Skip to content

Commit

Permalink
Update Msdeploy.yml and add copy utility (#354)
Browse files Browse the repository at this point in the history
  • Loading branch information
avihayeldad authored Jul 15, 2024
1 parent 70268a5 commit da4f6e5
Showing 1 changed file with 18 additions and 2 deletions.
20 changes: 18 additions & 2 deletions yml/OtherMSBinaries/Msdeploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,16 +10,30 @@ Commands:
Category: Execute
Privileges: User
MitreID: T1218
OperatingSystem: Windows server
OperatingSystem: Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11, Windows Server
- Command: msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand="c:\temp\calc.bat"
Description: Launch calc.bat via msdeploy.exe.
Usecase: Local execution of batch file using msdeploy.exe.
Category: AWL Bypass
Privileges: User
MitreID: T1218
OperatingSystem: Windows server
OperatingSystem: Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11, Windows Server
- Command: msdeploy.exe -verb:sync -source:filePath=C:\windows\system32\calc.exe -dest:filePath=C:\Users\Public\calc.exe
Description: Copy file from source to destination.
Usecase: Copy file.
Category: Copy
Privileges: User
MitreID: T1105
OperatingSystem: Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11, Windows Server
Full_Path:
- Path: C:\Program Files\IIS\Microsoft Web Deploy V2\msdeploy.exe
- Path: C:\Program Files (x86)\IIS\Microsoft Web Deploy V2\msdeploy.exe
- Path: C:\Program Files\IIS\Microsoft Web Deploy V3\msdeploy.exe
- Path: C:\Program Files (x86)\IIS\Microsoft Web Deploy V3\msdeploy.exe
- Path: C:\Program Files\IIS\Microsoft Web Deploy V4\msdeploy.exe
- Path: C:\Program Files (x86)\IIS\Microsoft Web Deploy V4\msdeploy.exe
- Path: C:\Program Files\IIS\Microsoft Web Deploy V5\msdeploy.exe
- Path: C:\Program Files (x86)\IIS\Microsoft Web Deploy V5\msdeploy.exe
Code_Sample:
- Code:
Detection:
Expand All @@ -30,3 +44,5 @@ Resources:
Acknowledgement:
- Person: Pierre-Alexandre Braeken
Handle: '@pabraeken'
- Person: Avihay Eldad
Handle: '@AvihayEldad'

0 comments on commit da4f6e5

Please sign in to comment.