE
cscapi.dll,TRUE
cryptxml.dll,TRUE
cryptui.dll,TRUE
cryptsp.dll,TRUE
cryptdll.dll,TRUE
cryptbase.dll,TRUE
credui.dll,TRUE
coreuicomponents.dll,TRUE
coremessaging.dll,TRUE
coredplus.dll,TRUE
connect.dll,TRUE
configmanager2.dll,TRUE
comdlg32.dll,TRUE
colorui.dll,TRUE
coloradapterclient.dll,TRUE
cmutil.dll,TRUE
cmpbk32.dll,TRUE
clusapi.dll,TRUE
clipc.dll,TRUE
cldapi.dll,TRUE
certenroll.dll,TRUE
certcli.dll,TRUE
cabview.dll,TRUE
cabinet.dll,TRUE
bootux.dll,TRUE
bootmenuux.dll,TRUE
bderepair.dll,TRUE
bcrypt.dll,TRUE
bcp47mrm.dll,TRUE
bcp47langs.dll,TRUE
bcd.dll,TRUE
batmeter.dll,TRUE
avrt.dll,TRUE
authz.dll,TRUE
authfwcfg.dll,TRUE
auditpolcore.dll,TRUE
audioses.dll,TRUE
atl.dll,TRUE
archiveint.dll,TRUE
appxdeploymentclient.dll,TRUE
appxalluserstore.dll,TRUE
appvpolicy.dll,TRUE
applicationframe.dll,TRUE
apphelp.dll,TRUE
aepic.dll,TRUE
adsldpc.dll,TRUE
activeds.dll,TRUE
amsi.dll,TRUE
1 library islibrary
2 outllib.dll TRUE
3 iviewers.dll TRUE
4 hha.dll TRUE
5 aclui.dll TRUE
6 xwtpw32.dll TRUE
7 xwizards.dll TRUE
8 xpsservices.dll TRUE
9 xolehlp.dll TRUE
10 xmllite.dll TRUE
11 wwapi.dll TRUE
12 wwancfg.dll TRUE
13 wtsapi32.dll TRUE
14 wsmsvc.dll TRUE
15 wshelper.dll TRUE
16 wshbth.dll TRUE
17 wscapi.dll TRUE
18 wpdshext.dll TRUE
19 wofutil.dll TRUE
20 wmsgapi.dll TRUE
21 wmpdui.dll TRUE
22 wmiutils.dll TRUE
23 wmidcom.dll TRUE
24 wmiclnt.dll TRUE
25 wlidprov.dll TRUE
26 wldp.dll TRUE
27 wlbsctrl.dll TRUE
28 wlancfg.dll TRUE
29 wlanapi.dll TRUE
30 wkscli.dll TRUE
31 winsync.dll TRUE
32 winsta.dll TRUE
33 winsqlite3.dll TRUE
34 winscard.dll TRUE
35 winrnr.dll TRUE
36 winnsi.dll TRUE
37 winmm.dll TRUE
38 winmde.dll TRUE
39 winipsec.dll TRUE
40 wininet.dll TRUE
41 winhttp.dll TRUE
42 windowsudk.shellcommon.dll TRUE
43 windowsperformancerecordercontrol.dll TRUE
44 windowscodecsext.dll TRUE
45 windowscodecs.dll TRUE
46 windows.ui.immersive.dll TRUE
47 windows.storage.search.dll TRUE
48 windows.storage.dll TRUE
49 winbrand.dll TRUE
50 winbio.dll TRUE
51 wimgapi.dll TRUE
52 whhelper.dll TRUE
53 wevtapi.dll TRUE
54 wer.dll TRUE
55 wecapi.dll TRUE
56 webservices.dll TRUE
57 wdscore.dll TRUE
58 wdi.dll TRUE
59 wcnnetsh.dll TRUE
60 wcmapi.dll TRUE
61 wbemsvc.dll TRUE
62 wbemprox.dll TRUE
63 vsstrace.dll TRUE
64 vssapi.dll TRUE
65 virtdisk.dll TRUE
66 version.dll TRUE
67 vdsutil.dll TRUE
68 vaultcli.dll TRUE
69 uxtheme.dll TRUE
70 uxinit.dll TRUE
71 utildll.dll TRUE
72 userenv.dll TRUE
73 urlmon.dll TRUE
74 upshared.dll TRUE
75 updatepolicy.dll TRUE
76 unattend.dll TRUE
77 umpdc.dll TRUE
78 uiribbon.dll TRUE
79 uireng.dll TRUE
80 uiautomationcore.dll TRUE
81 uianimation.dll TRUE
82 twinui.appcore.dll TRUE
83 twinapi.dll TRUE
84 twext.dll TRUE
85 ttdrecord.dll TRUE
86 tsworkspace.dll TRUE
87 tquery.dll TRUE
88 tpmcoreprovisioning.dll TRUE
89 timesync.dll TRUE
90 tdh.dll TRUE
91 tbs.dll TRUE
92 tapi32.dll TRUE
93 systemsettingsthresholdadminflowui.dll TRUE
94 sxshared.dll TRUE
95 structuredquery.dll TRUE
96 staterepository.core.dll TRUE
97 ssshim.dll TRUE
98 sspicli.dll TRUE
99 ssp_isv.exe_rsaenh.dll TRUE
100 ssp.exe_rsaenh.dll TRUE
101 srvcli.dll TRUE
102 srpapi.dll TRUE
103 srmtrace.dll TRUE
104 srcore.dll TRUE
105 srclient.dll TRUE
106 sppcext.dll TRUE
107 sppc.dll TRUE
108 spp.dll TRUE
109 spectrumsyncclient.dll TRUE
110 snmpapi.dll TRUE
111 slc.dll TRUE
112 shell32.dll TRUE
113 security.dll TRUE
114 secur32.dll TRUE
115 schedcli.dll TRUE
116 scecli.dll TRUE
117 scansetting.dll TRUE
118 sas.dll TRUE
119 sapi_onecore.dll TRUE
120 samlib.dll TRUE
121 samcli.dll TRUE
122 rtworkq.dll TRUE
123 rtutils.dll TRUE
124 rsaenh.dll TRUE
125 rpcnsh.dll TRUE
126 rmclient.dll TRUE
127 resutils.dll TRUE
128 resetengine.dll TRUE
129 reseteng.dll TRUE
130 regapi.dll TRUE
131 reagent.dll TRUE
132 rasmontr.dll TRUE
133 rasman.dll TRUE
134 rasgcw.dll TRUE
135 rasdlg.dll TRUE
136 rasapi32.dll TRUE
137 radcui.dll TRUE
138 puiapi.dll TRUE
139 prvdmofcomp.dll TRUE
140 proximityservicepal.dll TRUE
141 proximitycommon.dll TRUE
142 propsys.dll TRUE
143 profapi.dll TRUE
144 prntvpt.dll TRUE
145 printui.dll TRUE
146 powrprof.dll TRUE
147 polstore.dll TRUE
148 policymanager.dll TRUE
149 pnrpnsp.dll TRUE
150 playsndsrv.dll TRUE
151 pla.dll TRUE
152 pkeyhelper.dll TRUE
153 peerdistsh.dll TRUE
154 pdh.dll TRUE
155 pcaui.dll TRUE
156 p9np.dll TRUE
157 p2pnetsh.dll TRUE
158 p2p.dll TRUE
159 osuninst.dll TRUE
160 osksupport.dll TRUE
161 osbaseln.dll TRUE
162 opcservices.dll TRUE
163 onex.dll TRUE
164 omadmapi.dll TRUE
165 oleacc.dll TRUE
166 oci.dll TRUE
167 ntshrui.dll TRUE
168 ntmarta.dll TRUE
169 ntlmshared.dll TRUE
170 ntlanman.dll TRUE
171 ntdsapi.dll TRUE
172 nshwfp.dll TRUE
173 nshipsec.dll TRUE
174 nshhttp.dll TRUE
175 npmproxy.dll TRUE
176 nlansp_c.dll TRUE
177 nlaapi.dll TRUE
178 ninput.dll TRUE
179 newdev.dll TRUE
180 networkexplorer.dll TRUE
181 netutils.dll TRUE
182 nettrace.dll TRUE
183 netshell.dll TRUE
184 netsetupapi.dll TRUE
185 netprovfw.dll TRUE
186 netprofm.dll TRUE
187 netplwiz.dll TRUE
188 netjoin.dll TRUE
189 netiohlp.dll TRUE
190 netid.dll TRUE
191 netapi32.dll TRUE
192 ndfapi.dll TRUE
193 ncrypt.dll TRUE
194 napinsp.dll TRUE
195 mtxclu.dll TRUE
196 msxml3.dll TRUE
197 mswsock.dll TRUE
198 mswb7.dll TRUE
199 msvcp110_win.dll TRUE
200 msutb.dll TRUE
201 mstracer.dll TRUE
202 msiso.dll TRUE
203 msi.dll TRUE
204 msftedit.dll TRUE
205 msdtctm.dll TRUE
206 msdrm.dll TRUE
207 msctfmonitor.dll TRUE
208 msctf.dll TRUE
209 mscoree.dll TRUE
210 mscms.dll TRUE
211 msacm32.dll TRUE
212 mrmcorer.dll TRUE
213 mpsvc.dll TRUE
214 mprapi.dll TRUE
215 mpr.dll TRUE
216 mpclient.dll TRUE
217 mobilenetworking.dll TRUE
218 mmdevapi.dll TRUE
219 mlang.dll TRUE
220 miutils.dll TRUE
221 mintdh.dll TRUE
222 midimap.dll TRUE
223 mi.dll TRUE
224 mfplat.dll TRUE
225 mfcore.dll TRUE
226 mfc42u.dll TRUE
227 mdmdiagnostics.dll TRUE
228 mbaexmlparser.dll TRUE
229 mapistub.dll TRUE
230 maintenanceui.dll TRUE
231 magnification.dll TRUE
232 lrwizdll.dll TRUE
233 lpksetupproxyserv.dll TRUE
234 logoncontroller.dll TRUE
235 logoncli.dll TRUE
236 lockhostingframework.dll TRUE
237 loadperf.dll TRUE
238 linkinfo.dll TRUE
239 licensingdiagspp.dll TRUE
240 licensemanagerapi.dll TRUE
241 ktmw32.dll TRUE
242 ksuser.dll TRUE
243 kdstub.dll TRUE
244 joinutil.dll TRUE
245 iumsdk.dll TRUE
246 iumbase.dll TRUE
247 isv.exe_rsaenh.dll TRUE
248 iscsium.dll TRUE
249 iscsidsc.dll TRUE
250 iri.dll TRUE
251 iphlpapi.dll TRUE
252 inproclogger.dll TRUE
253 ifsutil.dll TRUE
254 ifmon.dll TRUE
255 iertutil.dll TRUE
256 iedkcs32.dll TRUE
257 ieadvpack.dll TRUE
258 idstore.dll TRUE
259 icmp.dll TRUE
260 httpapi.dll TRUE
261 hnetmon.dll TRUE
262 hid.dll TRUE
263 gpapi.dll TRUE
264 getuname.dll TRUE
265 fxstiff.dll TRUE
266 fxsst.dll TRUE
267 fxsapi.dll TRUE
268 fwpuclnt.dll TRUE
269 fwpolicyiomgr.dll TRUE
270 fwcfg.dll TRUE
271 fwbase.dll TRUE
272 fvewiz.dll TRUE
273 fveskybackup.dll TRUE
274 fveapi.dll TRUE
275 framedynos.dll TRUE
276 fltlib.dll TRUE
277 flightsettings.dll TRUE
278 firewallapi.dll TRUE
279 fhsvcctl.dll TRUE
280 fhcfg.dll TRUE
281 feclient.dll TRUE
282 fddevquery.dll TRUE
283 faultrep.dll TRUE
284 fastprox.dll TRUE
285 explorerframe.dll TRUE
286 execmodelproxy.dll TRUE
287 esent.dll TRUE
288 efsutil.dll TRUE
289 efsadu.dll TRUE
290 edputil.dll TRUE
291 edgeiso.dll TRUE
292 eappprxy.dll TRUE
293 eappcfg.dll TRUE
294 dynamoapi.dll TRUE
295 dxva2.dll TRUE
296 dxgi.dll TRUE
297 dxcore.dll TRUE
298 dwrite.dll TRUE
299 dwmcore.dll TRUE
300 dwmapi.dll TRUE
301 dusmapi.dll TRUE
302 duser.dll TRUE
303 dui70.dll TRUE
304 dsrole.dll TRUE
305 dsreg.dll TRUE
306 dsprop.dll TRUE
307 dsparse.dll TRUE
308 dsclient.dll TRUE
309 drvstore.dll TRUE
310 drprov.dll TRUE
311 dpx.dll TRUE
312 dot3cfg.dll TRUE
313 dot3api.dll TRUE
314 dnsapi.dll TRUE
315 dmxmlhelputils.dll TRUE
316 dmpushproxy.dll TRUE
317 dmprocessxmlfiltered.dll TRUE
318 dmoleaututils.dll TRUE
319 dmiso8601utils.dll TRUE
320 dmenterprisediagnostics.dll TRUE
321 dmenrollengine.dll TRUE
322 dmcommandlineutils.dll TRUE
323 dmcmnutils.dll TRUE
324 dmcfgutils.dll TRUE
325 dismcore.dll TRUE
326 dismapi.dll TRUE
327 directmanipulation.dll TRUE
328 dhcpcsvc6.dll TRUE
329 dhcpcsvc.dll TRUE
330 dhcpcmonitor.dll TRUE
331 devrtl.dll TRUE
332 devobj.dll TRUE
333 devicepairing.dll TRUE
334 devicecredential.dll TRUE
335 deviceassociation.dll TRUE
336 desktopshellext.dll TRUE
337 defragproxy.dll TRUE
338 dcomp.dll TRUE
339 dcntel.dll TRUE
340 dbghelp.dll TRUE
341 dbgcore.dll TRUE
342 davclnt.dll TRUE
343 dataexchange.dll TRUE
344 d3dcompiler_47.dll TRUE
345 d3d9.dll TRUE
346 d3d12.dll TRUE
347 d3d11.dll TRUE
348 d3d10warp.dll TRUE
349 d3d10core.dll TRUE
350 d3d10_1core.dll TRUE
351 d3d10_1.dll TRUE
352 d3d10.dll TRUE
353 d2d1.dll TRUE
354 cscui.dll TRUE
355 cscobj.dll TRUE
356 cscapi.dll TRUE
357 cryptxml.dll TRUE
358 cryptui.dll TRUE
359 cryptsp.dll TRUE
360 cryptdll.dll TRUE
361 cryptbase.dll TRUE
362 credui.dll TRUE
363 coreuicomponents.dll TRUE
364 coremessaging.dll TRUE
365 coredplus.dll TRUE
366 connect.dll TRUE
367 configmanager2.dll TRUE
368 comdlg32.dll TRUE
369 colorui.dll TRUE
370 coloradapterclient.dll TRUE
371 cmutil.dll TRUE
372 cmpbk32.dll TRUE
373 clusapi.dll TRUE
374 clipc.dll TRUE
375 cldapi.dll TRUE
376 certenroll.dll TRUE
377 certcli.dll TRUE
378 cabview.dll TRUE
379 cabinet.dll TRUE
380 bootux.dll TRUE
381 bootmenuux.dll TRUE
382 bderepair.dll TRUE
383 bcrypt.dll TRUE
384 bcp47mrm.dll TRUE
385 bcp47langs.dll TRUE
386 bcd.dll TRUE
387 batmeter.dll TRUE
388 avrt.dll TRUE
389 authz.dll TRUE
390 authfwcfg.dll TRUE
391 auditpolcore.dll TRUE
392 audioses.dll TRUE
393 atl.dll TRUE
394 archiveint.dll TRUE
395 appxdeploymentclient.dll TRUE
396 appxalluserstore.dll TRUE
397 appvpolicy.dll TRUE
398 applicationframe.dll TRUE
399 apphelp.dll TRUE
400 aepic.dll TRUE
401 adsldpc.dll TRUE
402 activeds.dll TRUE
403 amsi.dll TRUE
-886
View File
@@ -1,886 +0,0 @@
islibrary,library,excludes,ttp,comment
TRUE,aclui.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
TRUE,aclui.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
TRUE,acrodistdll.dll,*\Program Files\Adobe\Acrobat *,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
TRUE,acrodistdll.dll,*\Acrobat\acrodistdll*,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
TRUE,activeds.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,activeds.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,adsldpc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,adsldpc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,aepic.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,aepic.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,apphelp.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,apphelp.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,applicationframe.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,applicationframe.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,appvpolicy.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,appwiz.cpl,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
TRUE,appwiz.cpl,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
TRUE,appxalluserstore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,appxalluserstore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,appxdeploymentclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,appxdeploymentclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,archiveint.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,archiveint.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ashldres.dll,*\Program Files\McAfee.com\VSO*,T1574.002,https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf
TRUE,atl.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,atl.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,atltracetoolui.dll,*\Program Files\Microsoft Visual Studio 11.0\Common7\Tools*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
TRUE,audioses.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,audioses.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,auditpolcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,auditpolcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,authfwcfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,authfwcfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,authz.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,authz.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,avrt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,avrt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,basicnetutils.dll,*\Appdata\local\Temp\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
TRUE,basicnetutils.dll,*\Program Files\BAIDU\BAIDUPINYIN\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
TRUE,batmeter.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,batmeter.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,bcd.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,bcd.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,bcp47langs.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,bcp47langs.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,bcp47mrm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,bcp47mrm.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,bcrypt.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,bcrypt.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,bderepair.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,bootmenuux.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,bootux.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,cabinet.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cabinet.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cabview.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,cabview.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,certcli.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,certcli.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,certenroll.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,certenroll.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cfgmgr32.dll,*\Windows\System32\*,T1574.002,
TRUE,cfgmgr32.dll,*\Windows\SysWOW64\*,T1574.002,
TRUE,chrome_frame_helper.dll,*\Appdata\local\Google\Chrome\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
TRUE,chrome_frame_helper.dll,*\Program Files\Google\Chrome\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
TRUE,ciscosparklauncher.dll,*\Appdata\local\CiscoSparkLauncher*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
TRUE,ciscosparklauncher.dll,*\AppData\Local\Programs\Cisco Spark\*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
TRUE,classicexplorer32.dll,*\Program Files\Classic Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
TRUE,classicexplorer32.dll,*\Program Files\Open-Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
TRUE,cldapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cldapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,clipc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,clipc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,clusapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,clusapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cmpbk32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cmpbk32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cmutil.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,cmutil.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,coloradapterclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,coloradapterclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,colorui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,colorui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,comdlg32.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,comdlg32.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,commfunc.dll,*\Program Files\Lenovo\Communications Utility*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
TRUE,configmanager2.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,connect.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,connect.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,coredplus.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,coremessaging.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,coremessaging.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,coreuicomponents.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,coreuicomponents.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,credui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,credui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cryptbase.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cryptbase.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cryptdll.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cryptdll.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cryptsp.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,cryptsp.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,cryptui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cryptui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cryptxml.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cryptxml.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cscapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cscapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,cscobj.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,cscobj.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,cscui.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,cscui.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,d2d1.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d2d1.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10_1.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10_1.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10_1core.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10_1core.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10core.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10core.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10warp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d10warp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d11.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d11.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d12.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d12.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d9.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3d9.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\bin\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\bin\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\redist\d3d\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\redist\d3d\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Program Files\wireshark*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Program Files\cisco systems\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Program Files\microsoft\edge\application\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Program Files\Google\Chrome\Application\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Appdata\local\microsoft\teams\stage*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dcompiler_47.dll,*\Microsoft\Teams\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,d3dx9_43.dll,*\Windows\System32\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
TRUE,d3dx9_43.dll,*\Windows\SysWOW64\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
TRUE,dataexchange.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,dataexchange.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,davclnt.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,davclnt.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x86\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Program Files\microsoft office\root\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483
TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483
TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483
TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x86\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\cisco systems\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\microsoft office\root\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Program Files\microsoft office\root\vfs\programfilesx86\microsoft analysis services\as oledb\140*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbghelp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dbgmodel.dll,*\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,dbgmodel.dll,*\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,dbgmodel.dll,*\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,dcntel.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dcomp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dcomp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,defragproxy.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,defragproxy.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,desktopshellext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,desktopshellext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,deviceassociation.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,deviceassociation.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,devicecredential.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,devicecredential.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,devicepairing.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,devicepairing.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,devobj.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,devobj.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,devrtl.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,devrtl.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dhcpcmonitor.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dhcpcmonitor.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dhcpcsvc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dhcpcsvc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dhcpcsvc6.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dhcpcsvc6.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,directmanipulation.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,directmanipulation.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,dismapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dismapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dismcore.dll,*\Windows\System32\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
TRUE,dismcore.dll,*\Windows\SysWOW64\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
TRUE,dmcfgutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmcfgutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmcmnutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmcmnutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmcommandlineutils.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,dmcommandlineutils.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,dmenrollengine.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmenrollengine.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmenterprisediagnostics.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmiso8601utils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmiso8601utils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmoleaututils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmoleaututils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmprocessxmlfiltered.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmprocessxmlfiltered.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmpushproxy.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmpushproxy.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmxmlhelputils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dmxmlhelputils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dnsapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dnsapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dot3api.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dot3api.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dot3cfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dot3cfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dpx.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dpx.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,drprov.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,drprov.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,drvstore.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,drvstore.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,dsclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dsclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dsparse.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dsparse.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dsprop.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,dsprop.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,dsreg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dsreg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dsrole.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dsrole.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dui70.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dui70.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,duser.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,duser.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dusmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dusmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dwmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dwmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dwmcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dwrite.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dwrite.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dxcore.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,dxcore.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,dxgi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dxgi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dxva2.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dxva2.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,dynamoapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,eappcfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,eappcfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,eappprxy.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,eappprxy.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,edgeiso.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,edgeiso.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,edputil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,edputil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,efsadu.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,efsadu.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,efsutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,efsutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,esent.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,esent.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,execmodelproxy.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,execmodelproxy.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,explorerframe.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,explorerframe.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,facesdk.dll,*\Program Files\luxand\facesdk\bin\win64*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
TRUE,fastprox.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,fastprox.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,faultrep.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,faultrep.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fddevquery.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,fddevquery.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,feclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,feclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fhcfg.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,fhcfg.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,fhsvcctl.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,firewallapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,firewallapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,flightsettings.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,flightsettings.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,fltlib.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fltlib.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,formdll.dll,*\Program Files\Common Files\Microsoft Shared\NoteSync Forms*,T1574.002,https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1
TRUE,framedynos.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,framedynos.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,fveapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fveapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fveskybackup.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,fvewiz.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,fwbase.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fwbase.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fwcfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fwcfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fwpolicyiomgr.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fwpolicyiomgr.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fwpuclnt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fwpuclnt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fxsapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fxsapi.dll,*\Windows\System32\driverstore\filerepository\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fxsapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fxsst.dll,*\Windows\System32\*,T1574.001,https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/
TRUE,fxstiff.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,fxstiff.dll,*\Windows\System32\driverstore\filerepository\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,getuname.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,getuname.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,gflagsui.dll,*\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,glib-2.0.dll,*\Program Files\VMware\VMware Tools*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
TRUE,glib-2.0.dll,*\Program Files\VMware\VMware Workstation*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
TRUE,glib-2.0.dll,*\Program Files\VMware\VMware Player*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
TRUE,gpapi.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,gpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,hha.dll,*\Windows\System32\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
TRUE,hha.dll,*\Windows\SysWOW64\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
TRUE,hha.dll,*\Program Files\HTML Help Workshop*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
TRUE,hid.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,hid.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,hnetmon.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,hnetmon.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,hpcustpartui.dll,*\Program Files\HP*,T1574.002,https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html
TRUE,hpqhvsei.dll,*\Program Files\HP*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
TRUE,httpapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,httpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,icmp.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,icmp.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,idstore.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,idstore.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ieadvpack.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ieadvpack.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iedkcs32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iedkcs32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iernonce.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
TRUE,iernonce.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
TRUE,iertutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iertutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ifmon.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ifmon.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ifsutil.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,ifsutil.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,inproclogger.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iphlpapi.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iphlpapi.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iri.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iri.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iscsidsc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iscsidsc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iscsiexe.dll,*\Windows\System32\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
TRUE,iscsiexe.dll,*\Windows\SysWOW64\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
TRUE,iscsium.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iscsium.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,isv.exe_rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,isv.exe_rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,iumbase.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,iumsdk.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
TRUE,joinutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,joinutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,kdstub.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ksuser.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ksuser.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ktmw32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ktmw32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ldvpocx.ocx,*\Program Files\Symantec_Client_Security\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
TRUE,ldvpocx.ocx,*\Program Files\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
TRUE,libvlc.dll,*\Program Files\VideoLAN\VLC*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
TRUE,licensemanagerapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,licensemanagerapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,licensingdiagspp.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,licensingdiagspp.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,linkinfo.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,linkinfo.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,lmiguardiandll.dll,*\Program Files\LogMeIn*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619
TRUE,lmiguardiandll.dll,*\Program Files\LogMeIn\x86*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619
TRUE,lmiguardiandll.dll,*\Program Files\LogMeIn\x64*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619
TRUE,loadperf.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,loadperf.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,lockdown.dll,*\Program Files\McAfee\VirusScan Enterprise*,T1574.002,https://twitter.com/thepacketrat/status/1520878930449817600
TRUE,lockhostingframework.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,log.dll,*\Program Files\Bitdefender Antivirus Free*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
TRUE,logoncli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,logoncli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,logoncontroller.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,logoncontroller.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,lpksetupproxyserv.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,lpksetupproxyserv.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,lrwizdll.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,magnification.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,magnification.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,maintenanceui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mapistub.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mapistub.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mbaexmlparser.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,mdmdiagnostics.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mfc42u.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,mfc42u.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,mfcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mfcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mfplat.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mfplat.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,midimap.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,midimap.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mintdh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,miutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,miutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mlang.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mlang.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mmdevapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mmdevapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mobilenetworking.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mobilenetworking.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mozglue.dll,*\Program Files\SeaMonkey*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,mozglue.dll,*\Program Files\Mozilla Firefox*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,mozglue.dll,*\Program Files\Mozilla Thunderbird*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,mozglue.dll,*\AppData\Local\Mozilla Firefox\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,mpclient.dll,*\Program Files\Windows Defender*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
TRUE,mpclient.dll,*\ProgramData\Microsoft\Windows Defender\Platform\*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
TRUE,mpr.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,mpr.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,mprapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mprapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mpsvc.dll,*\Program Files\Windows Defender\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
TRUE,mpsvc.dll,*\ProgramData\Microsoft\Windows Defender\Platform\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
TRUE,mrmcorer.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mrmcorer.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msacm32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msacm32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mscms.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mscms.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mscoree.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mscoree.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mscorsvc.dll,*\Windows\Microsoft.NET\Framework\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
TRUE,mscorsvc.dll,*\Windows\Microsoft.NET\Framework64\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
TRUE,msctf.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,msctf.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,msctfmonitor.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msctfmonitor.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msdrm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msdrm.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msdtctm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msftedit.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
TRUE,msftedit.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
TRUE,msi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msiso.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,msiso.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,msutb.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msutb.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,msvcp110_win.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,msvcp110_win.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,msvcr100.dll,*\Windows\System32\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,msvcr100.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,mswb7.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,mswb7.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,mswsock.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,mswsock.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,msxml3.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,msxml3.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,mtxclu.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,mtxclu.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,napinsp.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,napinsp.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ncrypt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ncrypt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ndfapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ndfapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netapi32.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,netapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,netid.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netid.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netiohlp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netiohlp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netjoin.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,netjoin.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,netplwiz.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netplwiz.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netprofm.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,netprofm.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,netprovfw.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,netprovfw.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,netsetupapi.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,netsetupapi.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,netshell.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netshell.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,nettrace.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,netutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,networkexplorer.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,networkexplorer.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,newdev.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,newdev.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ninput.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ninput.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,nlaapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,nlaapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,nlansp_c.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,nlansp_c.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,npmproxy.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,npmproxy.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,nshhttp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,nshhttp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,nshipsec.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,nshipsec.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,nshwfp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,nshwfp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ntdsapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ntdsapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ntlanman.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ntlanman.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ntlmshared.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ntlmshared.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ntmarta.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ntmarta.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ntshrui.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ntshrui.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,nvsmartmax.dll,*\Program Files\NVIDIA Corporation\Display*,T1574.002,https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos
TRUE,oleacc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,oleacc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,omadmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,omadmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,onex.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,onex.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,opcservices.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,opcservices.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,opera_elf.dll,*\Appdata\local\programs\opera\*,T1574.002,https://twitter.com/ShitSecure/status/1566127363389329412
TRUE,osbaseln.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,osbaseln.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,osksupport.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,osuninst.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,osuninst.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,outllib.dll,*\Program Files\Microsoft Office\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
TRUE,outllib.dll,*\Program Files\Microsoft Office\Root\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
TRUE,p2p.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,p2p.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,p2pnetsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,p2pnetsh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,p9np.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,p9np.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,pcaui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,pcaui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,pdh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,pdh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,peerdistsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,peerdistsh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,pkeyhelper.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,pla.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,pla.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,playsndsrv.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,playsndsrv.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,pnrpnsp.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,pnrpnsp.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,policymanager.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,policymanager.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,polstore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,polstore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,powrprof.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,powrprof.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,printui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,printui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,prntvpt.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,prntvpt.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,profapi.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,profapi.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,propsys.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,propsys.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,proximitycommon.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,proximitycommon.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,proximityservicepal.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,prvdmofcomp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,prvdmofcomp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,puiapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,puiapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,python39.dll,*\Program Files\Python39*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,python39.dll,*\Appdata\local\Temp\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,python39.dll,*\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\CommonExtensions\Microsoft\VC\SecurityIssueAnalysis\python*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,python39.dll,*\Users\anaconda3*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
TRUE,qrt.dll,*\Program Files\F-Secure\Anti-Virus*,T1574.002,https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/
TRUE,radcui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,radcui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rasapi32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rasapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rasdlg.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,rasdlg.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,rasgcw.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,rasgcw.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,rasman.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rasman.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rasmontr.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rasmontr.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rastls.dll,*\Program Files\Symantec\Network Connected Devices Auto Setup*,T1574.002,https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf
TRUE,rcdll.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,reagent.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,reagent.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,regapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,regapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,reseteng.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,resetengine.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,resutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,resutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rjvplatform.dll,*\Windows\System32\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499
TRUE,rjvplatform.dll,*\Windows\SysWOW64\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499
TRUE,rmclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rmclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rpcnsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rpcnsh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,rtutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rtutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rtworkq.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rtworkq.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,rzlog4cpp_logger.dll,*\Appdata\local\razer\InGameEngine\cache\RzFpsApplet*,T1574.002,https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia
TRUE,safestore32.dll,*\Program Files\Sophos\Sophos Anti-Virus*,T1574.002,https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf
TRUE,samcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,samcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,samlib.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,samlib.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,sapi_onecore.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,sapi_onecore.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,sas.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,sas.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,scansetting.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,scansetting.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,scecli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,scecli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,schedcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,schedcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,secur32.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,secur32.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,security.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,security.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,sensapi.dll,*\Windows\System32\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792
TRUE,sensapi.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792
TRUE,shell32.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,shell32.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,shfolder.dll,*\Windows\System32\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226
TRUE,shfolder.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226
TRUE,siteadv.dll,*\Program Files\SiteAdvisor\*,T1574.002,https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf
TRUE,slc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,slc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,smadhook32c.dll,*\Program Files\Smadav*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
TRUE,snmpapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,snmpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,spectrumsyncclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,spp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,spp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,sppc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,sppc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,sppcext.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,sppcext.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,srclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,srclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,srcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,srmtrace.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,srmtrace.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,srpapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,srpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,srvcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,srvcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ssp.exe_rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ssp.exe_rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ssp_isv.exe_rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,ssp_isv.exe_rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,sspicli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,sspicli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ssshim.dll,*\Windows\System32\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410
TRUE,ssshim.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410
TRUE,staterepository.core.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,staterepository.core.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,structuredquery.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,structuredquery.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,sxshared.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,sxshared.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,symsrv.dll,*\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,systemsettingsthresholdadminflowui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tapi32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tbs.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tbs.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tdh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tdh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,textshaping.dll,*\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,textshaping.dll,*\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,timesync.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tmdbglog.dll,*\Program Files\Trend Micro\Titanium*,T1574.002,https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/
TRUE,tosbtkbd.dll,*\Program Files\Toshiba\Bluetooth Toshiba Stack*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
TRUE,tpmcoreprovisioning.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,tpmcoreprovisioning.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,tquery.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tquery.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tsworkspace.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,tsworkspace.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ttdrecord.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,ttdrecord.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,twext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,twext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,twinapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,twinapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
TRUE,twinui.appcore.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,twinui.appcore.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,uianimation.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,uianimation.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,uiautomationcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,uiautomationcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,uireng.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,uireng.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,uiribbon.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,uiribbon.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,umpdc.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,umpdc.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,unattend.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,unityplayer.dll,*\Appdata\local\Temp\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
TRUE,updatepolicy.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,updatepolicy.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,upshared.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,urlmon.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,urlmon.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,userenv.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,userenv.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,utildll.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,utildll.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,uxinit.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,uxinit.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,uxtheme.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,uxtheme.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,vaultcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,vaultcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,vdsutil.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,vdsutil.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,vender.dll,*\Program Files\ASUS\GPU TweakII*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
TRUE,vender.dll,*\Program Files\ASUS\VGA COM\*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
TRUE,version.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,version.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,vftrace.dll,*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x32*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
TRUE,vftrace.dll,*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x64*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
TRUE,vftrace.dll,*\Program Files\CyberArk\Endpoint Privilege Manager\Agent*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
TRUE,virtdisk.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,virtdisk.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,vivaldi_elf.dll,*\Appdata\local\Vivaldi\Application*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
TRUE,vivaldi_elf.dll,*\Appdata\local\Vivaldi\Application\*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
TRUE,vntfxf32.dll,*\Program Files\Venta\VentaFax &amp; Voice*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
TRUE,vsodscpl.dll,*\Program Files\McAfee\VirusScan Enterprise*,T1574.002,https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/
TRUE,vssapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,vssapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,vsstrace.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,vsstrace.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wbemprox.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wbemprox.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wbemsvc.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wbemsvc.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wcmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wcmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wcnnetsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wdi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wdi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wdscore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wdscore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,webservices.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,webservices.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wecapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wecapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wer.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wer.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wevtapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wevtapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,whhelper.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,whhelper.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wimgapi.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
TRUE,wimgapi.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
TRUE,wimgapi.dll,*\Program Files\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\arm64\DISM*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
TRUE,winbio.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,winbio.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,winbrand.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winbrand.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,windows.storage.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,windows.storage.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,windows.storage.search.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,windows.storage.search.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,windows.ui.immersive.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,windows.ui.immersive.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,windowscodecs.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,windowscodecs.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,windowscodecsext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,windowscodecsext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,windowsperformancerecordercontrol.dll,*\Program Files\windows kits\10\windows performance toolkit*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,windowsperformancerecordercontrol.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,windowsperformancerecordercontrol.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,windowsperformancerecorderui.dll,*\Program Files\Windows Kits\10\Windows Performance Toolkit*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,windowsudk.shellcommon.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,windowsudk.shellcommon.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,winhttp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winhttp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wininet.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wininet.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winipsec.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winipsec.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winmde.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winmm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winmm.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winnsi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winnsi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winrnr.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,winrnr.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,winscard.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,winscard.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,winsqlite3.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winsqlite3.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winsta.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winsta.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,winsync.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,winsync.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,winutils.dll,*\Program Files\Palo Alto Networks\Traps*,T1574.002,https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/
TRUE,wkscli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wkscli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wlanapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wlanapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wlancfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wlancfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wldp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wldp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wlidprov.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wlidprov.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wmiclnt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wmiclnt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wmidcom.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wmidcom.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wmiutils.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wmiutils.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wmpdui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wmsgapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wmsgapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wofutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wofutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wpdshext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wpdshext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wsc.dll,*\Program Files\AVAST Software\Avast*,T1574.001,https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2
TRUE,wscapi.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,wscapi.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,wsdapi.dll,*\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,wsdapi.dll,*\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
TRUE,wshbth.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wshbth.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,wshelper.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wshelper.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wsmsvc.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,wsmsvc.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,wtsapi32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wtsapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wwancfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wwancfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wwapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,wwapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,xmllite.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,xmllite.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,xolehlp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,xolehlp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
TRUE,xpsservices.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,xpsservices.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
TRUE,xwizards.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,xwizards.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,xwtpw32.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
TRUE,xwtpw32.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
1 islibrary library excludes ttp comment
2 TRUE aclui.dll *\Windows\System32\* T1574.002 https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
3 TRUE aclui.dll *\Windows\SysWOW64\* T1574.002 https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
4 TRUE acrodistdll.dll *\Program Files\Adobe\Acrobat * T1574.002 https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
5 TRUE acrodistdll.dll *\Acrobat\acrodistdll* T1574.002 https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
6 TRUE activeds.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
7 TRUE activeds.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
8 TRUE adsldpc.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
9 TRUE adsldpc.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
10 TRUE aepic.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
11 TRUE aepic.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
12 TRUE apphelp.dll *\Windows\System32\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
13 TRUE apphelp.dll *\Windows\SysWOW64\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
14 TRUE applicationframe.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
15 TRUE applicationframe.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
16 TRUE appvpolicy.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
17 TRUE appwiz.cpl *\Windows\System32\* T1574.002 https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
18 TRUE appwiz.cpl *\Windows\SysWOW64\* T1574.002 https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
19 TRUE appxalluserstore.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
20 TRUE appxalluserstore.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
21 TRUE appxdeploymentclient.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
22 TRUE appxdeploymentclient.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
23 TRUE archiveint.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
24 TRUE archiveint.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
25 TRUE ashldres.dll *\Program Files\McAfee.com\VSO* T1574.002 https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf
26 TRUE atl.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
27 TRUE atl.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
28 TRUE atltracetoolui.dll *\Program Files\Microsoft Visual Studio 11.0\Common7\Tools* T1574.002 https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
29 TRUE audioses.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
30 TRUE audioses.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
31 TRUE auditpolcore.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
32 TRUE auditpolcore.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
33 TRUE authfwcfg.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
34 TRUE authfwcfg.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
35 TRUE authz.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
36 TRUE authz.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
37 TRUE avrt.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
38 TRUE avrt.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
39 TRUE basicnetutils.dll *\Appdata\local\Temp\* T1574.002 https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
40 TRUE basicnetutils.dll *\Program Files\BAIDU\BAIDUPINYIN\* T1574.002 https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
41 TRUE batmeter.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
42 TRUE batmeter.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
43 TRUE bcd.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
44 TRUE bcd.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
45 TRUE bcp47langs.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
46 TRUE bcp47langs.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
47 TRUE bcp47mrm.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
48 TRUE bcp47mrm.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
49 TRUE bcrypt.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
50 TRUE bcrypt.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
51 TRUE bderepair.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
52 TRUE bootmenuux.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
53 TRUE bootux.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
54 TRUE cabinet.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
55 TRUE cabinet.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
56 TRUE cabview.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
57 TRUE cabview.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
58 TRUE certcli.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
59 TRUE certcli.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
60 TRUE certenroll.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
61 TRUE certenroll.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
62 TRUE cfgmgr32.dll *\Windows\System32\* T1574.002
63 TRUE cfgmgr32.dll *\Windows\SysWOW64\* T1574.002
64 TRUE chrome_frame_helper.dll *\Appdata\local\Google\Chrome\Application* T1574.002 https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
65 TRUE chrome_frame_helper.dll *\Program Files\Google\Chrome\Application* T1574.002 https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
66 TRUE ciscosparklauncher.dll *\Appdata\local\CiscoSparkLauncher* T1574.002 https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
67 TRUE ciscosparklauncher.dll *\AppData\Local\Programs\Cisco Spark\* T1574.002 https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
68 TRUE classicexplorer32.dll *\Program Files\Classic Shell* T1574.002 https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
69 TRUE classicexplorer32.dll *\Program Files\Open-Shell* T1574.002 https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
70 TRUE cldapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
71 TRUE cldapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
72 TRUE clipc.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
73 TRUE clipc.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
74 TRUE clusapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
75 TRUE clusapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
76 TRUE cmpbk32.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
77 TRUE cmpbk32.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
78 TRUE cmutil.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
79 TRUE cmutil.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
80 TRUE coloradapterclient.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
81 TRUE coloradapterclient.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
82 TRUE colorui.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
83 TRUE colorui.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
84 TRUE comdlg32.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
85 TRUE comdlg32.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
86 TRUE commfunc.dll *\Program Files\Lenovo\Communications Utility* T1574.002 https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
87 TRUE configmanager2.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
88 TRUE connect.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
89 TRUE connect.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
90 TRUE coredplus.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
91 TRUE coremessaging.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
92 TRUE coremessaging.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
93 TRUE coreuicomponents.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
94 TRUE coreuicomponents.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
95 TRUE credui.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
96 TRUE credui.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
97 TRUE cryptbase.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
98 TRUE cryptbase.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
99 TRUE cryptdll.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
100 TRUE cryptdll.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
101 TRUE cryptsp.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
102 TRUE cryptsp.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
103 TRUE cryptui.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
104 TRUE cryptui.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
105 TRUE cryptxml.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
106 TRUE cryptxml.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
107 TRUE cscapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
108 TRUE cscapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
109 TRUE cscobj.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
110 TRUE cscobj.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
111 TRUE cscui.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
112 TRUE cscui.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
113 TRUE d2d1.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
114 TRUE d2d1.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
115 TRUE d3d10.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
116 TRUE d3d10.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
117 TRUE d3d10_1.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
118 TRUE d3d10_1.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
119 TRUE d3d10_1core.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
120 TRUE d3d10_1core.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
121 TRUE d3d10core.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
122 TRUE d3d10core.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
123 TRUE d3d10warp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
124 TRUE d3d10warp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
125 TRUE d3d11.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
126 TRUE d3d11.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
127 TRUE d3d12.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
128 TRUE d3d12.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
129 TRUE d3d9.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
130 TRUE d3d9.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
131 TRUE d3dcompiler_47.dll *\Program Files\windows kits\10\bin\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
132 TRUE d3dcompiler_47.dll *\Program Files\windows kits\10\bin\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
133 TRUE d3dcompiler_47.dll *\Program Files\windows kits\10\redist\d3d\x64* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
134 TRUE d3dcompiler_47.dll *\Program Files\windows kits\10\redist\d3d\x86* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
135 TRUE d3dcompiler_47.dll *\Program Files\wireshark* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
136 TRUE d3dcompiler_47.dll *\Program Files\cisco systems\cisco jabber* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
137 TRUE d3dcompiler_47.dll *\Program Files\microsoft\edge\application\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
138 TRUE d3dcompiler_47.dll *\Program Files\Google\Chrome\Application\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
139 TRUE d3dcompiler_47.dll *\Appdata\local\microsoft\teams\stage* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
140 TRUE d3dcompiler_47.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
141 TRUE d3dcompiler_47.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
142 TRUE d3dcompiler_47.dll *\Microsoft\Teams\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
143 TRUE d3dx9_43.dll *\Windows\System32\* T1574.002 https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
144 TRUE d3dx9_43.dll *\Windows\SysWOW64\* T1574.002 https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
145 TRUE dataexchange.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
146 TRUE dataexchange.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
147 TRUE davclnt.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
148 TRUE davclnt.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
149 TRUE dbgcore.dll *\Program Files\windows kits\10\debuggers\arm* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
150 TRUE dbgcore.dll *\Program Files\windows kits\10\debuggers\arm\srcsrv* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
151 TRUE dbgcore.dll *\Program Files\windows kits\10\debuggers\arm64* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
152 TRUE dbgcore.dll *\Program Files\windows kits\10\debuggers\arm64\srcsrv* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
153 TRUE dbgcore.dll *\Program Files\windows kits\10\debuggers\x64* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
154 TRUE dbgcore.dll *\Program Files\windows kits\10\debuggers\x64\srcsrv* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
155 TRUE dbgcore.dll *\Program Files\windows kits\10\debuggers\x86* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
156 TRUE dbgcore.dll *\Program Files\windows kits\10\debuggers\x86\srcsrv* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
157 TRUE dbgcore.dll *\Program Files\microsoft office\root\office* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
158 TRUE dbgcore.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
159 TRUE dbgcore.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
160 TRUE dbgeng.dll *\Program Files\Windows Kits\* T1574.002 https://twitter.com/mrexodia/status/1630320327967252483
161 TRUE dbgeng.dll *\Program Files\Windows Kits\* T1574.002 https://twitter.com/mrexodia/status/1630320327967252483
162 TRUE dbgeng.dll *\Program Files\Windows Kits\* T1574.002 https://twitter.com/mrexodia/status/1630320327967252483
163 TRUE dbgeng.dll *\Program Files\Windows Kits\* T1574.002 https://twitter.com/mrexodia/status/1630320327967252483
164 TRUE dbghelp.dll *\Program Files\windows kits\10\debuggers\arm* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
165 TRUE dbghelp.dll *\Program Files\windows kits\10\debuggers\arm\srcsrv* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
166 TRUE dbghelp.dll *\Program Files\windows kits\10\debuggers\arm64* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
167 TRUE dbghelp.dll *\Program Files\windows kits\10\debuggers\arm64\srcsrv* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
168 TRUE dbghelp.dll *\Program Files\windows kits\10\debuggers\x64* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
169 TRUE dbghelp.dll *\Program Files\windows kits\10\debuggers\x64\srcsrv* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
170 TRUE dbghelp.dll *\Program Files\windows kits\10\debuggers\x86* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
171 TRUE dbghelp.dll *\Program Files\windows kits\10\debuggers\x86\srcsrv* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
172 TRUE dbghelp.dll *\Program Files\cisco systems\cisco jabber* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
173 TRUE dbghelp.dll *\Program Files\microsoft office\root\office* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
174 TRUE dbghelp.dll *\Program Files\microsoft office\root\vfs\programfilesx86\microsoft analysis services\as oledb\140* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
175 TRUE dbghelp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
176 TRUE dbghelp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
177 TRUE dbgmodel.dll *\Windows\System32\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
178 TRUE dbgmodel.dll *\Windows\SysWOW64\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
179 TRUE dbgmodel.dll *\Program Files\Windows Kits\10\Debuggers\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
180 TRUE dcntel.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
181 TRUE dcomp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
182 TRUE dcomp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
183 TRUE defragproxy.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
184 TRUE defragproxy.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
185 TRUE desktopshellext.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
186 TRUE desktopshellext.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
187 TRUE deviceassociation.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
188 TRUE deviceassociation.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
189 TRUE devicecredential.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
190 TRUE devicecredential.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
191 TRUE devicepairing.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
192 TRUE devicepairing.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
193 TRUE devobj.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
194 TRUE devobj.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
195 TRUE devrtl.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
196 TRUE devrtl.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
197 TRUE dhcpcmonitor.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
198 TRUE dhcpcmonitor.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
199 TRUE dhcpcsvc.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
200 TRUE dhcpcsvc.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
201 TRUE dhcpcsvc6.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
202 TRUE dhcpcsvc6.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
203 TRUE directmanipulation.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
204 TRUE directmanipulation.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
205 TRUE dismapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
206 TRUE dismapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
207 TRUE dismcore.dll *\Windows\System32\dism* T1574.001 https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
208 TRUE dismcore.dll *\Windows\SysWOW64\dism* T1574.001 https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
209 TRUE dmcfgutils.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
210 TRUE dmcfgutils.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
211 TRUE dmcmnutils.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
212 TRUE dmcmnutils.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
213 TRUE dmcommandlineutils.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
214 TRUE dmcommandlineutils.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
215 TRUE dmenrollengine.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
216 TRUE dmenrollengine.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
217 TRUE dmenterprisediagnostics.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
218 TRUE dmiso8601utils.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
219 TRUE dmiso8601utils.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
220 TRUE dmoleaututils.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
221 TRUE dmoleaututils.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
222 TRUE dmprocessxmlfiltered.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
223 TRUE dmprocessxmlfiltered.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
224 TRUE dmpushproxy.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
225 TRUE dmpushproxy.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
226 TRUE dmxmlhelputils.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
227 TRUE dmxmlhelputils.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
228 TRUE dnsapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
229 TRUE dnsapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
230 TRUE dot3api.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
231 TRUE dot3api.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
232 TRUE dot3cfg.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
233 TRUE dot3cfg.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
234 TRUE dpx.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
235 TRUE dpx.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
236 TRUE drprov.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
237 TRUE drprov.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
238 TRUE drvstore.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
239 TRUE drvstore.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
240 TRUE dsclient.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
241 TRUE dsclient.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
242 TRUE dsparse.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
243 TRUE dsparse.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
244 TRUE dsprop.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
245 TRUE dsprop.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
246 TRUE dsreg.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
247 TRUE dsreg.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
248 TRUE dsrole.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
249 TRUE dsrole.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
250 TRUE dui70.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
251 TRUE dui70.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
252 TRUE duser.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
253 TRUE duser.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
254 TRUE dusmapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
255 TRUE dusmapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
256 TRUE dwmapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
257 TRUE dwmapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
258 TRUE dwmcore.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
259 TRUE dwrite.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
260 TRUE dwrite.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
261 TRUE dxcore.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
262 TRUE dxcore.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
263 TRUE dxgi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
264 TRUE dxgi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
265 TRUE dxva2.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
266 TRUE dxva2.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
267 TRUE dynamoapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
268 TRUE eappcfg.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
269 TRUE eappcfg.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
270 TRUE eappprxy.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
271 TRUE eappprxy.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
272 TRUE edgeiso.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
273 TRUE edgeiso.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
274 TRUE edputil.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
275 TRUE edputil.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
276 TRUE efsadu.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
277 TRUE efsadu.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
278 TRUE efsutil.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
279 TRUE efsutil.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
280 TRUE esent.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
281 TRUE esent.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
282 TRUE execmodelproxy.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
283 TRUE execmodelproxy.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
284 TRUE explorerframe.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
285 TRUE explorerframe.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
286 TRUE facesdk.dll *\Program Files\luxand\facesdk\bin\win64* T1574.002 https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
287 TRUE fastprox.dll *\Windows\System32\wbem* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
288 TRUE fastprox.dll *\Windows\SysWOW64\wbem* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
289 TRUE faultrep.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
290 TRUE faultrep.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
291 TRUE fddevquery.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
292 TRUE fddevquery.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
293 TRUE feclient.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
294 TRUE feclient.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
295 TRUE fhcfg.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
296 TRUE fhcfg.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
297 TRUE fhsvcctl.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
298 TRUE firewallapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
299 TRUE firewallapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
300 TRUE flightsettings.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
301 TRUE flightsettings.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
302 TRUE fltlib.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
303 TRUE fltlib.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
304 TRUE formdll.dll *\Program Files\Common Files\Microsoft Shared\NoteSync Forms* T1574.002 https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1
305 TRUE framedynos.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
306 TRUE framedynos.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
307 TRUE fveapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
308 TRUE fveapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
309 TRUE fveskybackup.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
310 TRUE fvewiz.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
311 TRUE fwbase.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
312 TRUE fwbase.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
313 TRUE fwcfg.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
314 TRUE fwcfg.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
315 TRUE fwpolicyiomgr.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
316 TRUE fwpolicyiomgr.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
317 TRUE fwpuclnt.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
318 TRUE fwpuclnt.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
319 TRUE fxsapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
320 TRUE fxsapi.dll *\Windows\System32\driverstore\filerepository\prnms002.inf_* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
321 TRUE fxsapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
322 TRUE fxsst.dll *\Windows\System32\* T1574.001 https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/
323 TRUE fxstiff.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
324 TRUE fxstiff.dll *\Windows\System32\driverstore\filerepository\prnms002.inf_* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
325 TRUE getuname.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
326 TRUE getuname.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
327 TRUE gflagsui.dll *\Program Files\Windows Kits\10\Debuggers\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
328 TRUE glib-2.0.dll *\Program Files\VMware\VMware Tools* T1574.002 https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
329 TRUE glib-2.0.dll *\Program Files\VMware\VMware Workstation* T1574.002 https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
330 TRUE glib-2.0.dll *\Program Files\VMware\VMware Player* T1574.002 https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
331 TRUE gpapi.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
332 TRUE gpapi.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
333 TRUE hha.dll *\Windows\System32\* T1574.002 https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
334 TRUE hha.dll *\Windows\SysWOW64\* T1574.002 https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
335 TRUE hha.dll *\Program Files\HTML Help Workshop* T1574.002 https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
336 TRUE hid.dll *\Windows\System32\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
337 TRUE hid.dll *\Windows\SysWOW64\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
338 TRUE hnetmon.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
339 TRUE hnetmon.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
340 TRUE hpcustpartui.dll *\Program Files\HP* T1574.002 https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html
341 TRUE hpqhvsei.dll *\Program Files\HP* T1574.002 https://www.secureworks.com/research/shadowpad-malware-analysis
342 TRUE httpapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
343 TRUE httpapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
344 TRUE icmp.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
345 TRUE icmp.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
346 TRUE idstore.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
347 TRUE idstore.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
348 TRUE ieadvpack.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
349 TRUE ieadvpack.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
350 TRUE iedkcs32.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
351 TRUE iedkcs32.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
352 TRUE iernonce.dll *\Windows\System32\* T1574.002 https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
353 TRUE iernonce.dll *\Windows\SysWOW64\* T1574.002 https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
354 TRUE iertutil.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
355 TRUE iertutil.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
356 TRUE ifmon.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
357 TRUE ifmon.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
358 TRUE ifsutil.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
359 TRUE ifsutil.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
360 TRUE inproclogger.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
361 TRUE iphlpapi.dll *\Windows\System32\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
362 TRUE iphlpapi.dll *\Windows\SysWOW64\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
363 TRUE iri.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
364 TRUE iri.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
365 TRUE iscsidsc.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
366 TRUE iscsidsc.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
367 TRUE iscsiexe.dll *\Windows\System32\* T1574.001 https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
368 TRUE iscsiexe.dll *\Windows\SysWOW64\* T1574.001 https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
369 TRUE iscsium.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
370 TRUE iscsium.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
371 TRUE isv.exe_rsaenh.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
372 TRUE isv.exe_rsaenh.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
373 TRUE iumbase.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
374 TRUE iumsdk.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
375 TRUE iviewers.dll *\Program Files\Windows Kits\10\bin\* T1574.002 https://www.secureworks.com/research/shadowpad-malware-analysis
376 TRUE iviewers.dll *\Program Files\Windows Kits\10\bin\* T1574.002 https://www.secureworks.com/research/shadowpad-malware-analysis
377 TRUE iviewers.dll *\Program Files\Windows Kits\10\bin\* T1574.002 https://www.secureworks.com/research/shadowpad-malware-analysis
378 TRUE iviewers.dll *\Program Files\Windows Kits\10\bin\* T1574.002 https://www.secureworks.com/research/shadowpad-malware-analysis
379 TRUE joinutil.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
380 TRUE joinutil.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
381 TRUE kdstub.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
382 TRUE ksuser.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
383 TRUE ksuser.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
384 TRUE ktmw32.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
385 TRUE ktmw32.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
386 TRUE ldvpocx.ocx *\Program Files\Symantec_Client_Security\Symantec AntiVirus* T1574.002 https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
387 TRUE ldvpocx.ocx *\Program Files\Symantec AntiVirus* T1574.002 https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
388 TRUE libvlc.dll *\Program Files\VideoLAN\VLC* T1574.002 https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
389 TRUE licensemanagerapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
390 TRUE licensemanagerapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
391 TRUE licensingdiagspp.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
392 TRUE licensingdiagspp.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
393 TRUE linkinfo.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
394 TRUE linkinfo.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
395 TRUE lmiguardiandll.dll *\Program Files\LogMeIn* T1574.002 https://twitter.com/StopMalvertisin/status/1610961056163311619
396 TRUE lmiguardiandll.dll *\Program Files\LogMeIn\x86* T1574.002 https://twitter.com/StopMalvertisin/status/1610961056163311619
397 TRUE lmiguardiandll.dll *\Program Files\LogMeIn\x64* T1574.002 https://twitter.com/StopMalvertisin/status/1610961056163311619
398 TRUE loadperf.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
399 TRUE loadperf.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
400 TRUE lockdown.dll *\Program Files\McAfee\VirusScan Enterprise* T1574.002 https://twitter.com/thepacketrat/status/1520878930449817600
401 TRUE lockhostingframework.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
402 TRUE log.dll *\Program Files\Bitdefender Antivirus Free* T1574.002 https://www.secureworks.com/research/shadowpad-malware-analysis
403 TRUE logoncli.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
404 TRUE logoncli.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
405 TRUE logoncontroller.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
406 TRUE logoncontroller.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
407 TRUE lpksetupproxyserv.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
408 TRUE lpksetupproxyserv.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
409 TRUE lrwizdll.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
410 TRUE magnification.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
411 TRUE magnification.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
412 TRUE maintenanceui.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
413 TRUE mapistub.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
414 TRUE mapistub.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
415 TRUE mbaexmlparser.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
416 TRUE mdmdiagnostics.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
417 TRUE mfc42u.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
418 TRUE mfc42u.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
419 TRUE mfcore.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
420 TRUE mfcore.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
421 TRUE mfplat.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
422 TRUE mfplat.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
423 TRUE mi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
424 TRUE mi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
425 TRUE midimap.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
426 TRUE midimap.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
427 TRUE mintdh.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
428 TRUE miutils.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
429 TRUE miutils.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
430 TRUE mlang.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
431 TRUE mlang.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
432 TRUE mmdevapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
433 TRUE mmdevapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
434 TRUE mobilenetworking.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
435 TRUE mobilenetworking.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
436 TRUE mozglue.dll *\Program Files\SeaMonkey* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
437 TRUE mozglue.dll *\Program Files\Mozilla Firefox* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
438 TRUE mozglue.dll *\Program Files\Mozilla Thunderbird* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
439 TRUE mozglue.dll *\AppData\Local\Mozilla Firefox\* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
440 TRUE mpclient.dll *\Program Files\Windows Defender* T1574.002 https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
441 TRUE mpclient.dll *\ProgramData\Microsoft\Windows Defender\Platform\* T1574.002 https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
442 TRUE mpr.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
443 TRUE mpr.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
444 TRUE mprapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
445 TRUE mprapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
446 TRUE mpsvc.dll *\Program Files\Windows Defender\* T1574.002 https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
447 TRUE mpsvc.dll *\ProgramData\Microsoft\Windows Defender\Platform\* T1574.002 https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
448 TRUE mrmcorer.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
449 TRUE mrmcorer.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
450 TRUE msacm32.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
451 TRUE msacm32.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
452 TRUE mscms.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
453 TRUE mscms.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
454 TRUE mscoree.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
455 TRUE mscoree.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
456 TRUE mscorsvc.dll *\Windows\Microsoft.NET\Framework\v* T1574.002 https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
457 TRUE mscorsvc.dll *\Windows\Microsoft.NET\Framework64\v* T1574.002 https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
458 TRUE msctf.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
459 TRUE msctf.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
460 TRUE msctfmonitor.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
461 TRUE msctfmonitor.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
462 TRUE msdrm.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
463 TRUE msdrm.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
464 TRUE msdtctm.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
465 TRUE msftedit.dll *\Windows\System32\* T1574.002 https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
466 TRUE msftedit.dll *\Windows\SysWOW64\* T1574.002 https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
467 TRUE msi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
468 TRUE msi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
469 TRUE msiso.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
470 TRUE msiso.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
471 TRUE msutb.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
472 TRUE msutb.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
473 TRUE msvcp110_win.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
474 TRUE msvcp110_win.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
475 TRUE msvcr100.dll *\Windows\System32\* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
476 TRUE msvcr100.dll *\Windows\SysWOW64\* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
477 TRUE mswb7.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
478 TRUE mswb7.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
479 TRUE mswsock.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
480 TRUE mswsock.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
481 TRUE msxml3.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
482 TRUE msxml3.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
483 TRUE mtxclu.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
484 TRUE mtxclu.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
485 TRUE napinsp.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
486 TRUE napinsp.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
487 TRUE ncrypt.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
488 TRUE ncrypt.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
489 TRUE ndfapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
490 TRUE ndfapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
491 TRUE netapi32.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
492 TRUE netapi32.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
493 TRUE netid.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
494 TRUE netid.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
495 TRUE netiohlp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
496 TRUE netiohlp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
497 TRUE netjoin.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
498 TRUE netjoin.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
499 TRUE netplwiz.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
500 TRUE netplwiz.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
501 TRUE netprofm.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
502 TRUE netprofm.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
503 TRUE netprovfw.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
504 TRUE netprovfw.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
505 TRUE netsetupapi.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
506 TRUE netsetupapi.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
507 TRUE netshell.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
508 TRUE netshell.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
509 TRUE nettrace.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
510 TRUE netutils.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
511 TRUE netutils.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
512 TRUE networkexplorer.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
513 TRUE networkexplorer.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
514 TRUE newdev.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
515 TRUE newdev.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
516 TRUE ninput.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
517 TRUE ninput.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
518 TRUE nlaapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
519 TRUE nlaapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
520 TRUE nlansp_c.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
521 TRUE nlansp_c.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
522 TRUE npmproxy.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
523 TRUE npmproxy.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
524 TRUE nshhttp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
525 TRUE nshhttp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
526 TRUE nshipsec.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
527 TRUE nshipsec.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
528 TRUE nshwfp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
529 TRUE nshwfp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
530 TRUE ntdsapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
531 TRUE ntdsapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
532 TRUE ntlanman.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
533 TRUE ntlanman.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
534 TRUE ntlmshared.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
535 TRUE ntlmshared.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
536 TRUE ntmarta.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
537 TRUE ntmarta.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
538 TRUE ntshrui.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
539 TRUE ntshrui.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
540 TRUE nvsmartmax.dll *\Program Files\NVIDIA Corporation\Display* T1574.002 https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos
541 TRUE oleacc.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
542 TRUE oleacc.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
543 TRUE omadmapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
544 TRUE omadmapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
545 TRUE onex.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
546 TRUE onex.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
547 TRUE opcservices.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
548 TRUE opcservices.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
549 TRUE opera_elf.dll *\Appdata\local\programs\opera\* T1574.002 https://twitter.com/ShitSecure/status/1566127363389329412
550 TRUE osbaseln.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
551 TRUE osbaseln.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
552 TRUE osksupport.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
553 TRUE osuninst.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
554 TRUE osuninst.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
555 TRUE outllib.dll *\Program Files\Microsoft Office\OFFICE* T1574.002 https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
556 TRUE outllib.dll *\Program Files\Microsoft Office\Root\OFFICE* T1574.002 https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
557 TRUE p2p.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
558 TRUE p2p.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
559 TRUE p2pnetsh.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
560 TRUE p2pnetsh.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
561 TRUE p9np.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
562 TRUE p9np.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
563 TRUE pcaui.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
564 TRUE pcaui.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
565 TRUE pdh.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
566 TRUE pdh.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
567 TRUE peerdistsh.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
568 TRUE peerdistsh.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
569 TRUE pkeyhelper.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
570 TRUE pla.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
571 TRUE pla.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
572 TRUE playsndsrv.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
573 TRUE playsndsrv.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
574 TRUE pnrpnsp.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
575 TRUE pnrpnsp.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
576 TRUE policymanager.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
577 TRUE policymanager.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
578 TRUE polstore.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
579 TRUE polstore.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
580 TRUE powrprof.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
581 TRUE powrprof.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
582 TRUE printui.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
583 TRUE printui.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
584 TRUE prntvpt.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
585 TRUE prntvpt.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
586 TRUE profapi.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
587 TRUE profapi.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
588 TRUE propsys.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
589 TRUE propsys.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
590 TRUE proximitycommon.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
591 TRUE proximitycommon.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
592 TRUE proximityservicepal.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
593 TRUE prvdmofcomp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
594 TRUE prvdmofcomp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
595 TRUE puiapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
596 TRUE puiapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
597 TRUE python39.dll *\Program Files\Python39* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
598 TRUE python39.dll *\Appdata\local\Temp\* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
599 TRUE python39.dll *\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\CommonExtensions\Microsoft\VC\SecurityIssueAnalysis\python* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
600 TRUE python39.dll *\Users\anaconda3* T1574.002 https://twitter.com/SBousseaden/status/1530595156055011330
601 TRUE qrt.dll *\Program Files\F-Secure\Anti-Virus* T1574.002 https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/
602 TRUE radcui.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
603 TRUE radcui.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
604 TRUE rasapi32.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
605 TRUE rasapi32.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
606 TRUE rasdlg.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
607 TRUE rasdlg.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
608 TRUE rasgcw.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
609 TRUE rasgcw.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
610 TRUE rasman.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
611 TRUE rasman.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
612 TRUE rasmontr.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
613 TRUE rasmontr.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
614 TRUE rastls.dll *\Program Files\Symantec\Network Connected Devices Auto Setup* T1574.002 https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf
615 TRUE rcdll.dll *\Program Files\Windows Kits\10\bin\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
616 TRUE reagent.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
617 TRUE reagent.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
618 TRUE regapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
619 TRUE regapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
620 TRUE reseteng.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
621 TRUE resetengine.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
622 TRUE resutils.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
623 TRUE resutils.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
624 TRUE rjvplatform.dll *\Windows\System32\SystemResetPlatform* T1574.002 https://twitter.com/0gtweet/status/1666716511988330499
625 TRUE rjvplatform.dll *\Windows\SysWOW64\SystemResetPlatform* T1574.002 https://twitter.com/0gtweet/status/1666716511988330499
626 TRUE rmclient.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
627 TRUE rmclient.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
628 TRUE rpcnsh.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
629 TRUE rpcnsh.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
630 TRUE rsaenh.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
631 TRUE rsaenh.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
632 TRUE rtutils.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
633 TRUE rtutils.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
634 TRUE rtworkq.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
635 TRUE rtworkq.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
636 TRUE rzlog4cpp_logger.dll *\Appdata\local\razer\InGameEngine\cache\RzFpsApplet* T1574.002 https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia
637 TRUE safestore32.dll *\Program Files\Sophos\Sophos Anti-Virus* T1574.002 https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf
638 TRUE samcli.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
639 TRUE samcli.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
640 TRUE samlib.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
641 TRUE samlib.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
642 TRUE sapi_onecore.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
643 TRUE sapi_onecore.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
644 TRUE sas.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
645 TRUE sas.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
646 TRUE scansetting.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
647 TRUE scansetting.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
648 TRUE scecli.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
649 TRUE scecli.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
650 TRUE schedcli.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
651 TRUE schedcli.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
652 TRUE secur32.dll *\Windows\System32\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
653 TRUE secur32.dll *\Windows\SysWOW64\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
654 TRUE security.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
655 TRUE security.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
656 TRUE sensapi.dll *\Windows\System32\* T1574.002 https://twitter.com/AndrewOliveau/status/1682185200862625792
657 TRUE sensapi.dll *\Windows\SysWOW64\* T1574.002 https://twitter.com/AndrewOliveau/status/1682185200862625792
658 TRUE shell32.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
659 TRUE shell32.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
660 TRUE shfolder.dll *\Windows\System32\* T1574.002 https://twitter.com/dissectmalware/status/978017957480628226
661 TRUE shfolder.dll *\Windows\SysWOW64\* T1574.002 https://twitter.com/dissectmalware/status/978017957480628226
662 TRUE siteadv.dll *\Program Files\SiteAdvisor\* T1574.002 https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf
663 TRUE slc.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
664 TRUE slc.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
665 TRUE smadhook32c.dll *\Program Files\Smadav* T1574.002 https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
666 TRUE snmpapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
667 TRUE snmpapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
668 TRUE spectrumsyncclient.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
669 TRUE spp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
670 TRUE spp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
671 TRUE sppc.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
672 TRUE sppc.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
673 TRUE sppcext.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
674 TRUE sppcext.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
675 TRUE srclient.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
676 TRUE srclient.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
677 TRUE srcore.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
678 TRUE srmtrace.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
679 TRUE srmtrace.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
680 TRUE srpapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
681 TRUE srpapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
682 TRUE srvcli.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
683 TRUE srvcli.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
684 TRUE ssp.exe_rsaenh.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
685 TRUE ssp.exe_rsaenh.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
686 TRUE ssp_isv.exe_rsaenh.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
687 TRUE ssp_isv.exe_rsaenh.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
688 TRUE sspicli.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
689 TRUE sspicli.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
690 TRUE ssshim.dll *\Windows\System32\* T1574.002 https://twitter.com/0gtweet/status/1363107343018385410
691 TRUE ssshim.dll *\Windows\SysWOW64\* T1574.002 https://twitter.com/0gtweet/status/1363107343018385410
692 TRUE staterepository.core.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
693 TRUE staterepository.core.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
694 TRUE structuredquery.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
695 TRUE structuredquery.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
696 TRUE sxshared.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
697 TRUE sxshared.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
698 TRUE symsrv.dll *\Program Files\Windows Kits\10\Debuggers\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
699 TRUE systemsettingsthresholdadminflowui.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
700 TRUE tapi32.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
701 TRUE tapi32.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
702 TRUE tbs.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
703 TRUE tbs.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
704 TRUE tdh.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
705 TRUE tdh.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
706 TRUE textshaping.dll *\Windows\System32\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
707 TRUE textshaping.dll *\Windows\SysWOW64\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
708 TRUE timesync.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
709 TRUE tmdbglog.dll *\Program Files\Trend Micro\Titanium* T1574.002 https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/
710 TRUE tosbtkbd.dll *\Program Files\Toshiba\Bluetooth Toshiba Stack* T1574.002 https://www.secureworks.com/research/shadowpad-malware-analysis
711 TRUE tpmcoreprovisioning.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
712 TRUE tpmcoreprovisioning.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
713 TRUE tquery.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
714 TRUE tquery.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
715 TRUE tsworkspace.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
716 TRUE tsworkspace.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
717 TRUE ttdrecord.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
718 TRUE ttdrecord.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
719 TRUE twext.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
720 TRUE twext.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
721 TRUE twinapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
722 TRUE twinapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/save-the-environment-variables
723 TRUE twinui.appcore.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
724 TRUE twinui.appcore.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
725 TRUE uianimation.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
726 TRUE uianimation.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
727 TRUE uiautomationcore.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
728 TRUE uiautomationcore.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
729 TRUE uireng.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
730 TRUE uireng.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
731 TRUE uiribbon.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
732 TRUE uiribbon.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
733 TRUE umpdc.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
734 TRUE umpdc.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
735 TRUE unattend.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
736 TRUE unityplayer.dll *\Appdata\local\Temp\* T1574.002 https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
737 TRUE updatepolicy.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
738 TRUE updatepolicy.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
739 TRUE upshared.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
740 TRUE urlmon.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
741 TRUE urlmon.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
742 TRUE userenv.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
743 TRUE userenv.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
744 TRUE utildll.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
745 TRUE utildll.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
746 TRUE uxinit.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
747 TRUE uxinit.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
748 TRUE uxtheme.dll *\Windows\System32\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
749 TRUE uxtheme.dll *\Windows\SysWOW64\* T1574.001 https://wietze.github.io/blog/hijacking-dlls-in-windows
750 TRUE vaultcli.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
751 TRUE vaultcli.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
752 TRUE vdsutil.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
753 TRUE vdsutil.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
754 TRUE vender.dll *\Program Files\ASUS\GPU TweakII* T1574.002 https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
755 TRUE vender.dll *\Program Files\ASUS\VGA COM\* T1574.002 https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
756 TRUE version.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
757 TRUE version.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
758 TRUE vftrace.dll *\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x32* T1574.002 https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
759 TRUE vftrace.dll *\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x64* T1574.002 https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
760 TRUE vftrace.dll *\Program Files\CyberArk\Endpoint Privilege Manager\Agent* T1574.002 https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
761 TRUE virtdisk.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
762 TRUE virtdisk.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
763 TRUE vivaldi_elf.dll *\Appdata\local\Vivaldi\Application* T1574.002 https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
764 TRUE vivaldi_elf.dll *\Appdata\local\Vivaldi\Application\* T1574.002 https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
765 TRUE vntfxf32.dll *\Program Files\Venta\VentaFax &amp; Voice* T1574.002 https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
766 TRUE vsodscpl.dll *\Program Files\McAfee\VirusScan Enterprise* T1574.002 https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/
767 TRUE vssapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
768 TRUE vssapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
769 TRUE vsstrace.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
770 TRUE vsstrace.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
771 TRUE wbemprox.dll *\Windows\System32\wbem* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
772 TRUE wbemprox.dll *\Windows\SysWOW64\wbem* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
773 TRUE wbemsvc.dll *\Windows\System32\wbem* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
774 TRUE wbemsvc.dll *\Windows\SysWOW64\wbem* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
775 TRUE wcmapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
776 TRUE wcmapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
777 TRUE wcnnetsh.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
778 TRUE wdi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
779 TRUE wdi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
780 TRUE wdscore.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
781 TRUE wdscore.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
782 TRUE webservices.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
783 TRUE webservices.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
784 TRUE wecapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
785 TRUE wecapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
786 TRUE wer.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
787 TRUE wer.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
788 TRUE wevtapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
789 TRUE wevtapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
790 TRUE whhelper.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
791 TRUE whhelper.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
792 TRUE wimgapi.dll *\Windows\System32\* T1574.002 https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
793 TRUE wimgapi.dll *\Windows\SysWOW64\* T1574.002 https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
794 TRUE wimgapi.dll *\Program Files\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\arm64\DISM* T1574.002 https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
795 TRUE winbio.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
796 TRUE winbio.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
797 TRUE winbrand.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
798 TRUE winbrand.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
799 TRUE windows.storage.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
800 TRUE windows.storage.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
801 TRUE windows.storage.search.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
802 TRUE windows.storage.search.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
803 TRUE windows.ui.immersive.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
804 TRUE windows.ui.immersive.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
805 TRUE windowscodecs.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
806 TRUE windowscodecs.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
807 TRUE windowscodecsext.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
808 TRUE windowscodecsext.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
809 TRUE windowsperformancerecordercontrol.dll *\Program Files\windows kits\10\windows performance toolkit* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
810 TRUE windowsperformancerecordercontrol.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
811 TRUE windowsperformancerecordercontrol.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
812 TRUE windowsperformancerecorderui.dll *\Program Files\Windows Kits\10\Windows Performance Toolkit* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
813 TRUE windowsudk.shellcommon.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
814 TRUE windowsudk.shellcommon.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
815 TRUE winhttp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
816 TRUE winhttp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
817 TRUE wininet.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
818 TRUE wininet.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
819 TRUE winipsec.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
820 TRUE winipsec.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
821 TRUE winmde.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
822 TRUE winmm.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
823 TRUE winmm.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
824 TRUE winnsi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
825 TRUE winnsi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
826 TRUE winrnr.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
827 TRUE winrnr.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
828 TRUE winscard.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
829 TRUE winscard.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
830 TRUE winsqlite3.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
831 TRUE winsqlite3.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
832 TRUE winsta.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
833 TRUE winsta.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
834 TRUE winsync.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
835 TRUE winsync.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
836 TRUE winutils.dll *\Program Files\Palo Alto Networks\Traps* T1574.002 https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/
837 TRUE wkscli.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
838 TRUE wkscli.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
839 TRUE wlanapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
840 TRUE wlanapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
841 TRUE wlancfg.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
842 TRUE wlancfg.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
843 TRUE wldp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
844 TRUE wldp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
845 TRUE wlidprov.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
846 TRUE wlidprov.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
847 TRUE wmiclnt.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
848 TRUE wmiclnt.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
849 TRUE wmidcom.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
850 TRUE wmidcom.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
851 TRUE wmiutils.dll *\Windows\System32\wbem* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
852 TRUE wmiutils.dll *\Windows\SysWOW64\wbem* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
853 TRUE wmpdui.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
854 TRUE wmsgapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
855 TRUE wmsgapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
856 TRUE wofutil.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
857 TRUE wofutil.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
858 TRUE wpdshext.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
859 TRUE wpdshext.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
860 TRUE wsc.dll *\Program Files\AVAST Software\Avast* T1574.001 https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2
861 TRUE wscapi.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
862 TRUE wscapi.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
863 TRUE wsdapi.dll *\Windows\System32\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
864 TRUE wsdapi.dll *\Windows\SysWOW64\* T1574.002 https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
865 TRUE wshbth.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
866 TRUE wshbth.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
867 TRUE wshelper.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
868 TRUE wshelper.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
869 TRUE wsmsvc.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
870 TRUE wsmsvc.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
871 TRUE wtsapi32.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
872 TRUE wtsapi32.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
873 TRUE wwancfg.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
874 TRUE wwancfg.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
875 TRUE wwapi.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
876 TRUE wwapi.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
877 TRUE xmllite.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
878 TRUE xmllite.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
879 TRUE xolehlp.dll *\Windows\System32\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
880 TRUE xolehlp.dll *\Windows\SysWOW64\* T1574.002 https://wietze.github.io/blog/hijacking-dlls-in-windows
881 TRUE xpsservices.dll *\Windows\System32\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
882 TRUE xpsservices.dll *\Windows\SysWOW64\* T1574.002 https://securityintelligence.com/posts/windows-features-dll-sideloading/
883 TRUE xwizards.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
884 TRUE xwizards.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
885 TRUE xwtpw32.dll *\Windows\System32\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
886 TRUE xwtpw32.dll *\Windows\SysWOW64\* T1574.007 https://wietze.github.io/blog/save-the-environment-variables
@@ -1,3 +0,0 @@
image, repository
devsecops/cat_dog_client, splunk/devsecops_poc
devsecops/cat_dog_server, splunk/devsecops_poc
1 image repository
2 devsecops/cat_dog_client splunk/devsecops_poc
3 devsecops/cat_dog_server splunk/devsecops_poc
@@ -1,47 +0,0 @@
filename,originalFileName,netFile
MSBuild.exe,MSBuild.exe,True
ComSvcConfig.exe,ComSvcConfig.exe,True
DfsrAdmin.exe,DfsrAdmin.exe,True
dfsvc.exe,dfsvc.exe,True
Microsoft.Workflow.Compiler.exe,Microsoft.Workflow.Compiler.exe,True
SMSvcHost.exe,SMSvcHost.exe,True
WsatConfig.exe,WsatConfig.exe,True
AddInProcess.exe,AddInProcess.exe,True
AddInProcess32.exe,AddInProcess32.exe,True
AddInUtil.exe,AddInUtil.exe,True
aspnet_compiler.exe,aspnet_compiler.exe,True
aspnet_regbrowsers.exe,aspnet_regbrowsers.exe,True
aspnet_regsql.exe,aspnet_regsql.exe,True
CasPol.exe,CasPol.exe,True
DataSvcUtil.exe,DataSvcUtil.exe,True
EdmGen.exe,EdmGen.exe,True
InstallUtil.exe,InstallUtil.exe,True
jsc.exe,jsc.exe,True
ngentask.exe,ngentask.exe,True
ngen.exe,ngen.exe,True
RegAsm.exe,RegAsm.exe,True
RegSvcs.exe,RegSvcs.exe,True
SDNBR.exe,SDNBR.exe,True
acu.exe,acu.exe,True
AppVStreamingUX.exe,,True
dsac.exe,dsac.exe,True
LbfoAdmin.exe,LBFOADMIN.EXE,True
Microsoft.Uev.SyncController.exe,Microsoft.Uev.SyncController.exe,True
mtedit.exe,mtedit.exe,True
ScriptRunner.exe,ScriptRunner.exe,True
ServerManager.exe,servermanager.dll,True
stordiag.exe,stordiag.exe,True
storeadm.exe,storeadm.exe,True
tzsync.exe,tzsync.exe,True
UevAgentPolicyGenerator.exe,UevAgentPolicyGenerator.exe,True
UevAppMonitor.exe,UevAppMonitor.exe,True
UevTemplateBaselineGenerator.exe,UevTemplateBaselineGenerator.exe,True
UevTemplateConfigItemGenerator.exe,UevTemplateConfigItemGenerator.exe,True
powershell_ise.exe,powershell_ise.EXE,True
iediagcmd.exe,IEDiagCmd.exe,True
XBox.TCUI.exe,XBox.TCUI.exe,True
Microsoft.ActiveDirectory.WebServices.exe,Microsoft.ActiveDirectory.WebServices.exe,True
iisual.exe,iisual.exe,True
FileHistory.exe,FileHistory.exe,True
SecureAssessmentBrowser.exe,SecureAssessmentBrowser.exe,True
aspnet_regiis.exe,aspnet_regiis.exe,True
1 filename originalFileName netFile
2 MSBuild.exe MSBuild.exe True
3 ComSvcConfig.exe ComSvcConfig.exe True
4 DfsrAdmin.exe DfsrAdmin.exe True
5 dfsvc.exe dfsvc.exe True
6 Microsoft.Workflow.Compiler.exe Microsoft.Workflow.Compiler.exe True
7 SMSvcHost.exe SMSvcHost.exe True
8 WsatConfig.exe WsatConfig.exe True
9 AddInProcess.exe AddInProcess.exe True
10 AddInProcess32.exe AddInProcess32.exe True
11 AddInUtil.exe AddInUtil.exe True
12 aspnet_compiler.exe aspnet_compiler.exe True
13 aspnet_regbrowsers.exe aspnet_regbrowsers.exe True
14 aspnet_regsql.exe aspnet_regsql.exe True
15 CasPol.exe CasPol.exe True
16 DataSvcUtil.exe DataSvcUtil.exe True
17 EdmGen.exe EdmGen.exe True
18 InstallUtil.exe InstallUtil.exe True
19 jsc.exe jsc.exe True
20 ngentask.exe ngentask.exe True
21 ngen.exe ngen.exe True
22 RegAsm.exe RegAsm.exe True
23 RegSvcs.exe RegSvcs.exe True
24 SDNBR.exe SDNBR.exe True
25 acu.exe acu.exe True
26 AppVStreamingUX.exe True
27 dsac.exe dsac.exe True
28 LbfoAdmin.exe LBFOADMIN.EXE True
29 Microsoft.Uev.SyncController.exe Microsoft.Uev.SyncController.exe True
30 mtedit.exe mtedit.exe True
31 ScriptRunner.exe ScriptRunner.exe True
32 ServerManager.exe servermanager.dll True
33 stordiag.exe stordiag.exe True
34 storeadm.exe storeadm.exe True
35 tzsync.exe tzsync.exe True
36 UevAgentPolicyGenerator.exe UevAgentPolicyGenerator.exe True
37 UevAppMonitor.exe UevAppMonitor.exe True
38 UevTemplateBaselineGenerator.exe UevTemplateBaselineGenerator.exe True
39 UevTemplateConfigItemGenerator.exe UevTemplateConfigItemGenerator.exe True
40 powershell_ise.exe powershell_ise.EXE True
41 iediagcmd.exe IEDiagCmd.exe True
42 XBox.TCUI.exe XBox.TCUI.exe True
43 Microsoft.ActiveDirectory.WebServices.exe Microsoft.ActiveDirectory.WebServices.exe True
44 iisual.exe iisual.exe True
45 FileHistory.exe FileHistory.exe True
46 SecureAssessmentBrowser.exe SecureAssessmentBrowser.exe True
47 aspnet_regiis.exe aspnet_regiis.exe True
@@ -1,15 +0,0 @@
filename,nirsoftFile
AdvancedRun.exe,True
ChromePass.exe,True
CredHistView.exe,True
Dialupass.exe,True
iepv.exe,True
LostMyPassword.exe,True
mailpv.exe,True
mspass.exe,True
netpass.exe,True
PasswordFox.exe,True
PasswordHashesView.exe,True
PstPassword.exe,True
RegHiveBackup.exe,True
WebBrowserPassView.exe,True
1 filename nirsoftFile
2 AdvancedRun.exe True
3 ChromePass.exe True
4 CredHistView.exe True
5 Dialupass.exe True
6 iepv.exe True
7 LostMyPassword.exe True
8 mailpv.exe True
9 mspass.exe True
10 netpass.exe True
11 PasswordFox.exe True
12 PasswordHashesView.exe True
13 PstPassword.exe True
14 RegHiveBackup.exe True
15 WebBrowserPassView.exe True
@@ -1,52 +0,0 @@
file_name,suspicious
*.avi.com,true
*.avi.exe,true
*.doc.com,true
*.doc.exe,true
*.docx.com,true
*.docx.exe,true
*.jpg.com,true
*.jpg.exe,true
*.jpeg.com,true
*.jpeg.exe,true
*.mpg.com,true
*.mpg.exe,true
*.mpg2.com,true
*.mpg2.exe,true
*.mpeg.com,true
*.mpeg.exe,true
*.pdf.com,true
*.pdf.exe,true
*.png.com,true
*.png.exe,true
*.ppt.com,true
*.ppt.exe,true
*.pptx.com,true
*.pptx.exe,true
*.swf.com,true
*.swf.exe,true
*.xls.com,true
*.xls.exe,true
*.xlsx.com,true
*.xlsx.exe,true
*.zip.com,true
*.zip.exe,true
*.bat,true
*.chm,true
*.com,true
*.cmd,true
*.cpl,true
*.exe,true
*.hlp,true
*.hta,true
*.jar,true
*.js,true
*.msi,true
*.pif,true
*.ps1,true
*.rar,true
*.reg,true
*.scr,true
*.vbe,true
*.vbs,true
*.wsf,true
1 file_name suspicious
2 *.avi.com true
3 *.avi.exe true
4 *.doc.com true
5 *.doc.exe true
6 *.docx.com true
7 *.docx.exe true
8 *.jpg.com true
9 *.jpg.exe true
10 *.jpeg.com true
11 *.jpeg.exe true
12 *.mpg.com true
13 *.mpg.exe true
14 *.mpg2.com true
15 *.mpg2.exe true
16 *.mpeg.com true
17 *.mpeg.exe true
18 *.pdf.com true
19 *.pdf.exe true
20 *.png.com true
21 *.png.exe true
22 *.ppt.com true
23 *.ppt.exe true
24 *.pptx.com true
25 *.pptx.exe true
26 *.swf.com true
27 *.swf.exe true
28 *.xls.com true
29 *.xls.exe true
30 *.xlsx.com true
31 *.xlsx.exe true
32 *.zip.com true
33 *.zip.exe true
34 *.bat true
35 *.chm true
36 *.com true
37 *.cmd true
38 *.cpl true
39 *.exe true
40 *.hlp true
41 *.hta true
42 *.jar true
43 *.js true
44 *.msi true
45 *.pif true
46 *.ps1 true
47 *.rar true
48 *.reg true
49 *.scr true
50 *.vbe true
51 *.vbs true
52 *.wsf true
@@ -1,753 +0,0 @@
filename,systemFile
acu.exe,true
AgentService.exe,true
aitstatic.exe,true
alg.exe,true
AppHostRegistrationVerifier.exe,true
appidcertstorecheck.exe,true
appidpolicyconverter.exe,true
appidtel.exe,true
ApplicationFrameHost.exe,true
ApplySettingsTemplateCatalog.exe,true
AppVClient.exe,true
AppVDllSurrogate.exe,true
AppVNice.exe,true
AppVStreamingUX.exe,true
ARP.EXE,true
at.exe,true
AtBroker.exe,true
attrib.exe,true
audiodg.exe,true
auditpol.exe,true
AuthHost.exe,true
autochk.exe,true
autoconv.exe,true
autofmt.exe,true
AxInstUI.exe,true
backgroundTaskHost.exe,true
BackgroundTransferHost.exe,true
bcastdvr.exe,true
bcdboot.exe,true
bcdedit.exe,true
BioIso.exe,true
bitsadmin.exe,true
bootcfg.exe,true
bootim.exe,true
bridgeunattend.exe,true
browser_broker.exe,true
bthudtask.exe,true
ByteCodeGenerator.exe,true
cacls.exe,true
calc.exe,true
CameraSettingsUIHost.exe,true
CastSrv.exe,true
CertEnrollCtrl.exe,true
certreq.exe,true
certutil.exe,true
change.exe,true
changepk.exe,true
charmap.exe,true
CheckNetIsolation.exe,true
chglogon.exe,true
chgport.exe,true
chgusr.exe,true
chkdsk.exe,true
chkntfs.exe,true
choice.exe,true
cipher.exe,true
cleanmgr.exe,true
cliconfg.exe,true
clip.exe,true
ClipUp.exe,true
CloudExperienceHostBroker.exe,true
CloudNotifications.exe,true
CloudStorageWizard.exe,true
cmd.exe,true
cmdkey.exe,true
cmdl32.exe,true
cmmon32.exe,true
cmstp.exe,true
cofire.exe,true
colorcpl.exe,true
comp.exe,true
compact.exe,true
CompatTelRunner.exe,true
CompMgmtLauncher.exe,true
ComputerDefaults.exe,true
Configure-SMRemoting.exe,true
conhost.exe,true
consent.exe,true
control.exe,true
convert.exe,true
CredentialUIBroker.exe,true
credwiz.exe,true
cscript.exe,true
csrss.exe,true
ctfmon.exe,true
cttune.exe,true
cttunesvr.exe,true
dasHost.exe,true
DataExchangeHost.exe,true
DataSenseLiveTileTask.exe,true
dccw.exe,true
dcgpofix.exe,true
dcomcnfg.exe,true
dcpromo.exe,true
ddodiag.exe,true
Defrag.exe,true
DeviceCensus.exe,true
DeviceEject.exe,true
DeviceEnroller.exe,true
DevicePairingWizard.exe,true
DeviceProperties.exe,true
DFDWiz.exe,true
dfrgui.exe,true
dfsrdiag.exe,true
dialer.exe,true
DIMC.exe,true
diskpart.exe,true
diskperf.exe,true
diskraid.exe,true
diskshadow.exe,true
DiskSnapshot.exe,true
Dism.exe,true
dispdiag.exe,true
DisplaySwitch.exe,true
djoin.exe,true
dllhost.exe,true
dllhst3g.exe,true
dmcertinst.exe,true
dmcfghost.exe,true
DmNotificationBroker.exe,true
DmOmaCpMo.exe,true
dnscacheugc.exe,true
doskey.exe,true
dpapimig.exe,true
DpiScaling.exe,true
dpnsvr.exe,true
driverquery.exe,true
drvcfg.exe,true
drvinst.exe,true
DsmUserTask.exe,true
dsregcmd.exe,true
dstokenclean.exe,true
dvdplay.exe,true
dwm.exe,true
DWWIN.EXE,true
dxdiag.exe,true
Dxpserver.exe,true
Eap3Host.exe,true
EaseOfAccessDialog.exe,true
easinvoker.exe,true
EasPoliciesBrokerHost.exe,true
EDPCleanup.exe,true
edpnotify.exe,true
efsui.exe,true
EhStorAuthn.exe,true
embeddedapplauncher.exe,true
EmbeddedAppLauncherConfig.exe,true
escUnattend.exe,true
esentutl.exe,true
eudcedit.exe,true
eventcreate.exe,true
eventvwr.exe,true
expand.exe,true
extrac32.exe,true
fc.exe,true
find.exe,true
findstr.exe,true
finger.exe,true
fixmapi.exe,true
fltMC.exe,true
fodhelper.exe,true
Fondue.exe,true
fontdrvhost.exe,true
fontview.exe,true
forfiles.exe,true
fsavailux.exe,true
fsquirt.exe,true
fsutil.exe,true
ftp.exe,true
GameBarPresenceWriter.exe,true
GamePanel.exe,true
GenValObj.exe,true
getmac.exe,true
gpresult.exe,true
gpscript.exe,true
gpupdate.exe,true
grpconv.exe,true
hdwwiz.exe,true
help.exe,true
HOSTNAME.EXE,true
hvax64.exe,true
hvix64.exe,true
hvloader.exe,true
hwrcomp.exe,true
hwrreg.exe,true
iashost.exe,true
icacls.exe,true
IcsEntitlementHost.exe,true
icsunattend.exe,true
ie4uinit.exe,true
ieUnatt.exe,true
iexpress.exe,true
immersivetpmvscmgrsvr.exe,true
InfDefaultInstall.exe,true
InstallAgent.exe,true
InstallAgentUserBroker.exe,true
ipconfig.exe,true
iscsicli.exe,true
iscsicpl.exe,true
isoburn.exe,true
klist.exe,true
ksetup.exe,true
ktmutil.exe,true
ktpass.exe,true
label.exe,true
LanguageComponentsInstallerComHandler.exe,true
LaunchTM.exe,true
LaunchWinApp.exe,true
LbfoAdmin.exe,true
LegacyNetUXHost.exe,true
LicenseManagerShellext.exe,true
licensingdiag.exe,true
LicensingUI.exe,true
LocationNotificationWindows.exe,true
Locator.exe,true
LockAppHost.exe,true
LockScreenContentServer.exe,true
lodctr.exe,true
logagent.exe,true
logman.exe,true
logoff.exe,true
LogonUI.exe,true
lpkinstall.exe,true
lpksetup.exe,true
lpremove.exe,true
LsaIso.exe,true
lsass.exe,true
Magnify.exe,true
makecab.exe,true
mavinject.exe,true
MbaeParserTask.exe,true
mblctr.exe,true
mcbuilder.exe,true
MDEServer.exe,true
MDMAgent.exe,true
MDMAppInstaller.exe,true
MdmDiagnosticsTool.exe,true
MdRes.exe,true
MdSched.exe,true
mfpmp.exe,true
Microsoft.Uev.CscUnpinTool.exe,true
Microsoft.Uev.SyncController.exe,true
mmc.exe,true
mobsync.exe,true
mountvol.exe,true
mpnotify.exe,true
MpSigStub.exe,true
MRINFO.EXE,true
MRT-KB890830.exe,true
MRT.exe,true
MSchedExe.exe,true
msconfig.exe,true
msdt.exe,true
msdtc.exe,true
msfeedssync.exe,true
msg.exe,true
mshta.exe,true
msiexec.exe,true
msinfo32.exe,true
mspaint.exe,true
MsSpellCheckingHost.exe,true
mstsc.exe,true
mtstocom.exe,true
MuiUnattend.exe,true
MultiDigiMon.exe,true
MusNotification.exe,true
MusNotificationUx.exe,true
Narrator.exe,true
nbtstat.exe,true
ndadmin.exe,true
net.exe,true
net1.exe,true
netbtugc.exe,true
netcfg.exe,true
NetCfgNotifyObjectHost.exe,true
netdom.exe,true
NetEvtFwdr.exe,true
NetHost.exe,true
netiougc.exe,true
Netplwiz.exe,true
netsh.exe,true
NETSTAT.EXE,true
newdev.exe,true
nltest.exe,true
notepad.exe,true
nslookup.exe,true
ntoskrnl.exe,true
ntprint.exe,true
odbcad32.exe,true
odbcconf.exe,true
omadmclient.exe,true
omadmprc.exe,true
openfiles.exe,true
OpenWith.exe,true
OptionalFeatures.exe,true
osk.exe,true
PackagedCWALauncher.exe,true
PackageInspector.exe,true
PasswordOnWakeSettingFlyout.exe,true
PATHPING.EXE,true
pcalua.exe,true
pcaui.exe,true
pcwrun.exe,true
perfmon.exe,true
phoneactivate.exe,true
PickerHost.exe,true
PING.EXE,true
PkgMgr.exe,true
plasrv.exe,true
PnPUnattend.exe,true
pnputil.exe,true
poqexec.exe,true
powercfg.exe,true
PresentationHost.exe,true
PresentationSettings.exe,true
prevhost.exe,true
print.exe,true
PrintBrmUi.exe,true
PrintDialogHost.exe,true
PrintDialogHost3D.exe,true
printfilterpipelinesvc.exe,true
PrintIsolationHost.exe,true
printui.exe,true
proquota.exe,true
psr.exe,true
pwlauncher.exe,true
qappsrv.exe,true
qprocess.exe,true
query.exe,true
quser.exe,true
qwinsta.exe,true
rasdial.exe,true
rdpclip.exe,true
rdpinit.exe,true
rdpinput.exe,true
RdpSa.exe,true
RdpSaProxy.exe,true
RdpSaUacHelper.exe,true
rdpshell.exe,true
rdpsign.exe,true
rdrleakdiag.exe,true
RDSPnf.exe,true
ReAgentc.exe,true
recover.exe,true
RecoveryDrive.exe,true
reg.exe,true
regedt32.exe,true
regini.exe,true
Register-CimProvider.exe,true
regsvr32.exe,true
rekeywiz.exe,true
relog.exe,true
RelPost.exe,true
RemotePosWorker.exe,true
replace.exe,true
reset.exe,true
ResetEngine.exe,true
resmon.exe,true
RMActivate.exe,true
RMActivate_isv.exe,true
RMActivate_ssp.exe,true
RMActivate_ssp_isv.exe,true
RmClient.exe,true
rmttpmvscmgrsvr.exe,true
Robocopy.exe,true
ROUTE.EXE,true
RpcPing.exe,true
rrinstaller.exe,true
rsopprov.exe,true
runas.exe,true
rundll32.exe,true
RunLegacyCPLElevated.exe,true
runonce.exe,true
RuntimeBroker.exe,true
rwinsta.exe,true
sacsess.exe,true
sc.exe,true
schtasks.exe,true
ScriptRunner.exe,true
sdbinst.exe,true
sdiagnhost.exe,true
SearchFilterHost.exe,true
SearchIndexer.exe,true
SearchProtocolHost.exe,true
SecEdit.exe,true
secinit.exe,true
securekernel.exe,true
SensorDataService.exe,true
ServerManager.exe,true
ServerManagerLauncher.exe,true
services.exe,true
sessionmsg.exe,true
sethc.exe,true
setres.exe,true
setspn.exe,true
SettingSyncHost.exe,true
setupcl.exe,true
setupugc.exe,true
setx.exe,true
sfc.exe,true
shrpubw.exe,true
shutdown.exe,true
sigverif.exe,true
SIHClient.exe,true
sihost.exe,true
SlideToShutDown.exe,true
slui.exe,true
smartscreen.exe,true
SmartScreenSettings.exe,true
smss.exe,true
SndVol.exe,true
SnippingTool.exe,true
snmptrap.exe,true
sort.exe,true
SpaceAgent.exe,true
spaceman.exe,true
spoolsv.exe,true
SppExtComObj.Exe,true
sppsvc.exe,true
stordiag.exe,true
subst.exe,true
svchost.exe,true
sxstrace.exe,true
SyncAppvPublishingServer.exe,true
SyncHost.exe,true
syskey.exe,true
SysResetErr.exe,true
systeminfo.exe,true
SystemPropertiesAdvanced.exe,true
SystemPropertiesComputerName.exe,true
SystemPropertiesDataExecutionPrevention.exe,true
SystemPropertiesHardware.exe,true
SystemPropertiesPerformance.exe,true
SystemPropertiesProtection.exe,true
SystemPropertiesRemote.exe,true
systemreset.exe,true
SystemSettingsAdminFlows.exe,true
SystemSettingsBroker.exe,true
SystemSettingsRemoveDevice.exe,true
systray.exe,true
tabcal.exe,true
takeown.exe,true
TapiUnattend.exe,true
taskhostw.exe,true
taskkill.exe,true
tasklist.exe,true
Taskmgr.exe,true
tcmsetup.exe,true
TCPSVCS.EXE,true
tdlrecover.exe,true
ThumbnailExtractionHost.exe,true
TieringEngineService.exe,true
timeout.exe,true
TokenBrokerCookies.exe,true
TpmInit.exe,true
tpmvscmgr.exe,true
tpmvscmgrsvr.exe,true
tracerpt.exe,true
TRACERT.EXE,true
tscon.exe,true
tsdiscon.exe,true
tsecimp.exe,true
tskill.exe,true
TSTheme.exe,true
TSWbPrxy.exe,true
typeperf.exe,true
tzsync.exe,true
tzutil.exe,true
ucsvc.exe,true
UevAgentPolicyGenerator.exe,true
UevAppMonitor.exe,true
UevTemplateBaselineGenerator.exe,true
UevTemplateConfigItemGenerator.exe,true
UI0Detect.exe,true
unlodctr.exe,true
unregmp2.exe,true
UpgradeResultsUI.exe,true
upnpcont.exe,true
UserAccountBroker.exe,true
UserAccountControlSettings.exe,true
userinit.exe,true
UsoClient.exe,true
Utilman.exe,true
VaultCmd.exe,true
vds.exe,true
vdsldr.exe,true
verclsid.exe,true
verifier.exe,true
verifiergui.exe,true
vssadmin.exe,true
VSSUIRUN.exe,true
VSSVC.exe,true
w32tm.exe,true
waitfor.exe,true
WallpaperHost.exe,true
WebCache.exe,true
wecutil.exe,true
WerFault.exe,true
WerFaultSecure.exe,true
wermgr.exe,true
wevtutil.exe,true
wextract.exe,true
where.exe,true
whoami.exe,true
wiaacmgr.exe,true
wiawow64.exe,true
wimserv.exe,true
win32calc.exe,true
WinBioDataModelOOBE.exe,true
Windows.Media.BackgroundPlayback.exe,true
WindowsActionDialog.exe,true
WindowsUpdateElevatedInstaller.exe,true
wininit.exe,true
winload.exe,true
winlogon.exe,true
winresume.exe,true
winrs.exe,true
winrshost.exe,true
WinSAT.exe,true
winver.exe,true
wkspbroker.exe,true
wksprt.exe,true
wlrmdr.exe,true
WMPDMC.exe,true
wowreg32.exe,true
WPDShextAutoplay.exe,true
wpr.exe,true
write.exe,true
WSCollect.exe,true
wscript.exe,true
WSManHTTPConfig.exe,true
wsmprovhost.exe,true
wsqmcons.exe,true
WSReset.exe,true
wuapihost.exe,true
wuauclt.exe,true
WUDFHost.exe,true
wusa.exe,true
WWAHost.exe,true
XblGameSaveTask.exe,true
xcopy.exe,true
xwizard.exe,true
comrepl.exe,true
MigRegDB.exe,true
DiagnosticsHub.StandardCollector.Service.exe,true
DismHost.exe,true
F12Chooser.exe,true
IMJPDCT.EXE,true
IMJPSET.EXE,true
IMJPUEX.EXE,true
imjpuexc.exe,true
IMTCLNWZ.EXE,true
IMTCPROP.exe,true
IMCCPHR.exe,true
ImeBroker.exe,true
imecfmui.exe,true
IMEDICTUPDATEUI.EXE,true
IMEPADSV.EXE,true
IMESEARCH.EXE,true
IMEWDBLD.EXE,true
ChsIME.exe,true
ChtIME.exe,true
mighost.exe,true
audit.exe,true
AuditShD.exe,true
FirstLogonAnim.exe,true
msoobe.exe,true
oobeldr.exe,true
Setup.exe,true
UserOOBEBroker.exe,true
windeploy.exe,true
SpeechUXWiz.exe,true
SpeechModelDownload.exe,true
SpeechRuntime.exe,true
PrintBrm.exe,true
PrintBrmEngine.exe,true
sysprep.exe,true
SystemResetPlatform.exe,true
mofcomp.exe,true
scrcons.exe,true
unsecapp.exe,true
wbemtest.exe,true
WinMgmt.exe,true
WMIADAP.exe,true
WmiApSrv.exe,true
WMIC.exe,true
WmiPrvSE.exe,true
powershell.exe,true
powershell_ise.exe,true
dplaysvr.exe,true
dtdump.exe,true
hh.exe,true
instnm.exe,true
perfhost.exe,true
rasautou.exe,true
rasphone.exe,true
regedit.exe,true
setup16.exe,true
user.exe,true
_isdel.exe,true
agentactivationruntimestarter.exe,true
ApplyTrustOffline.exe,true
ApproveChildRequest.exe,true
appverif.exe,true
baaupdate.exe,true
bash.exe,true
bdechangepin.exe,true
BdeHdCfg.exe,true
BdeUISrv.exe,true
bdeunlock.exe,true
BitLockerDeviceEncryption.exe,true
BitLockerWizard.exe,true
BitLockerWizardElev.exe,true
bootsect.exe,true
browserexport.exe,true
CIDiag.exe,true
CompPkgSrv.exe,true
convertvhd.exe,true
coredpussvr.exe,true
CredentialEnrollmentManager.exe,true
curl.exe,true
CustomInstallExec.exe,true
d3dconfig.exe,true
DataStoreCacheDumpTool.exe,true
DataUsageLiveTileTask.exe,true
deploymentcsphelper.exe,true
desktopimgdownldr.exe,true
DeviceCredentialDeployment.exe,true
directxdatabaseupdater.exe,true
dmclient.exe,true
DTUHandler.exe,true
dusmtask.exe,true
DXCap.exe,true
DXCpl.exe,true
dxgiadaptercache.exe,true
EASPolicyManagerBrokerHost.exe,true
EduPrintProv.exe,true
EoAExperiences.exe,true
fhmanagew.exe,true
FileHistory.exe,true
FsIso.exe,true
fvenotify.exe,true
fveprompt.exe,true
FXSCOVER.exe,true
FXSSVC.exe,true
FXSUNATD.exe,true
hcsdiag.exe,true
hnsdiag.exe,true
hvsievaluator.exe,true
ie4ushowIE.exe,true
IESettingSync.exe,true
InputSwitchToastHandler.exe,true
iotstartup.exe,true
manage-bde.exe,true
MBR2GPT.EXE,true
microsoft.windows.softwarelogo.showdesktop.exe,true
MicrosoftEdgeBCHost.exe,true
MicrosoftEdgeCP.exe,true
MicrosoftEdgeDevTools.exe,true
MicrosoftEdgeSH.exe,true
mmgaserver.exe,true
MoUsoCoreWorker.exe,true
msra.exe,true
MusNotifyIcon.exe,true
NDKPing.exe,true
NgcIso.exe,true
nmbind.exe,true
nmscrub.exe,true
nvspinfo.exe,true
ofdeploy.exe,true
pacjsworker.exe,true
PinEnrollmentBroker.exe,true
PktMon.exe,true
pospaymentsworker.exe,true
provlaunch.exe,true
provtool.exe,true
ProximityUxHost.exe,true
prproc.exe,true
quickassist.exe,true
raserver.exe,true
RDVGHelper.exe,true
recdisc.exe,true
refsutil.exe,true
RemoteAppLifetimeManager.exe,true
RemoteFXvGPUDisablement.exe,true
repair-bde.exe,true
rstrui.exe,true
runexehelper.exe,true
sdchange.exe,true
sdclt.exe,true
SecurityHealthHost.exe,true
SecurityHealthService.exe,true
SecurityHealthSystray.exe,true
SgrmBroker.exe,true
SgrmLpac.exe,true
SpatialAudioLicenseSrv.exe,true
Spectrum.exe,true
srdelayed.exe,true
SrTasks.exe,true
SystemUWPLauncher.exe,true
tar.exe,true
tcblaunch.exe,true
TpmTool.exe,true
ttdinject.exe,true
tttracer.exe,true
UIMgrBroker.exe,true
upfc.exe,true
usocoreworker.exe,true
UtcDecoderHost.exe,true
VBoxControl.exe,true
VBoxService.exe,true
VBoxTray.exe,true
vfpctrl.exe,true
vmcompute.exe,true
vmwp.exe,true
VsGraphicsDesktopEngine.exe,true
VsGraphicsRemoteEngine.exe,true
vsjitdebugger.exe,true
WaaSMedicAgent.exe,true
wbadmin.exe,true
wbengine.exe,true
WFS.exe,true
wifitask.exe,true
Windows.WARP.JITService.exe,true
WinRTNetMUAHostServer.exe,true
wlanext.exe,true
WorkFolders.exe,true
WpcMon.exe,true
WpcTok.exe,true
wpnpinst.exe,true
wscadminui.exe,true
wsl.exe,true
wslconfig.exe,true
WUDFCompanionHost.exe,true
IEChooser.exe,true
wslhost.exe,true
scp.exe,true
sftp.exe,true
ssh-add.exe,true
ssh-agent.exe,true
ssh-keygen.exe,true
ssh-keyscan.exe,true
ssh.exe,true
PerceptionSimulationInput.exe,true
PerceptionSimulationService.exe,true
UNPUXHost.exe,true
UNPUXLauncher.exe,true
UpdateNotificationMgr.exe,true
FaceFodUninstaller.exe,true
wlms.exe,true
OneDriveSetup.exe,true
OposHost.exe,true
1 filename systemFile
2 acu.exe true
3 AgentService.exe true
4 aitstatic.exe true
5 alg.exe true
6 AppHostRegistrationVerifier.exe true
7 appidcertstorecheck.exe true
8 appidpolicyconverter.exe true
9 appidtel.exe true
10 ApplicationFrameHost.exe true
11 ApplySettingsTemplateCatalog.exe true
12 AppVClient.exe true
13 AppVDllSurrogate.exe true
14 AppVNice.exe true
15 AppVStreamingUX.exe true
16 ARP.EXE true
17 at.exe true
18 AtBroker.exe true
19 attrib.exe true
20 audiodg.exe true
21 auditpol.exe true
22 AuthHost.exe true
23 autochk.exe true
24 autoconv.exe true
25 autofmt.exe true
26 AxInstUI.exe true
27 backgroundTaskHost.exe true
28 BackgroundTransferHost.exe true
29 bcastdvr.exe true
30 bcdboot.exe true
31 bcdedit.exe true
32 BioIso.exe true
33 bitsadmin.exe true
34 bootcfg.exe true
35 bootim.exe true
36 bridgeunattend.exe true
37 browser_broker.exe true
38 bthudtask.exe true
39 ByteCodeGenerator.exe true
40 cacls.exe true
41 calc.exe true
42 CameraSettingsUIHost.exe true
43 CastSrv.exe true
44 CertEnrollCtrl.exe true
45 certreq.exe true
46 certutil.exe true
47 change.exe true
48 changepk.exe true
49 charmap.exe true
50 CheckNetIsolation.exe true
51 chglogon.exe true
52 chgport.exe true
53 chgusr.exe true
54 chkdsk.exe true
55 chkntfs.exe true
56 choice.exe true
57 cipher.exe true
58 cleanmgr.exe true
59 cliconfg.exe true
60 clip.exe true
61 ClipUp.exe true
62 CloudExperienceHostBroker.exe true
63 CloudNotifications.exe true
64 CloudStorageWizard.exe true
65 cmd.exe true
66 cmdkey.exe true
67 cmdl32.exe true
68 cmmon32.exe true
69 cmstp.exe true
70 cofire.exe true
71 colorcpl.exe true
72 comp.exe true
73 compact.exe true
74 CompatTelRunner.exe true
75 CompMgmtLauncher.exe true
76 ComputerDefaults.exe true
77 Configure-SMRemoting.exe true
78 conhost.exe true
79 consent.exe true
80 control.exe true
81 convert.exe true
82 CredentialUIBroker.exe true
83 credwiz.exe true
84 cscript.exe true
85 csrss.exe true
86 ctfmon.exe true
87 cttune.exe true
88 cttunesvr.exe true
89 dasHost.exe true
90 DataExchangeHost.exe true
91 DataSenseLiveTileTask.exe true
92 dccw.exe true
93 dcgpofix.exe true
94 dcomcnfg.exe true
95 dcpromo.exe true
96 ddodiag.exe true
97 Defrag.exe true
98 DeviceCensus.exe true
99 DeviceEject.exe true
100 DeviceEnroller.exe true
101 DevicePairingWizard.exe true
102 DeviceProperties.exe true
103 DFDWiz.exe true
104 dfrgui.exe true
105 dfsrdiag.exe true
106 dialer.exe true
107 DIMC.exe true
108 diskpart.exe true
109 diskperf.exe true
110 diskraid.exe true
111 diskshadow.exe true
112 DiskSnapshot.exe true
113 Dism.exe true
114 dispdiag.exe true
115 DisplaySwitch.exe true
116 djoin.exe true
117 dllhost.exe true
118 dllhst3g.exe true
119 dmcertinst.exe true
120 dmcfghost.exe true
121 DmNotificationBroker.exe true
122 DmOmaCpMo.exe true
123 dnscacheugc.exe true
124 doskey.exe true
125 dpapimig.exe true
126 DpiScaling.exe true
127 dpnsvr.exe true
128 driverquery.exe true
129 drvcfg.exe true
130 drvinst.exe true
131 DsmUserTask.exe true
132 dsregcmd.exe true
133 dstokenclean.exe true
134 dvdplay.exe true
135 dwm.exe true
136 DWWIN.EXE true
137 dxdiag.exe true
138 Dxpserver.exe true
139 Eap3Host.exe true
140 EaseOfAccessDialog.exe true
141 easinvoker.exe true
142 EasPoliciesBrokerHost.exe true
143 EDPCleanup.exe true
144 edpnotify.exe true
145 efsui.exe true
146 EhStorAuthn.exe true
147 embeddedapplauncher.exe true
148 EmbeddedAppLauncherConfig.exe true
149 escUnattend.exe true
150 esentutl.exe true
151 eudcedit.exe true
152 eventcreate.exe true
153 eventvwr.exe true
154 expand.exe true
155 extrac32.exe true
156 fc.exe true
157 find.exe true
158 findstr.exe true
159 finger.exe true
160 fixmapi.exe true
161 fltMC.exe true
162 fodhelper.exe true
163 Fondue.exe true
164 fontdrvhost.exe true
165 fontview.exe true
166 forfiles.exe true
167 fsavailux.exe true
168 fsquirt.exe true
169 fsutil.exe true
170 ftp.exe true
171 GameBarPresenceWriter.exe true
172 GamePanel.exe true
173 GenValObj.exe true
174 getmac.exe true
175 gpresult.exe true
176 gpscript.exe true
177 gpupdate.exe true
178 grpconv.exe true
179 hdwwiz.exe true
180 help.exe true
181 HOSTNAME.EXE true
182 hvax64.exe true
183 hvix64.exe true
184 hvloader.exe true
185 hwrcomp.exe true
186 hwrreg.exe true
187 iashost.exe true
188 icacls.exe true
189 IcsEntitlementHost.exe true
190 icsunattend.exe true
191 ie4uinit.exe true
192 ieUnatt.exe true
193 iexpress.exe true
194 immersivetpmvscmgrsvr.exe true
195 InfDefaultInstall.exe true
196 InstallAgent.exe true
197 InstallAgentUserBroker.exe true
198 ipconfig.exe true
199 iscsicli.exe true
200 iscsicpl.exe true
201 isoburn.exe true
202 klist.exe true
203 ksetup.exe true
204 ktmutil.exe true
205 ktpass.exe true
206 label.exe true
207 LanguageComponentsInstallerComHandler.exe true
208 LaunchTM.exe true
209 LaunchWinApp.exe true
210 LbfoAdmin.exe true
211 LegacyNetUXHost.exe true
212 LicenseManagerShellext.exe true
213 licensingdiag.exe true
214 LicensingUI.exe true
215 LocationNotificationWindows.exe true
216 Locator.exe true
217 LockAppHost.exe true
218 LockScreenContentServer.exe true
219 lodctr.exe true
220 logagent.exe true
221 logman.exe true
222 logoff.exe true
223 LogonUI.exe true
224 lpkinstall.exe true
225 lpksetup.exe true
226 lpremove.exe true
227 LsaIso.exe true
228 lsass.exe true
229 Magnify.exe true
230 makecab.exe true
231 mavinject.exe true
232 MbaeParserTask.exe true
233 mblctr.exe true
234 mcbuilder.exe true
235 MDEServer.exe true
236 MDMAgent.exe true
237 MDMAppInstaller.exe true
238 MdmDiagnosticsTool.exe true
239 MdRes.exe true
240 MdSched.exe true
241 mfpmp.exe true
242 Microsoft.Uev.CscUnpinTool.exe true
243 Microsoft.Uev.SyncController.exe true
244 mmc.exe true
245 mobsync.exe true
246 mountvol.exe true
247 mpnotify.exe true
248 MpSigStub.exe true
249 MRINFO.EXE true
250 MRT-KB890830.exe true
251 MRT.exe true
252 MSchedExe.exe true
253 msconfig.exe true
254 msdt.exe true
255 msdtc.exe true
256 msfeedssync.exe true
257 msg.exe true
258 mshta.exe true
259 msiexec.exe true
260 msinfo32.exe true
261 mspaint.exe true
262 MsSpellCheckingHost.exe true
263 mstsc.exe true
264 mtstocom.exe true
265 MuiUnattend.exe true
266 MultiDigiMon.exe true
267 MusNotification.exe true
268 MusNotificationUx.exe true
269 Narrator.exe true
270 nbtstat.exe true
271 ndadmin.exe true
272 net.exe true
273 net1.exe true
274 netbtugc.exe true
275 netcfg.exe true
276 NetCfgNotifyObjectHost.exe true
277 netdom.exe true
278 NetEvtFwdr.exe true
279 NetHost.exe true
280 netiougc.exe true
281 Netplwiz.exe true
282 netsh.exe true
283 NETSTAT.EXE true
284 newdev.exe true
285 nltest.exe true
286 notepad.exe true
287 nslookup.exe true
288 ntoskrnl.exe true
289 ntprint.exe true
290 odbcad32.exe true
291 odbcconf.exe true
292 omadmclient.exe true
293 omadmprc.exe true
294 openfiles.exe true
295 OpenWith.exe true
296 OptionalFeatures.exe true
297 osk.exe true
298 PackagedCWALauncher.exe true
299 PackageInspector.exe true
300 PasswordOnWakeSettingFlyout.exe true
301 PATHPING.EXE true
302 pcalua.exe true
303 pcaui.exe true
304 pcwrun.exe true
305 perfmon.exe true
306 phoneactivate.exe true
307 PickerHost.exe true
308 PING.EXE true
309 PkgMgr.exe true
310 plasrv.exe true
311 PnPUnattend.exe true
312 pnputil.exe true
313 poqexec.exe true
314 powercfg.exe true
315 PresentationHost.exe true
316 PresentationSettings.exe true
317 prevhost.exe true
318 print.exe true
319 PrintBrmUi.exe true
320 PrintDialogHost.exe true
321 PrintDialogHost3D.exe true
322 printfilterpipelinesvc.exe true
323 PrintIsolationHost.exe true
324 printui.exe true
325 proquota.exe true
326 psr.exe true
327 pwlauncher.exe true
328 qappsrv.exe true
329 qprocess.exe true
330 query.exe true
331 quser.exe true
332 qwinsta.exe true
333 rasdial.exe true
334 rdpclip.exe true
335 rdpinit.exe true
336 rdpinput.exe true
337 RdpSa.exe true
338 RdpSaProxy.exe true
339 RdpSaUacHelper.exe true
340 rdpshell.exe true
341 rdpsign.exe true
342 rdrleakdiag.exe true
343 RDSPnf.exe true
344 ReAgentc.exe true
345 recover.exe true
346 RecoveryDrive.exe true
347 reg.exe true
348 regedt32.exe true
349 regini.exe true
350 Register-CimProvider.exe true
351 regsvr32.exe true
352 rekeywiz.exe true
353 relog.exe true
354 RelPost.exe true
355 RemotePosWorker.exe true
356 replace.exe true
357 reset.exe true
358 ResetEngine.exe true
359 resmon.exe true
360 RMActivate.exe true
361 RMActivate_isv.exe true
362 RMActivate_ssp.exe true
363 RMActivate_ssp_isv.exe true
364 RmClient.exe true
365 rmttpmvscmgrsvr.exe true
366 Robocopy.exe true
367 ROUTE.EXE true
368 RpcPing.exe true
369 rrinstaller.exe true
370 rsopprov.exe true
371 runas.exe true
372 rundll32.exe true
373 RunLegacyCPLElevated.exe true
374 runonce.exe true
375 RuntimeBroker.exe true
376 rwinsta.exe true
377 sacsess.exe true
378 sc.exe true
379 schtasks.exe true
380 ScriptRunner.exe true
381 sdbinst.exe true
382 sdiagnhost.exe true
383 SearchFilterHost.exe true
384 SearchIndexer.exe true
385 SearchProtocolHost.exe true
386 SecEdit.exe true
387 secinit.exe true
388 securekernel.exe true
389 SensorDataService.exe true
390 ServerManager.exe true
391 ServerManagerLauncher.exe true
392 services.exe true
393 sessionmsg.exe true
394 sethc.exe true
395 setres.exe true
396 setspn.exe true
397 SettingSyncHost.exe true
398 setupcl.exe true
399 setupugc.exe true
400 setx.exe true
401 sfc.exe true
402 shrpubw.exe true
403 shutdown.exe true
404 sigverif.exe true
405 SIHClient.exe true
406 sihost.exe true
407 SlideToShutDown.exe true
408 slui.exe true
409 smartscreen.exe true
410 SmartScreenSettings.exe true
411 smss.exe true
412 SndVol.exe true
413 SnippingTool.exe true
414 snmptrap.exe true
415 sort.exe true
416 SpaceAgent.exe true
417 spaceman.exe true
418 spoolsv.exe true
419 SppExtComObj.Exe true
420 sppsvc.exe true
421 stordiag.exe true
422 subst.exe true
423 svchost.exe true
424 sxstrace.exe true
425 SyncAppvPublishingServer.exe true
426 SyncHost.exe true
427 syskey.exe true
428 SysResetErr.exe true
429 systeminfo.exe true
430 SystemPropertiesAdvanced.exe true
431 SystemPropertiesComputerName.exe true
432 SystemPropertiesDataExecutionPrevention.exe true
433 SystemPropertiesHardware.exe true
434 SystemPropertiesPerformance.exe true
435 SystemPropertiesProtection.exe true
436 SystemPropertiesRemote.exe true
437 systemreset.exe true
438 SystemSettingsAdminFlows.exe true
439 SystemSettingsBroker.exe true
440 SystemSettingsRemoveDevice.exe true
441 systray.exe true
442 tabcal.exe true
443 takeown.exe true
444 TapiUnattend.exe true
445 taskhostw.exe true
446 taskkill.exe true
447 tasklist.exe true
448 Taskmgr.exe true
449 tcmsetup.exe true
450 TCPSVCS.EXE true
451 tdlrecover.exe true
452 ThumbnailExtractionHost.exe true
453 TieringEngineService.exe true
454 timeout.exe true
455 TokenBrokerCookies.exe true
456 TpmInit.exe true
457 tpmvscmgr.exe true
458 tpmvscmgrsvr.exe true
459 tracerpt.exe true
460 TRACERT.EXE true
461 tscon.exe true
462 tsdiscon.exe true
463 tsecimp.exe true
464 tskill.exe true
465 TSTheme.exe true
466 TSWbPrxy.exe true
467 typeperf.exe true
468 tzsync.exe true
469 tzutil.exe true
470 ucsvc.exe true
471 UevAgentPolicyGenerator.exe true
472 UevAppMonitor.exe true
473 UevTemplateBaselineGenerator.exe true
474 UevTemplateConfigItemGenerator.exe true
475 UI0Detect.exe true
476 unlodctr.exe true
477 unregmp2.exe true
478 UpgradeResultsUI.exe true
479 upnpcont.exe true
480 UserAccountBroker.exe true
481 UserAccountControlSettings.exe true
482 userinit.exe true
483 UsoClient.exe true
484 Utilman.exe true
485 VaultCmd.exe true
486 vds.exe true
487 vdsldr.exe true
488 verclsid.exe true
489 verifier.exe true
490 verifiergui.exe true
491 vssadmin.exe true
492 VSSUIRUN.exe true
493 VSSVC.exe true
494 w32tm.exe true
495 waitfor.exe true
496 WallpaperHost.exe true
497 WebCache.exe true
498 wecutil.exe true
499 WerFault.exe true
500 WerFaultSecure.exe true
501 wermgr.exe true
502 wevtutil.exe true
503 wextract.exe true
504 where.exe true
505 whoami.exe true
506 wiaacmgr.exe true
507 wiawow64.exe true
508 wimserv.exe true
509 win32calc.exe true
510 WinBioDataModelOOBE.exe true
511 Windows.Media.BackgroundPlayback.exe true
512 WindowsActionDialog.exe true
513 WindowsUpdateElevatedInstaller.exe true
514 wininit.exe true
515 winload.exe true
516 winlogon.exe true
517 winresume.exe true
518 winrs.exe true
519 winrshost.exe true
520 WinSAT.exe true
521 winver.exe true
522 wkspbroker.exe true
523 wksprt.exe true
524 wlrmdr.exe true
525 WMPDMC.exe true
526 wowreg32.exe true
527 WPDShextAutoplay.exe true
528 wpr.exe true
529 write.exe true
530 WSCollect.exe true
531 wscript.exe true
532 WSManHTTPConfig.exe true
533 wsmprovhost.exe true
534 wsqmcons.exe true
535 WSReset.exe true
536 wuapihost.exe true
537 wuauclt.exe true
538 WUDFHost.exe true
539 wusa.exe true
540 WWAHost.exe true
541 XblGameSaveTask.exe true
542 xcopy.exe true
543 xwizard.exe true
544 comrepl.exe true
545 MigRegDB.exe true
546 DiagnosticsHub.StandardCollector.Service.exe true
547 DismHost.exe true
548 F12Chooser.exe true
549 IMJPDCT.EXE true
550 IMJPSET.EXE true
551 IMJPUEX.EXE true
552 imjpuexc.exe true
553 IMTCLNWZ.EXE true
554 IMTCPROP.exe true
555 IMCCPHR.exe true
556 ImeBroker.exe true
557 imecfmui.exe true
558 IMEDICTUPDATEUI.EXE true
559 IMEPADSV.EXE true
560 IMESEARCH.EXE true
561 IMEWDBLD.EXE true
562 ChsIME.exe true
563 ChtIME.exe true
564 mighost.exe true
565 audit.exe true
566 AuditShD.exe true
567 FirstLogonAnim.exe true
568 msoobe.exe true
569 oobeldr.exe true
570 Setup.exe true
571 UserOOBEBroker.exe true
572 windeploy.exe true
573 SpeechUXWiz.exe true
574 SpeechModelDownload.exe true
575 SpeechRuntime.exe true
576 PrintBrm.exe true
577 PrintBrmEngine.exe true
578 sysprep.exe true
579 SystemResetPlatform.exe true
580 mofcomp.exe true
581 scrcons.exe true
582 unsecapp.exe true
583 wbemtest.exe true
584 WinMgmt.exe true
585 WMIADAP.exe true
586 WmiApSrv.exe true
587 WMIC.exe true
588 WmiPrvSE.exe true
589 powershell.exe true
590 powershell_ise.exe true
591 dplaysvr.exe true
592 dtdump.exe true
593 hh.exe true
594 instnm.exe true
595 perfhost.exe true
596 rasautou.exe true
597 rasphone.exe true
598 regedit.exe true
599 setup16.exe true
600 user.exe true
601 _isdel.exe true
602 agentactivationruntimestarter.exe true
603 ApplyTrustOffline.exe true
604 ApproveChildRequest.exe true
605 appverif.exe true
606 baaupdate.exe true
607 bash.exe true
608 bdechangepin.exe true
609 BdeHdCfg.exe true
610 BdeUISrv.exe true
611 bdeunlock.exe true
612 BitLockerDeviceEncryption.exe true
613 BitLockerWizard.exe true
614 BitLockerWizardElev.exe true
615 bootsect.exe true
616 browserexport.exe true
617 CIDiag.exe true
618 CompPkgSrv.exe true
619 convertvhd.exe true
620 coredpussvr.exe true
621 CredentialEnrollmentManager.exe true
622 curl.exe true
623 CustomInstallExec.exe true
624 d3dconfig.exe true
625 DataStoreCacheDumpTool.exe true
626 DataUsageLiveTileTask.exe true
627 deploymentcsphelper.exe true
628 desktopimgdownldr.exe true
629 DeviceCredentialDeployment.exe true
630 directxdatabaseupdater.exe true
631 dmclient.exe true
632 DTUHandler.exe true
633 dusmtask.exe true
634 DXCap.exe true
635 DXCpl.exe true
636 dxgiadaptercache.exe true
637 EASPolicyManagerBrokerHost.exe true
638 EduPrintProv.exe true
639 EoAExperiences.exe true
640 fhmanagew.exe true
641 FileHistory.exe true
642 FsIso.exe true
643 fvenotify.exe true
644 fveprompt.exe true
645 FXSCOVER.exe true
646 FXSSVC.exe true
647 FXSUNATD.exe true
648 hcsdiag.exe true
649 hnsdiag.exe true
650 hvsievaluator.exe true
651 ie4ushowIE.exe true
652 IESettingSync.exe true
653 InputSwitchToastHandler.exe true
654 iotstartup.exe true
655 manage-bde.exe true
656 MBR2GPT.EXE true
657 microsoft.windows.softwarelogo.showdesktop.exe true
658 MicrosoftEdgeBCHost.exe true
659 MicrosoftEdgeCP.exe true
660 MicrosoftEdgeDevTools.exe true
661 MicrosoftEdgeSH.exe true
662 mmgaserver.exe true
663 MoUsoCoreWorker.exe true
664 msra.exe true
665 MusNotifyIcon.exe true
666 NDKPing.exe true
667 NgcIso.exe true
668 nmbind.exe true
669 nmscrub.exe true
670 nvspinfo.exe true
671 ofdeploy.exe true
672 pacjsworker.exe true
673 PinEnrollmentBroker.exe true
674 PktMon.exe true
675 pospaymentsworker.exe true
676 provlaunch.exe true
677 provtool.exe true
678 ProximityUxHost.exe true
679 prproc.exe true
680 quickassist.exe true
681 raserver.exe true
682 RDVGHelper.exe true
683 recdisc.exe true
684 refsutil.exe true
685 RemoteAppLifetimeManager.exe true
686 RemoteFXvGPUDisablement.exe true
687 repair-bde.exe true
688 rstrui.exe true
689 runexehelper.exe true
690 sdchange.exe true
691 sdclt.exe true
692 SecurityHealthHost.exe true
693 SecurityHealthService.exe true
694 SecurityHealthSystray.exe true
695 SgrmBroker.exe true
696 SgrmLpac.exe true
697 SpatialAudioLicenseSrv.exe true
698 Spectrum.exe true
699 srdelayed.exe true
700 SrTasks.exe true
701 SystemUWPLauncher.exe true
702 tar.exe true
703 tcblaunch.exe true
704 TpmTool.exe true
705 ttdinject.exe true
706 tttracer.exe true
707 UIMgrBroker.exe true
708 upfc.exe true
709 usocoreworker.exe true
710 UtcDecoderHost.exe true
711 VBoxControl.exe true
712 VBoxService.exe true
713 VBoxTray.exe true
714 vfpctrl.exe true
715 vmcompute.exe true
716 vmwp.exe true
717 VsGraphicsDesktopEngine.exe true
718 VsGraphicsRemoteEngine.exe true
719 vsjitdebugger.exe true
720 WaaSMedicAgent.exe true
721 wbadmin.exe true
722 wbengine.exe true
723 WFS.exe true
724 wifitask.exe true
725 Windows.WARP.JITService.exe true
726 WinRTNetMUAHostServer.exe true
727 wlanext.exe true
728 WorkFolders.exe true
729 WpcMon.exe true
730 WpcTok.exe true
731 wpnpinst.exe true
732 wscadminui.exe true
733 wsl.exe true
734 wslconfig.exe true
735 WUDFCompanionHost.exe true
736 IEChooser.exe true
737 wslhost.exe true
738 scp.exe true
739 sftp.exe true
740 ssh-add.exe true
741 ssh-agent.exe true
742 ssh-keygen.exe true
743 ssh-keyscan.exe true
744 ssh.exe true
745 PerceptionSimulationInput.exe true
746 PerceptionSimulationService.exe true
747 UNPUXHost.exe true
748 UNPUXLauncher.exe true
749 UpdateNotificationMgr.exe true
750 FaceFodUninstaller.exe true
751 wlms.exe true
752 OneDriveSetup.exe true
753 OposHost.exe true
-20
View File
@@ -1,20 +0,0 @@
domain, isLegit
amazon.com, True
ssl-images-amazon.com, True
facebook.com, True
xx.fbcdn.net, True
github.com, True
githubassets.com, True
instagram.com, True
linkedin.com, True
microsoftonline.com, True
office.com, True
okta.com, True
live.com, True
protonmail.com, True
reddit.com, True
redditstatic.com, True
twitter.com, True
twimg.com, True
google.com, True
1 domain isLegit
2 amazon.com True
3 ssl-images-amazon.com True
4 facebook.com True
5 xx.fbcdn.net True
6 github.com True
7 githubassets.com True
8 instagram.com True
9 linkedin.com True
10 microsoftonline.com True
11 office.com True
12 okta.com True
13 live.com True
14 protonmail.com True
15 reddit.com True
16 redditstatic.com True
17 twitter.com True
18 twimg.com True
19 google.com True
@@ -1,61 +0,0 @@
process
cat /proc/version
cat /etc/*-release
/etc/passwd
cat /etc/*
lastlog
id
PermitRootLogin
sestatus *
ps
mysql*
netstat*
find *
head /var/mail/root
docker
cat /etc/issue
cat /etc/*-release
cat /proc/version
uname -a
uname -mrs
rpm -q kernel
dmesg | grep Linux
ls /boot | grep vmlinuz-
cat /etc/profile
cat /etc/bashrc
cat ~/.bash_profile
cat ~/.bashrc
cat ~/.bash_logout
ps -aux | grep root
ps -ef | grep root
crontab -l
cat /etc/cron*
cat /etc/cron.allow
cat /etc/cron.deny
cat /etc/crontab
grep -i user *
grep -i pass *
ifconfig
cat /etc/network/interfaces
cat /etc/sysconfig/network
cat /etc/resolv.conf
cat /etc/networks
cvelist-file:*
exploit-db*
strings -e /etc/apache2/apache2.conf
strings -e /etc/ssh/sshd_config
strings -e /etc/shadow
iptables -L
lsof -i
netstat -antup
netstat -antpx
netstat -tulpn
arp -e
route
cat /etc/passwd
cat /etc/group
cat /etc/shadow
find / -perm -u=s
find / -perm -g=s
find / -perm -4000
find / -perm -2000
1 process
2 cat /proc/version
3 cat /etc/*-release
4 /etc/passwd
5 cat /etc/*
6 lastlog
7 id
8 PermitRootLogin
9 sestatus *
10 ps
11 mysql*
12 netstat*
13 find *
14 head /var/mail/root
15 docker
16 cat /etc/issue
17 cat /etc/*-release
18 cat /proc/version
19 uname -a
20 uname -mrs
21 rpm -q kernel
22 dmesg | grep Linux
23 ls /boot | grep vmlinuz-
24 cat /etc/profile
25 cat /etc/bashrc
26 cat ~/.bash_profile
27 cat ~/.bashrc
28 cat ~/.bash_logout
29 ps -aux | grep root
30 ps -ef | grep root
31 crontab -l
32 cat /etc/cron*
33 cat /etc/cron.allow
34 cat /etc/cron.deny
35 cat /etc/crontab
36 grep -i user *
37 grep -i pass *
38 ifconfig
39 cat /etc/network/interfaces
40 cat /etc/sysconfig/network
41 cat /etc/resolv.conf
42 cat /etc/networks
43 cvelist-file:*
44 exploit-db*
45 strings -e /etc/apache2/apache2.conf
46 strings -e /etc/ssh/sshd_config
47 strings -e /etc/shadow
48 iptables -L
49 lsof -i
50 netstat -antup
51 netstat -antpx
52 netstat -tulpn
53 arp -e
54 route
55 cat /etc/passwd
56 cat /etc/group
57 cat /etc/shadow
58 find / -perm -u=s
59 find / -perm -g=s
60 find / -perm -4000
61 find / -perm -2000
File diff suppressed because it is too large Load Diff
-480
View File
@@ -1,480 +0,0 @@
lolbas_file_name,lolbas_file_path,description
eventvwr.exe,c:\windows\system32\*,Displays Windows Event Logs in a GUI window.
eventvwr.exe,c:\windows\syswow64\*,Displays Windows Event Logs in a GUI window.
rasautou.exe,c:\windows\system32\*,Windows Remote Access Dialer
regedit.exe,c:\windows\system32\*,Used by Windows to manipulate registry
regedit.exe,c:\windows\syswow64\*,Used by Windows to manipulate registry
regsvr32.exe,c:\windows\system32\*,Used by Windows to register dlls
regsvr32.exe,c:\windows\syswow64\*,Used by Windows to register dlls
control.exe,c:\windows\system32\*,Binary used to launch controlpanel items in Windows
control.exe,c:\windows\syswow64\*,Binary used to launch controlpanel items in Windows
configsecuritypolicy.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
scriptrunner.exe,c:\windows\system32\*,Execute binary through proxy binary to evade defensive counter measures
scriptrunner.exe,c:\windows\syswow64\*,Execute binary through proxy binary to evade defensive counter measures
offlinescannershell.exe,c:\program files\windows defender\offline\*,Windows Defender Offline Shell
atbroker.exe,c:\windows\system32\*,Helper binary for Assistive Technology (AT)
atbroker.exe,c:\windows\syswow64\*,Helper binary for Assistive Technology (AT)
mmc.exe,c:\windows\system32\*,Load snap-ins to locally and remotely manage Windows systems
mmc.exe,c:\windows\syswow64\*,Load snap-ins to locally and remotely manage Windows systems
mavinject.exe,c:\windows\system32\*,Used by App-v in Windows
mavinject.exe,c:\windows\syswow64\*,Used by App-v in Windows
ftp.exe,c:\windows\system32\*,A binary designed for connecting to FTP servers
ftp.exe,c:\windows\syswow64\*,A binary designed for connecting to FTP servers
ttdinject.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
ttdinject.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
certoc.exe,c:\windows\system32\*,Used for installing certificates
certoc.exe,c:\windows\syswow64\*,Used for installing certificates
at.exe,c:\windows\system32\*,Schedule periodic tasks
at.exe,c:\windows\syswow64\*,Schedule periodic tasks
netsh.exe,c:\windows\system32\*,Netsh is a Windows tool used to manipulate network interface settings.
netsh.exe,c:\windows\syswow64\*,Netsh is a Windows tool used to manipulate network interface settings.
pnputil.exe,c:\windows\system32\*,Used for installing drivers
ie4uinit.exe,c:\windows\system32\*,Executes commands from a specially prepared ie4uinit.inf file.
ie4uinit.exe,c:\windows\syswow64\*,Executes commands from a specially prepared ie4uinit.inf file.
infdefaultinstall.exe,c:\windows\system32\*,Binary used to perform installation based on content inside inf files
infdefaultinstall.exe,c:\windows\syswow64\*,Binary used to perform installation based on content inside inf files
forfiles.exe,c:\windows\system32\*,Selects and executes a command on a file or set of files. This command is useful for batch processing.
forfiles.exe,c:\windows\syswow64\*,Selects and executes a command on a file or set of files. This command is useful for batch processing.
register-cimprovider.exe,c:\windows\system32\*,Used to register new wmi providers
register-cimprovider.exe,c:\windows\syswow64\*,Used to register new wmi providers
tttracer.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel
tttracer.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel
xwizard.exe,c:\windows\system32\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe
xwizard.exe,c:\windows\syswow64\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe
pcalua.exe,c:\windows\system32\*,Program Compatibility Assistant
print.exe,c:\windows\system32\*,Used by Windows to send files to the printer
print.exe,c:\windows\syswow64\*,Used by Windows to send files to the printer
runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\*,Execute target PowerShell script
runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\*,Execute target PowerShell script
regasm.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Part of .NET
regasm.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Part of .NET
regasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Part of .NET
regasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Part of .NET
cmd.exe,c:\windows\system32\*,The command-line interpreter in Windows
cmd.exe,c:\windows\syswow64\*,The command-line interpreter in Windows
msbuild.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Used to compile and execute code
msbuild.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Used to compile and execute code
msbuild.exe,c:\windows\microsoft.net\framework\v3.5\*,Used to compile and execute code
msbuild.exe,c:\windows\microsoft.net\framework64\v3.5\*,Used to compile and execute code
msbuild.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Used to compile and execute code
msbuild.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Used to compile and execute code
msbuild.exe,c:\program files (x86)\msbuild\14.0\bin\*,Used to compile and execute code
certutil.exe,c:\windows\system32\*,Windows binary used for handling certificates
certutil.exe,c:\windows\syswow64\*,Windows binary used for handling certificates
vbc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used for compile vbs code
vbc.exe,c:\windows\microsoft.net\framework64\v3.5\*,Binary file used for compile vbs code
psr.exe,c:\windows\system32\*,"Windows Problem Steps Recorder, used to record screen and clicks."
psr.exe,c:\windows\syswow64\*,"Windows Problem Steps Recorder, used to record screen and clicks."
extexport.exe,c:\program files\internet explorer\*,Load a DLL located in the c:\test folder with a specific name.
extexport.exe,c:\program files (x86)\internet explorer\*,Load a DLL located in the c:\test folder with a specific name.
rpcping.exe,c:\windows\system32\*,Used to verify rpc connection
rpcping.exe,c:\windows\syswow64\*,Used to verify rpc connection
msdt.exe,c:\windows\system32\*,Microsoft diagnostics tool
msdt.exe,c:\windows\syswow64\*,Microsoft diagnostics tool
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\64kb6472.inf_amd64_3daef03bbe98572b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_0e9c57ae3396e055\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_209bd95d56b1ac2d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_3fa2a843f8b7f16d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_85c860f05274baa0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_f7412e3e3404de80\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_feb9f1cf05b0de58\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_component.inf_amd64_0219cc1c7085a93f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_component.inf_amd64_df4f60b1cae9b14a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_16eb18b0e2526e57\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_1c77f1231c19bc72\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_31c60cc38cfcca28\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_82f69cea8b2d928f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_b4d94f3e41ceb839\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_0606619cc97463de\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_0e95edab338ad669\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_22aac1442d387216\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_2461d914696db722\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_29d727269a34edf5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_2caf76dbce56546d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_353320edb98da643\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_4ea0ed0af1507894\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_56a48f4f1c2da7a7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_64f23fdadb76a511\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_668dd0c6d3f9fa0e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_6be8e5b7f731a6e5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_6dad7e4e9a8fa889\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_6df442103a1937a4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_767e7683f9ad126c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_8644298f665a12c4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_868acf86149aef5d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_92cf9d9d84f1d3db\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_93239c65f222d453\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_9de8154b682af864\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_a7428663aca90897\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_ad7cb5e55a410add\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_afbf41cf8ab202d7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_d193c96475eaa96e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_db953c52208ada71\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_e7523682cc7528cc\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_e9f341319ca84274\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_f3a64c75ee4defb7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_f51939e52b944f4b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch_comp.inf_amd64_4938423c9b9639d7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch_comp.inf_amd64_c8e108d4a62c59d5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch_comp.inf_amd64_deecec7d232ced2b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_01ee1299f4982efe\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_02edfc87000937e4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0541b698fc6e40b0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0707757077710fff\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0cff362f9dff4228\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_16ed7d82b93e4f68\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1a33d2f73651d989\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1aca2a92a37fce23\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1af2dd3e4df5fd61\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1d571527c7083952\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_23f7302c2b9ee813\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_24de78387e6208e4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_250db833a1cd577e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_25e7c5a58c052bc5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_28d80681d3523b1c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_2dda3b1147a3a572\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_31ba00ea6900d67d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_329877a66f240808\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_42af9f4718aa1395\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_4645af5c659ae51a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_48c2e68e54c92258\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_48e7e903a369eae2\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_491d20003583dabe\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_4b34c18659561116\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_51ce968bf19942c2\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_555cfc07a674ecdd\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_561bd21d54545ed3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_579a75f602cc2dce\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_57f66a4f0a97f1a3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_587befb80671fb38\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_62f096fe77e085c0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_6ae0ddbb4a38e23c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_6bb02522ea3fdb0d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_6d34ac0763025a06\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_712b6a0adbaabc0a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_78b09d9681a2400f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_842874489af34daa\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_88084eb1fe7cebc3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_89033455cb08186f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_8a9535cd18c90bc3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_8c1fc948b5a01c52\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_9088b61921a6ff9f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_90f68cd0dc48b625\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_95cb371d046d4b4c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_a58de0cf5f3e9dca\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_abe9d37302f8b1ae\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_acb3edda7b82982f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_aebc5a8535dd3184\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_b5d4c82c67b39358\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_b846bbf1e81ea3cf\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_babb2e8b8072ff3b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_bc75cebf5edbbc50\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_be91293cf20d4372\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c11f4d5f0bc4c592\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c4e5173126d31cf0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c4f600ffe34acc7b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c8634ed19e331cda\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c9081e50bcffa972\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_ceddadac8a2b489e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_d4406f0ad6ec2581\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_d5877a2e0e6374b6\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_d8ca5f86add535ef\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_e8abe176c7b553b5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_eabb3ac2c517211f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_f8d8be8fea71e1a0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_fe5e116bb07c0629\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_fe73d2ebaa05fb95\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64_kbl_kit127397.inf_amd64_e1da8ee9e92ccadb\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\k127153.inf_amd64_364f43f2a27f7bd7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\k127153.inf_amd64_3f3936d8dec668b8\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\k127793.inf_amd64_3ab7883eddccbf0f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki129523.inf_amd64_32947eecf8f3e231\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki126950.inf_amd64_fa7f56314967630d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki126951.inf_amd64_94804e3918169543\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki126973.inf_amd64_06dde156632145e3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki126974.inf_amd64_9168fc04b8275db9\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127005.inf_amd64_753576c4406c1193\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127018.inf_amd64_0f67ff47e9e30716\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127021.inf_amd64_0d68af55c12c7c17\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127171.inf_amd64_368f8c7337214025\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127176.inf_amd64_86c658cabfb17c9c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127390.inf_amd64_e1ccb879ece8f084\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127678.inf_amd64_8427d3a09f47dfc1\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127727.inf_amd64_cf8e31692f82192e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127807.inf_amd64_fc915899816dbc5d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127850.inf_amd64_6ad8d99023b59fd5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki128602.inf_amd64_6ff790822fd674ab\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki128916.inf_amd64_3509e1eb83b83cfb\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki129407.inf_amd64_f26f36ac54ce3076\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki129633.inf_amd64_d9b8af875f664a8c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki129866.inf_amd64_e7cdca9882c16f55\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130274.inf_amd64_bafd2440fa1ffdd6\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130350.inf_amd64_696b7c6764071b63\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130409.inf_amd64_0d8d61270dfb4560\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130471.inf_amd64_26ad6921447aa568\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130624.inf_amd64_d85487143eec5e1a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130825.inf_amd64_ee3ba427c553f15f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130871.inf_amd64_382f7c369d4bf777\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki131064.inf_amd64_5d13f27a9a9843fa\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki131176.inf_amd64_fb4fe914575fdd15\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki131191.inf_amd64_d668106cb6f2eae0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki131622.inf_amd64_0058d71ace34db73\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132032.inf_amd64_f29660d80998e019\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132337.inf_amd64_223d6831ffa64ab1\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132535.inf_amd64_7875dff189ab2fa2\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132544.inf_amd64_b8c1f31373153db4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132574.inf_amd64_54c9b905b975ee55\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132869.inf_amd64_052eb72d070df60f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\kit126731.inf_amd64_1905c9d5f38631d9\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
dnscmd.exe,c:\windows\system32\*,A command-line interface for managing DNS servers
dnscmd.exe,c:\windows\syswow64\*,A command-line interface for managing DNS servers
wab.exe,c:\program files\windows mail\*,Windows address book manager
wab.exe,c:\program files (x86)\windows mail\*,Windows address book manager
msconfig.exe,c:\windows\system32\*,"MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows"
wscript.exe,c:\windows\system32\*,Used by Windows to execute scripts
wscript.exe,c:\windows\syswow64\*,Used by Windows to execute scripts
makecab.exe,c:\windows\system32\*,Binary to package existing files into a cabinet (.cab) file
makecab.exe,c:\windows\syswow64\*,Binary to package existing files into a cabinet (.cab) file
datasvcutil.exe,c:\windows\microsoft.net\framework64\v3.5\*,DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.
cmdl32.exe,c:\windows\system32\*,Microsoft Connection Manager Auto-Download
cmdl32.exe,c:\windows\syswow64\*,Microsoft Connection Manager Auto-Download
mshta.exe,c:\windows\system32\*,Used by Windows to execute html applications. (.hta)
mshta.exe,c:\windows\syswow64\*,Used by Windows to execute html applications. (.hta)
cmdkey.exe,c:\windows\system32\*,"creates, lists, and deletes stored user names and passwords or credentials."
cmdkey.exe,c:\windows\syswow64\*,"creates, lists, and deletes stored user names and passwords or credentials."
ilasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,used for compile c# code into dll or exe.
ilasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,used for compile c# code into dll or exe.
rdrleakdiag.exe,c:\windows\system32\*,Microsoft Windows resource leak diagnostic tool
rdrleakdiag.exe,c:\windows\syswow64\*,Microsoft Windows resource leak diagnostic tool
mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.4-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender
mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.7-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender
mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender
jsc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format
cmstp.exe,c:\windows\system32\*,Installs or removes a Connection Manager service profile.
cmstp.exe,c:\windows\syswow64\*,Installs or removes a Connection Manager service profile.
stordiag.exe,c:\windows\system32\*,Storage diagnostic tool
stordiag.exe,c:\windows\syswow64\*,Storage diagnostic tool
odbcconf.exe,c:\windows\system32\*,Used in Windows for managing ODBC connections
odbcconf.exe,c:\windows\syswow64\*,Used in Windows for managing ODBC connections
wlrmdr.exe,c:\windows\system32\*,Windows Logon Reminder executable
printbrm.exe,c:\windows\system32\spool\tools\*,Printer Migration Command-Line Tool
dfsvc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfsvc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfsvc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET
dfsvc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET
extrac32.exe,c:\windows\system32\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe"
extrac32.exe,c:\windows\syswow64\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe"
rundll32.exe,c:\windows\system32\*,Used by Windows to execute dll files
rundll32.exe,c:\windows\syswow64\*,Used by Windows to execute dll files
runonce.exe,c:\windows\system32\*,Executes a Run Once Task that has been configured in the registry
runonce.exe,c:\windows\syswow64\*,Executes a Run Once Task that has been configured in the registry
explorer.exe,c:\windows\*,Binary used for managing files and system components within Windows
explorer.exe,c:\windows\syswow64\*,Binary used for managing files and system components within Windows
wuauclt.exe,c:\windows\system32\*,Windows Update Client
wsreset.exe,c:\windows\system32\*,Used to reset Windows Store settings according to its manifest file
finger.exe,c:\windows\system32\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
finger.exe,c:\windows\syswow64\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
regini.exe,c:\windows\system32\*,Used to manipulate the registry
regini.exe,c:\windows\syswow64\*,Used to manipulate the registry
reg.exe,c:\windows\system32\*,Used to manipulate the registry
reg.exe,c:\windows\syswow64\*,Used to manipulate the registry
syncappvpublishingserver.exe,c:\windows\system32\*,Used by App-v to get App-v server lists
syncappvpublishingserver.exe,c:\windows\syswow64\*,Used by App-v to get App-v server lists
bitsadmin.exe,c:\windows\system32\*,Used for managing background intelligent transfer
bitsadmin.exe,c:\windows\syswow64\*,Used for managing background intelligent transfer
msiexec.exe,c:\windows\system32\*,Used by Windows to execute msi files
msiexec.exe,c:\windows\syswow64\*,Used by Windows to execute msi files
regsvcs.exe,c:\windows\system32\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
regsvcs.exe,c:\windows\syswow64\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
gpscript.exe,c:\windows\system32\*,Used by group policy to process scripts
gpscript.exe,c:\windows\syswow64\*,Used by group policy to process scripts
diskshadow.exe,c:\windows\system32\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
diskshadow.exe,c:\windows\syswow64\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
ieexec.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
ieexec.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
diantz.exe,c:\windows\system32\*,Binary that package existing files into a cabinet (.cab) file
diantz.exe,c:\windows\syswow64\*,Binary that package existing files into a cabinet (.cab) file
desktopimgdownldr.exe,c:\windows\system32\*,Windows binary used to configure lockscreen/desktop image
appinstaller.exe,c:\program files\windowsapps\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe\*,Tool used for installation of AppX/MSIX applications on Windows 10
sc.exe,c:\windows\system32\*,Used by Windows to manage services
sc.exe,c:\windows\syswow64\*,Used by Windows to manage services
replace.exe,c:\windows\system32\*,Used to replace file with another file
replace.exe,c:\windows\syswow64\*,Used to replace file with another file
schtasks.exe,c:\windows\system32\*,Schedule periodic tasks
schtasks.exe,c:\windows\syswow64\*,Schedule periodic tasks
microsoft.workflow.compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,A utility included with .NET that is capable of compiling and executing C# or VB.net code.
expand.exe,c:\windows\system32\*,Binary that expands one or more compressed files
expand.exe,c:\windows\syswow64\*,Binary that expands one or more compressed files
conhost.exe,c:\windows\system32\*,Console Window host
bash.exe,c:\windows\system32\*,File used by Windows subsystem for Linux
bash.exe,c:\windows\syswow64\*,File used by Windows subsystem for Linux
pcwrun.exe,c:\windows\system32\*,Program Compatibility Wizard
fltmc.exe,c:\windows\system32\*,Filter Manager Control Program used by Windows
wmic.exe,c:\windows\system32\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI
wmic.exe,c:\windows\syswow64\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI
workfolders.exe,c:\windows\system32\*,Work Folders
settingsynchost.exe,c:\windows\system32\*,Host Process for Setting Synchronization
settingsynchost.exe,c:\windows\syswow64\*,Host Process for Setting Synchronization
pktmon.exe,c:\windows\system32\*,Capture Network Packets on the windows 10 with October 2018 Update or later.
pktmon.exe,c:\windows\syswow64\*,Capture Network Packets on the windows 10 with October 2018 Update or later.
aspnet_compiler.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ASP.NET Compilation Tool
aspnet_compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ASP.NET Compilation Tool
cscript.exe,c:\windows\system32\*,Binary used to execute scripts in Windows
cscript.exe,c:\windows\syswow64\*,Binary used to execute scripts in Windows
installutil.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
installutil.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
installutil.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
installutil.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
esentutl.exe,c:\windows\system32\*,Binary for working with Microsoft Joint Engine Technology (JET) database
esentutl.exe,c:\windows\syswow64\*,Binary for working with Microsoft Joint Engine Technology (JET) database
hh.exe,c:\windows\*,Binary used for processing chm files in Windows
hh.exe,c:\windows\syswow64\*,Binary used for processing chm files in Windows
findstr.exe,c:\windows\system32\*,"Write to ADS, discover, or download files with Findstr.exe"
findstr.exe,c:\windows\syswow64\*,"Write to ADS, discover, or download files with Findstr.exe"
verclsid.exe,c:\windows\system32\*,Used to verify a COM object before it is instantiated by Windows Explorer
verclsid.exe,c:\windows\syswow64\*,Used to verify a COM object before it is instantiated by Windows Explorer
certreq.exe,c:\windows\system32\*,Used for requesting and managing certificates
certreq.exe,c:\windows\syswow64\*,Used for requesting and managing certificates
csc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile C# code
csc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile C# code
imewdbld.exe,c:\windows\system32\ime\shared\*,Microsoft IME Open Extended Dictionary Module
presentationhost.exe,c:\windows\system32\*,File is used for executing Browser applications
presentationhost.exe,c:\windows\syswow64\*,File is used for executing Browser applications
shell32.dll,c:\windows\system32\*,Windows Shell Common Dll
shell32.dll,c:\windows\syswow64\*,Windows Shell Common Dll
zipfldr.dll,c:\windows\system32\*,Compressed Folder library
zipfldr.dll,c:\windows\syswow64\*,Compressed Folder library
desk.cpl,c:\windows\system32\*,Desktop Settings Control Panel
desk.cpl,c:\windows\syswow64\*,Desktop Settings Control Panel
comsvcs.dll,c:\windows\system32\*,COM+ Services
setupapi.dll,c:\windows\system32\*,Windows Setup Application Programming Interface
setupapi.dll,c:\windows\syswow64\*,Windows Setup Application Programming Interface
mshtml.dll,c:\windows\system32\*,Microsoft HTML Viewer
mshtml.dll,c:\windows\syswow64\*,Microsoft HTML Viewer
advpack.dll,c:\windows\system32\*,Utility for installing software and drivers with rundll32.exe
advpack.dll,c:\windows\syswow64\*,Utility for installing software and drivers with rundll32.exe
pcwutl.dll,c:\windows\system32\*,Microsoft HTML Viewer
pcwutl.dll,c:\windows\syswow64\*,Microsoft HTML Viewer
shdocvw.dll,c:\windows\system32\*,Shell Doc Object and Control Library.
shdocvw.dll,c:\windows\syswow64\*,Shell Doc Object and Control Library.
ieframe.dll,c:\windows\system32\*,Internet Browser DLL for translating HTML code.
ieframe.dll,c:\windows\syswow64\*,Internet Browser DLL for translating HTML code.
dfshim.dll,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfshim.dll,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfshim.dll,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET
dfshim.dll,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET
url.dll,c:\windows\system32\*,Internet Shortcut Shell Extension DLL.
url.dll,c:\windows\syswow64\*,Internet Shortcut Shell Extension DLL.
ieadvpack.dll,c:\windows\system32\*,INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
ieadvpack.dll,c:\windows\syswow64\*,INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
syssetup.dll,c:\windows\system32\*,Windows NT System Setup
syssetup.dll,c:\windows\syswow64\*,Windows NT System Setup
winrm.vbs,c:\windows\system32\*,Script used for manage Windows RM settings
winrm.vbs,c:\windows\syswow64\*,Script used for manage Windows RM settings
manage-bde.wsf,c:\windows\system32\*,Script for managing BitLocker
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\windowsupdate\*,Proxy execution with CL_Mutexverifiers.ps1
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\audio\*,Proxy execution with CL_Mutexverifiers.ps1
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\video\*,Proxy execution with CL_Mutexverifiers.ps1
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\speech\*,Proxy execution with CL_Mutexverifiers.ps1
pubprn.vbs,c:\windows\system32\printing_admin_scripts\en-us\*,Proxy execution with Pubprn.vbs
pubprn.vbs,c:\windows\syswow64\printing_admin_scripts\en-us\*,Proxy execution with Pubprn.vbs
pester.bat,c:\program files\windowspowershell\modules\pester\3.4.0\bin\*,Used as part of the Powershell pester
pester.bat,c:\program files\windowspowershell\modules\pester\*\bin\*,Used as part of the Powershell pester
cl_loadassembly.ps1,c:\windows\diagnostics\system\audio\*,PowerShell Diagnostic Script
syncappvpublishingserver.vbs,c:\windows\system32\*,Script used related to app-v and publishing server
cl_invocation.ps1,c:\windows\diagnostics\system\aero\*,Aero diagnostics script
cl_invocation.ps1,c:\windows\diagnostics\system\audio\*,Aero diagnostics script
cl_invocation.ps1,c:\windows\diagnostics\system\windowsupdate\*,Aero diagnostics script
utilityfunctions.ps1,c:\windows\diagnostics\system\networking\*,PowerShell Diagnostic Script
coregen.exe,c:\program files\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight."
coregen.exe,c:\program files (x86)\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight."
fsi.exe,c:\program files\dotnet\sdk\[sdk version]\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
fsi.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\arm64\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\x64\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
ntdsutil.exe,c:\windows\system32\*,Command line utility used to export Active Directory.
sqltoolsps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+.
dump64.exe,c:\program files (x86)\microsoft visual studio\installer\feedback\*,Memory dump tool that comes with Microsoft Visual Studio
wsl.exe,c:\windows\system32\*,Windows subsystem for Linux executable
csi.exe,c:\program files (x86)\microsoft visual studio\2017\community\msbuild\15.0\bin\roslyn\*,Command line interface included with Visual Studio.
csi.exe,c:\program files (x86)\microsoft web tools\packages\microsoft.net.compilers.x.y.z\tools\*,Command line interface included with Visual Studio.
mftrace.exe,c:\program files (x86)\windows kits\10\bin\10.0.16299.0\*,Trace log generation tool for Media Foundation Tools.
mftrace.exe,c:\program files (x86)\windows kits\10\bin\*,Trace log generation tool for Media Foundation Tools.
adplus.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools
adplus.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools
excel.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary
excel.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary
excel.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary
excel.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary
excel.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary
excel.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary
excel.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary
excel.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary
excel.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary
excel.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary
excel.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary
excel.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary
excel.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary
excel.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary
dotnet.exe,c:\program files\dotnet\*,dotnet.exe comes with .NET Framework
sqlps.exe,c:\program files (x86)\microsoft sql server\100\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\110\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\120\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\150\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x86\accchecker\*,Verifies UI accessibility requirements
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x64\accchecker\*,Verifies UI accessibility requirements
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm\accchecker\*,Verifies UI accessibility requirements
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm64\accchecker\*,Verifies UI accessibility requirements
powerpnt.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary.
sqldumper.exe,c:\program files\microsoft sql server\90\shared\*,Debugging utility included with Microsoft SQL.
sqldumper.exe,c:\program files (x86)\microsoft office\root\vfs\programfilesx86\microsoft analysis\as oledb\140\*,Debugging utility included with Microsoft SQL.
remote.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools
remote.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools
appvlp.exe,c:\program files\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016
appvlp.exe,c:\program files (x86)\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016
agentexecutor.exe,c:\program files (x86)\*,Intune Management Extension included on Intune Managed Devices
dxcap.exe,c:\windows\system32\*,DirectX diagnostics/debugger included with Visual Studio.
dxcap.exe,c:\windows\syswow64\*,DirectX diagnostics/debugger included with Visual Studio.
cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools.
cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools.
defaultpack.exe,c:\program files (x86)\microsoft\defaultpack\*,This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.
devtoolslauncher.exe,c:\windows\system32\*,Binary will execute specified binary. Part of VS/VScode installation.
vsiisexelauncher.exe,c:\program files (x86)\microsoft visual studio\2019\community\common7\ide\extensions\microsoft\web tools\projectsystem\*,Binary will execute specified binary. Part of VS/VScode installation.
winword.exe,c:\program files\microsoft office\root\office16\*,Microsoft Office binary
winword.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary
winword.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary
winword.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary
winword.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary
winword.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary
winword.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary
winword.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary
winword.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary
winword.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary
winword.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary
winword.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary
winword.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary
winword.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary
winword.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary
fsianycpu.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,32/64-bit FSharp (F#) Interpreter included with Visual Studio.
vsjitdebugger.exe,c:\windows\system32\*,Just-In-Time (JIT) debugger included with Visual Studio
wfc.exe,c:\program files (x86)\microsoft sdks\windows\v10.0a\bin\netfx 4.8 tools\*,The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).
msdeploy.exe,c:\program files (x86)\iis\microsoft web deploy v3\*,Microsoft tool used to deploy Web Applications.
1 lolbas_file_name lolbas_file_path description
2 eventvwr.exe c:\windows\system32\* Displays Windows Event Logs in a GUI window.
3 eventvwr.exe c:\windows\syswow64\* Displays Windows Event Logs in a GUI window.
4 rasautou.exe c:\windows\system32\* Windows Remote Access Dialer
5 regedit.exe c:\windows\system32\* Used by Windows to manipulate registry
6 regedit.exe c:\windows\syswow64\* Used by Windows to manipulate registry
7 regsvr32.exe c:\windows\system32\* Used by Windows to register dlls
8 regsvr32.exe c:\windows\syswow64\* Used by Windows to register dlls
9 control.exe c:\windows\system32\* Binary used to launch controlpanel items in Windows
10 control.exe c:\windows\syswow64\* Binary used to launch controlpanel items in Windows
11 configsecuritypolicy.exe c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\* Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
12 scriptrunner.exe c:\windows\system32\* Execute binary through proxy binary to evade defensive counter measures
13 scriptrunner.exe c:\windows\syswow64\* Execute binary through proxy binary to evade defensive counter measures
14 offlinescannershell.exe c:\program files\windows defender\offline\* Windows Defender Offline Shell
15 atbroker.exe c:\windows\system32\* Helper binary for Assistive Technology (AT)
16 atbroker.exe c:\windows\syswow64\* Helper binary for Assistive Technology (AT)
17 mmc.exe c:\windows\system32\* Load snap-ins to locally and remotely manage Windows systems
18 mmc.exe c:\windows\syswow64\* Load snap-ins to locally and remotely manage Windows systems
19 mavinject.exe c:\windows\system32\* Used by App-v in Windows
20 mavinject.exe c:\windows\syswow64\* Used by App-v in Windows
21 ftp.exe c:\windows\system32\* A binary designed for connecting to FTP servers
22 ftp.exe c:\windows\syswow64\* A binary designed for connecting to FTP servers
23 ttdinject.exe c:\windows\system32\* Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
24 ttdinject.exe c:\windows\syswow64\* Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
25 certoc.exe c:\windows\system32\* Used for installing certificates
26 certoc.exe c:\windows\syswow64\* Used for installing certificates
27 at.exe c:\windows\system32\* Schedule periodic tasks
28 at.exe c:\windows\syswow64\* Schedule periodic tasks
29 netsh.exe c:\windows\system32\* Netsh is a Windows tool used to manipulate network interface settings.
30 netsh.exe c:\windows\syswow64\* Netsh is a Windows tool used to manipulate network interface settings.
31 pnputil.exe c:\windows\system32\* Used for installing drivers
32 ie4uinit.exe c:\windows\system32\* Executes commands from a specially prepared ie4uinit.inf file.
33 ie4uinit.exe c:\windows\syswow64\* Executes commands from a specially prepared ie4uinit.inf file.
34 infdefaultinstall.exe c:\windows\system32\* Binary used to perform installation based on content inside inf files
35 infdefaultinstall.exe c:\windows\syswow64\* Binary used to perform installation based on content inside inf files
36 forfiles.exe c:\windows\system32\* Selects and executes a command on a file or set of files. This command is useful for batch processing.
37 forfiles.exe c:\windows\syswow64\* Selects and executes a command on a file or set of files. This command is useful for batch processing.
38 register-cimprovider.exe c:\windows\system32\* Used to register new wmi providers
39 register-cimprovider.exe c:\windows\syswow64\* Used to register new wmi providers
40 tttracer.exe c:\windows\system32\* Used by Windows 1809 and newer to Debug Time Travel
41 tttracer.exe c:\windows\syswow64\* Used by Windows 1809 and newer to Debug Time Travel
42 xwizard.exe c:\windows\system32\* Execute custom class that has been added to the registry or download a file with Xwizard.exe
43 xwizard.exe c:\windows\syswow64\* Execute custom class that has been added to the registry or download a file with Xwizard.exe
44 pcalua.exe c:\windows\system32\* Program Compatibility Assistant
45 print.exe c:\windows\system32\* Used by Windows to send files to the printer
46 print.exe c:\windows\syswow64\* Used by Windows to send files to the printer
47 runscripthelper.exe c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\* Execute target PowerShell script
48 runscripthelper.exe c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\* Execute target PowerShell script
49 regasm.exe c:\windows\microsoft.net\framework\v2.0.50727\* Part of .NET
50 regasm.exe c:\windows\microsoft.net\framework64\v2.0.50727\* Part of .NET
51 regasm.exe c:\windows\microsoft.net\framework\v4.0.30319\* Part of .NET
52 regasm.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Part of .NET
53 cmd.exe c:\windows\system32\* The command-line interpreter in Windows
54 cmd.exe c:\windows\syswow64\* The command-line interpreter in Windows
55 msbuild.exe c:\windows\microsoft.net\framework\v2.0.50727\* Used to compile and execute code
56 msbuild.exe c:\windows\microsoft.net\framework64\v2.0.50727\* Used to compile and execute code
57 msbuild.exe c:\windows\microsoft.net\framework\v3.5\* Used to compile and execute code
58 msbuild.exe c:\windows\microsoft.net\framework64\v3.5\* Used to compile and execute code
59 msbuild.exe c:\windows\microsoft.net\framework\v4.0.30319\* Used to compile and execute code
60 msbuild.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Used to compile and execute code
61 msbuild.exe c:\program files (x86)\msbuild\14.0\bin\* Used to compile and execute code
62 certutil.exe c:\windows\system32\* Windows binary used for handling certificates
63 certutil.exe c:\windows\syswow64\* Windows binary used for handling certificates
64 vbc.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Binary file used for compile vbs code
65 vbc.exe c:\windows\microsoft.net\framework64\v3.5\* Binary file used for compile vbs code
66 psr.exe c:\windows\system32\* Windows Problem Steps Recorder, used to record screen and clicks.
67 psr.exe c:\windows\syswow64\* Windows Problem Steps Recorder, used to record screen and clicks.
68 extexport.exe c:\program files\internet explorer\* Load a DLL located in the c:\test folder with a specific name.
69 extexport.exe c:\program files (x86)\internet explorer\* Load a DLL located in the c:\test folder with a specific name.
70 rpcping.exe c:\windows\system32\* Used to verify rpc connection
71 rpcping.exe c:\windows\syswow64\* Used to verify rpc connection
72 msdt.exe c:\windows\system32\* Microsoft diagnostics tool
73 msdt.exe c:\windows\syswow64\* Microsoft diagnostics tool
74 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\64kb6472.inf_amd64_3daef03bbe98572b\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
75 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_0e9c57ae3396e055\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
76 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_209bd95d56b1ac2d\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
77 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_3fa2a843f8b7f16d\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
78 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_85c860f05274baa0\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
79 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_f7412e3e3404de80\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
80 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_feb9f1cf05b0de58\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
81 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_component.inf_amd64_0219cc1c7085a93f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
82 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_component.inf_amd64_df4f60b1cae9b14a\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
83 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_16eb18b0e2526e57\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
84 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_1c77f1231c19bc72\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
85 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_31c60cc38cfcca28\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
86 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_82f69cea8b2d928f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
87 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_b4d94f3e41ceb839\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
88 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_0606619cc97463de\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
89 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_0e95edab338ad669\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
90 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_22aac1442d387216\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
91 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_2461d914696db722\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
92 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_29d727269a34edf5\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
93 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_2caf76dbce56546d\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
94 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_353320edb98da643\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
95 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_4ea0ed0af1507894\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
96 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_56a48f4f1c2da7a7\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
97 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_64f23fdadb76a511\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
98 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_668dd0c6d3f9fa0e\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
99 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_6be8e5b7f731a6e5\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
100 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_6dad7e4e9a8fa889\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
101 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_6df442103a1937a4\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
102 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_767e7683f9ad126c\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
103 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_8644298f665a12c4\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
104 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_868acf86149aef5d\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
105 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_92cf9d9d84f1d3db\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
106 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_93239c65f222d453\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
107 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_9de8154b682af864\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
108 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_a7428663aca90897\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
109 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_ad7cb5e55a410add\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
110 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_afbf41cf8ab202d7\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
111 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_d193c96475eaa96e\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
112 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_db953c52208ada71\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
113 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_e7523682cc7528cc\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
114 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_e9f341319ca84274\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
115 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_f3a64c75ee4defb7\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
116 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_f51939e52b944f4b\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
117 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch_comp.inf_amd64_4938423c9b9639d7\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
118 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch_comp.inf_amd64_c8e108d4a62c59d5\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
119 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_dch_comp.inf_amd64_deecec7d232ced2b\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
120 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_01ee1299f4982efe\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
121 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_02edfc87000937e4\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
122 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0541b698fc6e40b0\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
123 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0707757077710fff\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
124 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
125 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0cff362f9dff4228\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
126 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_16ed7d82b93e4f68\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
127 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1a33d2f73651d989\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
128 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1aca2a92a37fce23\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
129 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1af2dd3e4df5fd61\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
130 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1d571527c7083952\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
131 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_23f7302c2b9ee813\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
132 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_24de78387e6208e4\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
133 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_250db833a1cd577e\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
134 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_25e7c5a58c052bc5\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
135 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_28d80681d3523b1c\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
136 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_2dda3b1147a3a572\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
137 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_31ba00ea6900d67d\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
138 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_329877a66f240808\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
139 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_42af9f4718aa1395\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
140 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_4645af5c659ae51a\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
141 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_48c2e68e54c92258\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
142 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_48e7e903a369eae2\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
143 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_491d20003583dabe\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
144 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_4b34c18659561116\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
145 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_51ce968bf19942c2\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
146 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_555cfc07a674ecdd\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
147 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_561bd21d54545ed3\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
148 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_579a75f602cc2dce\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
149 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_57f66a4f0a97f1a3\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
150 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_587befb80671fb38\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
151 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_62f096fe77e085c0\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
152 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_6ae0ddbb4a38e23c\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
153 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_6bb02522ea3fdb0d\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
154 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_6d34ac0763025a06\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
155 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_712b6a0adbaabc0a\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
156 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_78b09d9681a2400f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
157 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_842874489af34daa\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
158 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_88084eb1fe7cebc3\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
159 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_89033455cb08186f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
160 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_8a9535cd18c90bc3\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
161 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_8c1fc948b5a01c52\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
162 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_9088b61921a6ff9f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
163 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_90f68cd0dc48b625\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
164 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_95cb371d046d4b4c\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
165 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_a58de0cf5f3e9dca\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
166 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_abe9d37302f8b1ae\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
167 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_acb3edda7b82982f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
168 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_aebc5a8535dd3184\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
169 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_b5d4c82c67b39358\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
170 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_b846bbf1e81ea3cf\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
171 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_babb2e8b8072ff3b\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
172 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_bc75cebf5edbbc50\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
173 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_be91293cf20d4372\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
174 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c11f4d5f0bc4c592\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
175 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c4e5173126d31cf0\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
176 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c4f600ffe34acc7b\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
177 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c8634ed19e331cda\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
178 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c9081e50bcffa972\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
179 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_ceddadac8a2b489e\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
180 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_d4406f0ad6ec2581\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
181 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_d5877a2e0e6374b6\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
182 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_d8ca5f86add535ef\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
183 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_e8abe176c7b553b5\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
184 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_eabb3ac2c517211f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
185 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_f8d8be8fea71e1a0\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
186 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_fe5e116bb07c0629\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
187 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_fe73d2ebaa05fb95\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
188 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\igdlh64_kbl_kit127397.inf_amd64_e1da8ee9e92ccadb\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
189 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\k127153.inf_amd64_364f43f2a27f7bd7\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
190 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\k127153.inf_amd64_3f3936d8dec668b8\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
191 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\k127793.inf_amd64_3ab7883eddccbf0f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
192 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki129523.inf_amd64_32947eecf8f3e231\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
193 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki126950.inf_amd64_fa7f56314967630d\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
194 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki126951.inf_amd64_94804e3918169543\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
195 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki126973.inf_amd64_06dde156632145e3\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
196 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki126974.inf_amd64_9168fc04b8275db9\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
197 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127005.inf_amd64_753576c4406c1193\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
198 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127018.inf_amd64_0f67ff47e9e30716\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
199 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127021.inf_amd64_0d68af55c12c7c17\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
200 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127171.inf_amd64_368f8c7337214025\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
201 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127176.inf_amd64_86c658cabfb17c9c\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
202 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127390.inf_amd64_e1ccb879ece8f084\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
203 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127678.inf_amd64_8427d3a09f47dfc1\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
204 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127727.inf_amd64_cf8e31692f82192e\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
205 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127807.inf_amd64_fc915899816dbc5d\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
206 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki127850.inf_amd64_6ad8d99023b59fd5\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
207 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki128602.inf_amd64_6ff790822fd674ab\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
208 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki128916.inf_amd64_3509e1eb83b83cfb\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
209 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki129407.inf_amd64_f26f36ac54ce3076\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
210 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki129633.inf_amd64_d9b8af875f664a8c\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
211 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki129866.inf_amd64_e7cdca9882c16f55\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
212 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki130274.inf_amd64_bafd2440fa1ffdd6\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
213 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki130350.inf_amd64_696b7c6764071b63\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
214 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki130409.inf_amd64_0d8d61270dfb4560\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
215 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki130471.inf_amd64_26ad6921447aa568\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
216 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki130624.inf_amd64_d85487143eec5e1a\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
217 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki130825.inf_amd64_ee3ba427c553f15f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
218 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki130871.inf_amd64_382f7c369d4bf777\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
219 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki131064.inf_amd64_5d13f27a9a9843fa\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
220 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki131176.inf_amd64_fb4fe914575fdd15\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
221 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki131191.inf_amd64_d668106cb6f2eae0\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
222 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki131622.inf_amd64_0058d71ace34db73\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
223 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki132032.inf_amd64_f29660d80998e019\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
224 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki132337.inf_amd64_223d6831ffa64ab1\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
225 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki132535.inf_amd64_7875dff189ab2fa2\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
226 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki132544.inf_amd64_b8c1f31373153db4\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
227 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki132574.inf_amd64_54c9b905b975ee55\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
228 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki132869.inf_amd64_052eb72d070df60f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
229 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\kit126731.inf_amd64_1905c9d5f38631d9\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
230 dnscmd.exe c:\windows\system32\* A command-line interface for managing DNS servers
231 dnscmd.exe c:\windows\syswow64\* A command-line interface for managing DNS servers
232 wab.exe c:\program files\windows mail\* Windows address book manager
233 wab.exe c:\program files (x86)\windows mail\* Windows address book manager
234 msconfig.exe c:\windows\system32\* MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows
235 wscript.exe c:\windows\system32\* Used by Windows to execute scripts
236 wscript.exe c:\windows\syswow64\* Used by Windows to execute scripts
237 makecab.exe c:\windows\system32\* Binary to package existing files into a cabinet (.cab) file
238 makecab.exe c:\windows\syswow64\* Binary to package existing files into a cabinet (.cab) file
239 datasvcutil.exe c:\windows\microsoft.net\framework64\v3.5\* DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.
240 cmdl32.exe c:\windows\system32\* Microsoft Connection Manager Auto-Download
241 cmdl32.exe c:\windows\syswow64\* Microsoft Connection Manager Auto-Download
242 mshta.exe c:\windows\system32\* Used by Windows to execute html applications. (.hta)
243 mshta.exe c:\windows\syswow64\* Used by Windows to execute html applications. (.hta)
244 cmdkey.exe c:\windows\system32\* creates, lists, and deletes stored user names and passwords or credentials.
245 cmdkey.exe c:\windows\syswow64\* creates, lists, and deletes stored user names and passwords or credentials.
246 ilasm.exe c:\windows\microsoft.net\framework\v4.0.30319\* used for compile c# code into dll or exe.
247 ilasm.exe c:\windows\microsoft.net\framework64\v4.0.30319\* used for compile c# code into dll or exe.
248 rdrleakdiag.exe c:\windows\system32\* Microsoft Windows resource leak diagnostic tool
249 rdrleakdiag.exe c:\windows\syswow64\* Microsoft Windows resource leak diagnostic tool
250 mpcmdrun.exe c:\programdata\microsoft\windows defender\platform\4.18.2008.4-0\* Binary part of Windows Defender. Used to manage settings in Windows Defender
251 mpcmdrun.exe c:\programdata\microsoft\windows defender\platform\4.18.2008.7-0\* Binary part of Windows Defender. Used to manage settings in Windows Defender
252 mpcmdrun.exe c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\* Binary part of Windows Defender. Used to manage settings in Windows Defender
253 jsc.exe c:\windows\microsoft.net\framework\v4.0.30319\* Binary file used by .NET to compile javascript code to .exe or .dll format
254 jsc.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Binary file used by .NET to compile javascript code to .exe or .dll format
255 jsc.exe c:\windows\microsoft.net\framework\v2.0.50727\* Binary file used by .NET to compile javascript code to .exe or .dll format
256 jsc.exe c:\windows\microsoft.net\framework64\v2.0.50727\* Binary file used by .NET to compile javascript code to .exe or .dll format
257 cmstp.exe c:\windows\system32\* Installs or removes a Connection Manager service profile.
258 cmstp.exe c:\windows\syswow64\* Installs or removes a Connection Manager service profile.
259 stordiag.exe c:\windows\system32\* Storage diagnostic tool
260 stordiag.exe c:\windows\syswow64\* Storage diagnostic tool
261 odbcconf.exe c:\windows\system32\* Used in Windows for managing ODBC connections
262 odbcconf.exe c:\windows\syswow64\* Used in Windows for managing ODBC connections
263 wlrmdr.exe c:\windows\system32\* Windows Logon Reminder executable
264 printbrm.exe c:\windows\system32\spool\tools\* Printer Migration Command-Line Tool
265 dfsvc.exe c:\windows\microsoft.net\framework\v2.0.50727\* ClickOnce engine in Windows used by .NET
266 dfsvc.exe c:\windows\microsoft.net\framework64\v2.0.50727\* ClickOnce engine in Windows used by .NET
267 dfsvc.exe c:\windows\microsoft.net\framework\v4.0.30319\* ClickOnce engine in Windows used by .NET
268 dfsvc.exe c:\windows\microsoft.net\framework64\v4.0.30319\* ClickOnce engine in Windows used by .NET
269 extrac32.exe c:\windows\system32\* Extract to ADS, copy or overwrite a file with Extrac32.exe
270 extrac32.exe c:\windows\syswow64\* Extract to ADS, copy or overwrite a file with Extrac32.exe
271 rundll32.exe c:\windows\system32\* Used by Windows to execute dll files
272 rundll32.exe c:\windows\syswow64\* Used by Windows to execute dll files
273 runonce.exe c:\windows\system32\* Executes a Run Once Task that has been configured in the registry
274 runonce.exe c:\windows\syswow64\* Executes a Run Once Task that has been configured in the registry
275 explorer.exe c:\windows\* Binary used for managing files and system components within Windows
276 explorer.exe c:\windows\syswow64\* Binary used for managing files and system components within Windows
277 wuauclt.exe c:\windows\system32\* Windows Update Client
278 wsreset.exe c:\windows\system32\* Used to reset Windows Store settings according to its manifest file
279 finger.exe c:\windows\system32\* Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
280 finger.exe c:\windows\syswow64\* Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
281 regini.exe c:\windows\system32\* Used to manipulate the registry
282 regini.exe c:\windows\syswow64\* Used to manipulate the registry
283 reg.exe c:\windows\system32\* Used to manipulate the registry
284 reg.exe c:\windows\syswow64\* Used to manipulate the registry
285 syncappvpublishingserver.exe c:\windows\system32\* Used by App-v to get App-v server lists
286 syncappvpublishingserver.exe c:\windows\syswow64\* Used by App-v to get App-v server lists
287 bitsadmin.exe c:\windows\system32\* Used for managing background intelligent transfer
288 bitsadmin.exe c:\windows\syswow64\* Used for managing background intelligent transfer
289 msiexec.exe c:\windows\system32\* Used by Windows to execute msi files
290 msiexec.exe c:\windows\syswow64\* Used by Windows to execute msi files
291 regsvcs.exe c:\windows\system32\* Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
292 regsvcs.exe c:\windows\syswow64\* Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
293 gpscript.exe c:\windows\system32\* Used by group policy to process scripts
294 gpscript.exe c:\windows\syswow64\* Used by group policy to process scripts
295 diskshadow.exe c:\windows\system32\* Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
296 diskshadow.exe c:\windows\syswow64\* Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
297 ieexec.exe c:\windows\microsoft.net\framework\v2.0.50727\* The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
298 ieexec.exe c:\windows\microsoft.net\framework64\v2.0.50727\* The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
299 diantz.exe c:\windows\system32\* Binary that package existing files into a cabinet (.cab) file
300 diantz.exe c:\windows\syswow64\* Binary that package existing files into a cabinet (.cab) file
301 desktopimgdownldr.exe c:\windows\system32\* Windows binary used to configure lockscreen/desktop image
302 appinstaller.exe c:\program files\windowsapps\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe\* Tool used for installation of AppX/MSIX applications on Windows 10
303 sc.exe c:\windows\system32\* Used by Windows to manage services
304 sc.exe c:\windows\syswow64\* Used by Windows to manage services
305 replace.exe c:\windows\system32\* Used to replace file with another file
306 replace.exe c:\windows\syswow64\* Used to replace file with another file
307 schtasks.exe c:\windows\system32\* Schedule periodic tasks
308 schtasks.exe c:\windows\syswow64\* Schedule periodic tasks
309 microsoft.workflow.compiler.exe c:\windows\microsoft.net\framework64\v4.0.30319\* A utility included with .NET that is capable of compiling and executing C# or VB.net code.
310 expand.exe c:\windows\system32\* Binary that expands one or more compressed files
311 expand.exe c:\windows\syswow64\* Binary that expands one or more compressed files
312 conhost.exe c:\windows\system32\* Console Window host
313 bash.exe c:\windows\system32\* File used by Windows subsystem for Linux
314 bash.exe c:\windows\syswow64\* File used by Windows subsystem for Linux
315 pcwrun.exe c:\windows\system32\* Program Compatibility Wizard
316 fltmc.exe c:\windows\system32\* Filter Manager Control Program used by Windows
317 wmic.exe c:\windows\system32\wbem\* The WMI command-line (WMIC) utility provides a command-line interface for WMI
318 wmic.exe c:\windows\syswow64\wbem\* The WMI command-line (WMIC) utility provides a command-line interface for WMI
319 workfolders.exe c:\windows\system32\* Work Folders
320 settingsynchost.exe c:\windows\system32\* Host Process for Setting Synchronization
321 settingsynchost.exe c:\windows\syswow64\* Host Process for Setting Synchronization
322 pktmon.exe c:\windows\system32\* Capture Network Packets on the windows 10 with October 2018 Update or later.
323 pktmon.exe c:\windows\syswow64\* Capture Network Packets on the windows 10 with October 2018 Update or later.
324 aspnet_compiler.exe c:\windows\microsoft.net\framework\v4.0.30319\* ASP.NET Compilation Tool
325 aspnet_compiler.exe c:\windows\microsoft.net\framework64\v4.0.30319\* ASP.NET Compilation Tool
326 cscript.exe c:\windows\system32\* Binary used to execute scripts in Windows
327 cscript.exe c:\windows\syswow64\* Binary used to execute scripts in Windows
328 installutil.exe c:\windows\microsoft.net\framework\v2.0.50727\* The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
329 installutil.exe c:\windows\microsoft.net\framework64\v2.0.50727\* The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
330 installutil.exe c:\windows\microsoft.net\framework\v4.0.30319\* The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
331 installutil.exe c:\windows\microsoft.net\framework64\v4.0.30319\* The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
332 esentutl.exe c:\windows\system32\* Binary for working with Microsoft Joint Engine Technology (JET) database
333 esentutl.exe c:\windows\syswow64\* Binary for working with Microsoft Joint Engine Technology (JET) database
334 hh.exe c:\windows\* Binary used for processing chm files in Windows
335 hh.exe c:\windows\syswow64\* Binary used for processing chm files in Windows
336 findstr.exe c:\windows\system32\* Write to ADS, discover, or download files with Findstr.exe
337 findstr.exe c:\windows\syswow64\* Write to ADS, discover, or download files with Findstr.exe
338 verclsid.exe c:\windows\system32\* Used to verify a COM object before it is instantiated by Windows Explorer
339 verclsid.exe c:\windows\syswow64\* Used to verify a COM object before it is instantiated by Windows Explorer
340 certreq.exe c:\windows\system32\* Used for requesting and managing certificates
341 certreq.exe c:\windows\syswow64\* Used for requesting and managing certificates
342 csc.exe c:\windows\microsoft.net\framework\v4.0.30319\* Binary file used by .NET to compile C# code
343 csc.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Binary file used by .NET to compile C# code
344 imewdbld.exe c:\windows\system32\ime\shared\* Microsoft IME Open Extended Dictionary Module
345 presentationhost.exe c:\windows\system32\* File is used for executing Browser applications
346 presentationhost.exe c:\windows\syswow64\* File is used for executing Browser applications
347 shell32.dll c:\windows\system32\* Windows Shell Common Dll
348 shell32.dll c:\windows\syswow64\* Windows Shell Common Dll
349 zipfldr.dll c:\windows\system32\* Compressed Folder library
350 zipfldr.dll c:\windows\syswow64\* Compressed Folder library
351 desk.cpl c:\windows\system32\* Desktop Settings Control Panel
352 desk.cpl c:\windows\syswow64\* Desktop Settings Control Panel
353 comsvcs.dll c:\windows\system32\* COM+ Services
354 setupapi.dll c:\windows\system32\* Windows Setup Application Programming Interface
355 setupapi.dll c:\windows\syswow64\* Windows Setup Application Programming Interface
356 mshtml.dll c:\windows\system32\* Microsoft HTML Viewer
357 mshtml.dll c:\windows\syswow64\* Microsoft HTML Viewer
358 advpack.dll c:\windows\system32\* Utility for installing software and drivers with rundll32.exe
359 advpack.dll c:\windows\syswow64\* Utility for installing software and drivers with rundll32.exe
360 pcwutl.dll c:\windows\system32\* Microsoft HTML Viewer
361 pcwutl.dll c:\windows\syswow64\* Microsoft HTML Viewer
362 shdocvw.dll c:\windows\system32\* Shell Doc Object and Control Library.
363 shdocvw.dll c:\windows\syswow64\* Shell Doc Object and Control Library.
364 ieframe.dll c:\windows\system32\* Internet Browser DLL for translating HTML code.
365 ieframe.dll c:\windows\syswow64\* Internet Browser DLL for translating HTML code.
366 dfshim.dll c:\windows\microsoft.net\framework\v2.0.50727\* ClickOnce engine in Windows used by .NET
367 dfshim.dll c:\windows\microsoft.net\framework64\v2.0.50727\* ClickOnce engine in Windows used by .NET
368 dfshim.dll c:\windows\microsoft.net\framework\v4.0.30319\* ClickOnce engine in Windows used by .NET
369 dfshim.dll c:\windows\microsoft.net\framework64\v4.0.30319\* ClickOnce engine in Windows used by .NET
370 url.dll c:\windows\system32\* Internet Shortcut Shell Extension DLL.
371 url.dll c:\windows\syswow64\* Internet Shortcut Shell Extension DLL.
372 ieadvpack.dll c:\windows\system32\* INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
373 ieadvpack.dll c:\windows\syswow64\* INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
374 syssetup.dll c:\windows\system32\* Windows NT System Setup
375 syssetup.dll c:\windows\syswow64\* Windows NT System Setup
376 winrm.vbs c:\windows\system32\* Script used for manage Windows RM settings
377 winrm.vbs c:\windows\syswow64\* Script used for manage Windows RM settings
378 manage-bde.wsf c:\windows\system32\* Script for managing BitLocker
379 cl_mutexverifiers.ps1 c:\windows\diagnostics\system\windowsupdate\* Proxy execution with CL_Mutexverifiers.ps1
380 cl_mutexverifiers.ps1 c:\windows\diagnostics\system\audio\* Proxy execution with CL_Mutexverifiers.ps1
381 cl_mutexverifiers.ps1 c:\windows\diagnostics\system\video\* Proxy execution with CL_Mutexverifiers.ps1
382 cl_mutexverifiers.ps1 c:\windows\diagnostics\system\speech\* Proxy execution with CL_Mutexverifiers.ps1
383 pubprn.vbs c:\windows\system32\printing_admin_scripts\en-us\* Proxy execution with Pubprn.vbs
384 pubprn.vbs c:\windows\syswow64\printing_admin_scripts\en-us\* Proxy execution with Pubprn.vbs
385 pester.bat c:\program files\windowspowershell\modules\pester\3.4.0\bin\* Used as part of the Powershell pester
386 pester.bat c:\program files\windowspowershell\modules\pester\*\bin\* Used as part of the Powershell pester
387 cl_loadassembly.ps1 c:\windows\diagnostics\system\audio\* PowerShell Diagnostic Script
388 syncappvpublishingserver.vbs c:\windows\system32\* Script used related to app-v and publishing server
389 cl_invocation.ps1 c:\windows\diagnostics\system\aero\* Aero diagnostics script
390 cl_invocation.ps1 c:\windows\diagnostics\system\audio\* Aero diagnostics script
391 cl_invocation.ps1 c:\windows\diagnostics\system\windowsupdate\* Aero diagnostics script
392 utilityfunctions.ps1 c:\windows\diagnostics\system\networking\* PowerShell Diagnostic Script
393 coregen.exe c:\program files\microsoft silverlight\5.1.50918.0\* Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.
394 coregen.exe c:\program files (x86)\microsoft silverlight\5.1.50918.0\* Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.
395 fsi.exe c:\program files\dotnet\sdk\[sdk version]\fsharp\* 64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
396 fsi.exe c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\* 64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
397 visualuiaverifynative.exe c:\program files (x86)\windows kits\10\bin\[sdk version]\arm64\uiaverify\* A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
398 visualuiaverifynative.exe c:\program files (x86)\windows kits\10\bin\[sdk version]\x64\uiaverify\* A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
399 visualuiaverifynative.exe c:\program files (x86)\windows kits\10\bin\[sdk version]\uiaverify\* A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
400 ntdsutil.exe c:\windows\system32\* Command line utility used to export Active Directory.
401 sqltoolsps.exe c:\program files (x86)\microsoft sql server\130\tools\binn\* Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+.
402 dump64.exe c:\program files (x86)\microsoft visual studio\installer\feedback\* Memory dump tool that comes with Microsoft Visual Studio
403 wsl.exe c:\windows\system32\* Windows subsystem for Linux executable
404 csi.exe c:\program files (x86)\microsoft visual studio\2017\community\msbuild\15.0\bin\roslyn\* Command line interface included with Visual Studio.
405 csi.exe c:\program files (x86)\microsoft web tools\packages\microsoft.net.compilers.x.y.z\tools\* Command line interface included with Visual Studio.
406 mftrace.exe c:\program files (x86)\windows kits\10\bin\10.0.16299.0\* Trace log generation tool for Media Foundation Tools.
407 mftrace.exe c:\program files (x86)\windows kits\10\bin\* Trace log generation tool for Media Foundation Tools.
408 adplus.exe c:\program files (x86)\windows kits\10\debuggers\x64\* Debugging tool included with Windows Debugging Tools
409 adplus.exe c:\program files (x86)\windows kits\10\debuggers\x86\* Debugging tool included with Windows Debugging Tools
410 excel.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* Microsoft Office binary
411 excel.exe c:\program files\microsoft office 16\clientx64\root\office16\* Microsoft Office binary
412 excel.exe c:\program files (x86)\microsoft office\office16\* Microsoft Office binary
413 excel.exe c:\program files\microsoft office\office16\* Microsoft Office binary
414 excel.exe c:\program files (x86)\microsoft office 15\clientx86\root\office15\* Microsoft Office binary
415 excel.exe c:\program files\microsoft office 15\clientx64\root\office15\* Microsoft Office binary
416 excel.exe c:\program files (x86)\microsoft office\office15\* Microsoft Office binary
417 excel.exe c:\program files\microsoft office\office15\* Microsoft Office binary
418 excel.exe c:\program files (x86)\microsoft office 14\clientx86\root\office14\* Microsoft Office binary
419 excel.exe c:\program files\microsoft office 14\clientx64\root\office14\* Microsoft Office binary
420 excel.exe c:\program files (x86)\microsoft office\office14\* Microsoft Office binary
421 excel.exe c:\program files\microsoft office\office14\* Microsoft Office binary
422 excel.exe c:\program files (x86)\microsoft office\office12\* Microsoft Office binary
423 excel.exe c:\program files\microsoft office\office12\* Microsoft Office binary
424 dotnet.exe c:\program files\dotnet\* dotnet.exe comes with .NET Framework
425 sqlps.exe c:\program files (x86)\microsoft sql server\100\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
426 sqlps.exe c:\program files (x86)\microsoft sql server\110\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
427 sqlps.exe c:\program files (x86)\microsoft sql server\120\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
428 sqlps.exe c:\program files (x86)\microsoft sql server\130\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
429 sqlps.exe c:\program files (x86)\microsoft sql server\150\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
430 acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x86\accchecker\* Verifies UI accessibility requirements
431 acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x64\accchecker\* Verifies UI accessibility requirements
432 acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm\accchecker\* Verifies UI accessibility requirements
433 acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm64\accchecker\* Verifies UI accessibility requirements
434 powerpnt.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* Microsoft Office binary.
435 powerpnt.exe c:\program files\microsoft office 16\clientx64\root\office16\* Microsoft Office binary.
436 powerpnt.exe c:\program files (x86)\microsoft office\office16\* Microsoft Office binary.
437 powerpnt.exe c:\program files\microsoft office\office16\* Microsoft Office binary.
438 powerpnt.exe c:\program files (x86)\microsoft office 15\clientx86\root\office15\* Microsoft Office binary.
439 powerpnt.exe c:\program files\microsoft office 15\clientx64\root\office15\* Microsoft Office binary.
440 powerpnt.exe c:\program files (x86)\microsoft office\office15\* Microsoft Office binary.
441 powerpnt.exe c:\program files\microsoft office\office15\* Microsoft Office binary.
442 powerpnt.exe c:\program files (x86)\microsoft office 14\clientx86\root\office14\* Microsoft Office binary.
443 powerpnt.exe c:\program files\microsoft office 14\clientx64\root\office14\* Microsoft Office binary.
444 powerpnt.exe c:\program files (x86)\microsoft office\office14\* Microsoft Office binary.
445 powerpnt.exe c:\program files\microsoft office\office14\* Microsoft Office binary.
446 powerpnt.exe c:\program files (x86)\microsoft office\office12\* Microsoft Office binary.
447 powerpnt.exe c:\program files\microsoft office\office12\* Microsoft Office binary.
448 sqldumper.exe c:\program files\microsoft sql server\90\shared\* Debugging utility included with Microsoft SQL.
449 sqldumper.exe c:\program files (x86)\microsoft office\root\vfs\programfilesx86\microsoft analysis\as oledb\140\* Debugging utility included with Microsoft SQL.
450 remote.exe c:\program files (x86)\windows kits\10\debuggers\x64\* Debugging tool included with Windows Debugging Tools
451 remote.exe c:\program files (x86)\windows kits\10\debuggers\x86\* Debugging tool included with Windows Debugging Tools
452 appvlp.exe c:\program files\microsoft office\root\client\* Application Virtualization Utility Included with Microsoft Office 2016
453 appvlp.exe c:\program files (x86)\microsoft office\root\client\* Application Virtualization Utility Included with Microsoft Office 2016
454 agentexecutor.exe c:\program files (x86)\* Intune Management Extension included on Intune Managed Devices
455 dxcap.exe c:\windows\system32\* DirectX diagnostics/debugger included with Visual Studio.
456 dxcap.exe c:\windows\syswow64\* DirectX diagnostics/debugger included with Visual Studio.
457 cdb.exe c:\program files (x86)\windows kits\10\debuggers\x64\* Debugging tool included with Windows Debugging Tools.
458 cdb.exe c:\program files (x86)\windows kits\10\debuggers\x86\* Debugging tool included with Windows Debugging Tools.
459 defaultpack.exe c:\program files (x86)\microsoft\defaultpack\* This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.
460 devtoolslauncher.exe c:\windows\system32\* Binary will execute specified binary. Part of VS/VScode installation.
461 vsiisexelauncher.exe c:\program files (x86)\microsoft visual studio\2019\community\common7\ide\extensions\microsoft\web tools\projectsystem\* Binary will execute specified binary. Part of VS/VScode installation.
462 winword.exe c:\program files\microsoft office\root\office16\* Microsoft Office binary
463 winword.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* Microsoft Office binary
464 winword.exe c:\program files\microsoft office 16\clientx64\root\office16\* Microsoft Office binary
465 winword.exe c:\program files (x86)\microsoft office\office16\* Microsoft Office binary
466 winword.exe c:\program files\microsoft office\office16\* Microsoft Office binary
467 winword.exe c:\program files (x86)\microsoft office 15\clientx86\root\office15\* Microsoft Office binary
468 winword.exe c:\program files\microsoft office 15\clientx64\root\office15\* Microsoft Office binary
469 winword.exe c:\program files (x86)\microsoft office\office15\* Microsoft Office binary
470 winword.exe c:\program files\microsoft office\office15\* Microsoft Office binary
471 winword.exe c:\program files (x86)\microsoft office 14\clientx86\root\office14\* Microsoft Office binary
472 winword.exe c:\program files\microsoft office 14\clientx64\root\office14\* Microsoft Office binary
473 winword.exe c:\program files (x86)\microsoft office\office14\* Microsoft Office binary
474 winword.exe c:\program files\microsoft office\office14\* Microsoft Office binary
475 winword.exe c:\program files (x86)\microsoft office\office12\* Microsoft Office binary
476 winword.exe c:\program files\microsoft office\office12\* Microsoft Office binary
477 fsianycpu.exe c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\* 32/64-bit FSharp (F#) Interpreter included with Visual Studio.
478 vsjitdebugger.exe c:\windows\system32\* Just-In-Time (JIT) debugger included with Visual Studio
479 wfc.exe c:\program files (x86)\microsoft sdks\windows\v10.0a\bin\netfx 4.8 tools\* The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).
480 msdeploy.exe c:\program files (x86)\iis\microsoft web deploy v3\* Microsoft tool used to deploy Web Applications.

Some files were not shown because too many files have changed in this diff Show More