From 1f52d1fe625697f88644bf635e3b2d4368601221 Mon Sep 17 00:00:00 2001 From: op7ic <3172590+op7ic@users.noreply.github.com> Date: Fri, 3 Aug 2018 22:44:19 +0100 Subject: [PATCH] fixes --- README.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 43d5bcc..12b4932 100644 --- a/README.md +++ b/README.md @@ -27,12 +27,12 @@ The script executes calc.exe. You can replace this easily with metasploit execut The following techniques are currently covered by this script: | ATT&CK | LOLBAS | Invoke-CradleCrafter | Custom | Variants | -| ------------- | ------------- | ------------- | ------------- | +| ------------- | ------------- | ------------- | ------------- | ------------- | | T1197 | msiexec.exe | MEMORY\PSWEBSTRING | winnt32 | bitsadmin regsrv32 | | T1118 | diskshadow.exe | MEMORY\PSWEBDATA | winrs | manage-bde.wsf + rundll32 JS | -| T1170 | esentutl.exe | MEMORY\PSWEBOPENREAD | waitfor | -| T1086 | replace.exe | MEMORY\NETWEBSTRING | .SettingContent-ms file | -| T1121 | SyncAppvPublishingServer | MEMORY\NETWEBDATA | +| T1170 | esentutl.exe | MEMORY\PSWEBOPENREAD | waitfor | | +| T1086 | replace.exe | MEMORY\NETWEBSTRING | .SettingContent-ms file | | +| T1121 | SyncAppvPublishingServer | MEMORY\NETWEBDATA | | | T1117 | hh.exe | MEMORY\NETWEBOPENREAD | | T1127 | ieexec.exe | MEMORY\PSWEBREQUEST | | T1047 | Setupapi | MEMORY\PSRESTMETHOD |