Skip to content

Commit cc34b08

Browse files
1 parent a4ea46a commit cc34b08

File tree

1 file changed

+11
-0
lines changed

1 file changed

+11
-0
lines changed

_lolbas/Binaries/Mmc.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,15 @@ Commands:
2222
OperatingSystem: Windows 10 (and possibly earlier versions), Windows 11
2323
Tags:
2424
- Execute: DLL
25+
- Command: mmc.exe -Embedding {PATH_ABSOLUTE:.msc}
26+
Description: Download and save an executable to disk
27+
Usecase: Download file from Internet
28+
Category: Download
29+
Privileges: User
30+
MitreID: T1218.014
31+
OperatingSystem: Windows 10 (and possibly earlier versions), Windows 11
32+
Tags:
33+
- Application: GUI
2534
Full_Path:
2635
- Path: C:\Windows\System32\mmc.exe
2736
- Path: C:\Windows\SysWOW64\mmc.exe
@@ -31,9 +40,11 @@ Detection:
3140
Resources:
3241
- Link: https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/
3342
- Link: https://offsec.almond.consulting/UAC-bypass-dotnet.html
43+
- Link: https://www.youtube.com/watch?v=LFgZOTmhzeA
3444
Acknowledgement:
3545
- Person: Jimmy
3646
Handle: '@bohops'
3747
- Person: clem
3848
Handle: '@clavoillotte'
49+
- Person: Fredrik H. Brathen
3950
---

0 commit comments

Comments
 (0)