Skip to content

Commit 960fa25

Browse files
1 parent 8abdda1 commit 960fa25

File tree

2 files changed

+48
-0
lines changed

2 files changed

+48
-0
lines changed
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
---
2+
Name: AppLauncher.exe
3+
Description: User Experience Virtualization tool that launches applications under monitoring to capture and synchronize user settings.
4+
Author: Avihay Eldad
5+
Created: 2025-09-21
6+
Commands:
7+
- Command: AppLauncher.exe {PATH_ABSOLUTE:.exe}
8+
Description: Launches an executable via User Experience Virtualization tool.
9+
Usecase: Executes an executable under a trusted, Microsoft signed binary.
10+
Category: Execute
11+
Privileges: User
12+
MitreID: T1127
13+
OperatingSystem: Windows
14+
Tags:
15+
- Execute: EXE
16+
Full_Path:
17+
- Path: C:\Program Files\Windows Kits\10\Microsoft User Experience Virtualization\Management\AppLauncher.exe
18+
- Path: C:\Program Files (x86)\Windows Kits\10\Microsoft User Experience Virtualization\Management\AppLauncher.exe
19+
Resources:
20+
- Link: https://learn.microsoft.com/en-us/microsoft-desktop-optimization-pack/ue-v/uev-getting-started
21+
Acknowledgement:
22+
- Person: Avihay Eldad
23+
Handle: '@AvihayEldad'
24+
---

_lolbas/OtherMSBinaries/Mpiexec.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
---
2+
Name: Mpiexec.exe
3+
Description: Command-line tool for running Message Passing Interface (MPI) applications.
4+
Author: Avihay Eldad
5+
Created: 2025-09-25
6+
Commands:
7+
- Command: mpiexec.exe {CMD}
8+
Description: Executes a command via MPI commad-line tool.
9+
Usecase: Executes commands under a trusted, Microsoft signed binary.
10+
Category: Execute
11+
Privileges: User
12+
MitreID: T1127
13+
OperatingSystem: Windows
14+
Tags:
15+
- Execute: CMD
16+
Full_Path:
17+
- Path: C:\Program Files\Microsoft MPI\Bin\mpiexec.exe
18+
- Path: C:\Program Files (x86)\Microsoft MPI\Bin\mpiexec.exe
19+
Resources:
20+
- Link: https://learn.microsoft.com/en-us/powershell/high-performance-computing/mpiexec
21+
Acknowledgement:
22+
- Person: Avihay Eldad
23+
Handle: '@AvihayEldad'
24+
---

0 commit comments

Comments
 (0)