Living off the land » 履歴 » バージョン 5
kanata, 2025/06/06 19:10
| 1 | 1 | kanata | # Living off the land |
|---|---|---|---|
| 2 | 2 | kanata | |
| 3 | 3 | kanata | {{last_updated_at}} |
| 4 | |||
| 5 | 4 | kanata | {{>toc}} |
| 6 | |||
| 7 | ## LOLBAS(Living Off The Land Binaries, Scripts and Libraries) |
||
| 8 | 2 | kanata | https://lolbas-project.github.io |
| 9 | 1 | kanata | > Windows |
| 10 | 2 | kanata | |
| 11 | 4 | kanata | ## LOLDrivers(Living Off The Land Drivers) |
| 12 | 1 | kanata | https://www.loldrivers.io |
| 13 | 2 | kanata | > Windowsのドライバ |
| 14 | |||
| 15 | 4 | kanata | ## LOOBins(Living Off the Orchard: macOS Binaries) |
| 16 | 2 | kanata | https://www.loobins.io |
| 17 | > MacOS |
||
| 18 | 1 | kanata | |
| 19 | 4 | kanata | ## GTFOBins |
| 20 | 2 | kanata | https://gtfobins.github.io |
| 21 | 1 | kanata | > Unix,Linux |
| 22 | 2 | kanata | |
| 23 | 5 | kanata | ### splunk Detection: Curl Download and Bash Execution |
| 24 | |||
| 25 | splunkで検出するための情報 |
||
| 26 | https://research.splunk.com/endpoint/900bc324-59f3-11ec-9fb4-acde48001122/#implementation |
||
| 27 | |||
| 28 | 4 | kanata | ## LOLESXi(Living Off The Land ESXi) |
| 29 | 1 | kanata | https://lolesxi-project.github.io/LOLESXi/ |
| 30 | 2 | kanata | > ESXi |
| 31 | |||
| 32 | 4 | kanata | ## LOTS(Living Off Trusted Sites) |
| 33 | 2 | kanata | https://lots-project.com |
| 34 | > ドメイン |
||
| 35 | |||
| 36 | 4 | kanata | ## LOLC2 |
| 37 | 2 | kanata | https://lolc2.github.io |
| 38 | >C2 |
||
| 39 | |||
| 40 | 4 | kanata | ## LOTTunnels(Living Off The Tunnels) |
| 41 | 2 | kanata | https://lottunnels.github.io |
| 42 | >検知 |