Top 25 Windows LOLBAS Binaries Flashcards

Top 25 most abused LOLBIN per the lolbas-project and chatgpt analysis. (61 cards)

1
Q

Front (Question)

A

Back (Answer)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the folder path for Command Line Interface?

A

C:\Windows\System32\cmd.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the LOLBAS functions of C:\Windows\System32\cmd.exe?

A

Command Line Interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the expected use of C:\Windows\System32\cmd.exe?

A

Execute system commands, scripts, batch files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the expected parent processes for C:\Windows\System32\cmd.exe?

A

explorer.exe, services.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the expected conditions C:\Windows\System32\cmd.exe is created for?

A

User interaction, script execution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are common malicious uses of C:\Windows\System32\cmd.exe?

A

Command execution, script deployment, persistence mechanisms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the folder path for Scripting Language, Automation?

A

C:\Windows\System32\powershell.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the LOLBAS functions of C:\Windows\System32\powershell.exe?

A

Scripting Language, Automation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the expected use of C:\Windows\System32\powershell.exe?

A

Automation, configuration management, task automation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the expected parent processes for C:\Windows\System32\powershell.exe?

A

explorer.exe, taskeng.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the expected conditions C:\Windows\System32\powershell.exe is created for?

A

Task scheduling, user scripts, administrative tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are common malicious uses of C:\Windows\System32\powershell.exe?

A

Download and execute payloads, bypassing security controls, lateral movement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the folder path for Execute DLLs?

A

C:\Windows\System32\rundll32.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the LOLBAS functions of C:\Windows\System32\rundll32.exe?

A

Execute DLLs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the expected use of C:\Windows\System32\rundll32.exe?

A

Load and run DLLs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What are the expected parent processes for C:\Windows\System32\rundll32.exe?

A

explorer.exe, taskeng.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the expected conditions C:\Windows\System32\rundll32.exe is created for?

A

DLL execution, system configuration changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are common malicious uses of C:\Windows\System32\rundll32.exe?

A

DLL injection, persistence, command execution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the folder path for Execute HTML applications?

A

C:\Windows\System32\mshta.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What are the LOLBAS functions of C:\Windows\System32\mshta.exe?

A

Execute HTML applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is the expected use of C:\Windows\System32\mshta.exe?

A

Run HTML-based scripts and applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What are the expected parent processes for C:\Windows\System32\mshta.exe?

A

explorer.exe, wscript.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What are the expected conditions C:\Windows\System32\mshta.exe is created for?

A

Script execution, user interaction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
What are common malicious uses of C:\Windows\System32\mshta.exe?
Download and execute payloads, phishing attacks, persistence
26
What is the folder path for Task scheduling?
C:\Windows\System32\schtasks.exe
27
What are the LOLBAS functions of C:\Windows\System32\schtasks.exe?
Task scheduling
28
What is the expected use of C:\Windows\System32\schtasks.exe?
Create and manage scheduled tasks
29
What are the expected parent processes for C:\Windows\System32\schtasks.exe?
explorer.exe, taskeng.exe
30
What are the expected conditions C:\Windows\System32\schtasks.exe is created for?
Task automation, system maintenance
31
What are common malicious uses of C:\Windows\System32\schtasks.exe?
Persistence, privilege escalation, lateral movement
32
What is the folder path for WMI Command-line tool?
C:\Windows\System32\wmic.exe
33
What are the LOLBAS functions of C:\Windows\System32\wmic.exe?
WMI Command-line tool
34
What is the expected use of C:\Windows\System32\wmic.exe?
Management and configuration of local and remote systems
35
What are the expected parent processes for C:\Windows\System32\wmic.exe?
explorer.exe, cmd.exe
36
What are the expected conditions C:\Windows\System32\wmic.exe is created for?
System administration, automation scripts
37
What are common malicious uses of C:\Windows\System32\wmic.exe?
Information gathering, lateral movement, persistence
38
What is the folder path for Certificate Services?
C:\Windows\System32\certutil.exe
39
What are the LOLBAS functions of C:\Windows\System32\certutil.exe?
Certificate Services
40
What is the expected use of C:\Windows\System32\certutil.exe?
Manage and manipulate certificates
41
What are the expected parent processes for C:\Windows\System32\certutil.exe?
explorer.exe, cmd.exe
42
What are the expected conditions C:\Windows\System32\certutil.exe is created for?
Certificate management, network security
43
What are common malicious uses of C:\Windows\System32\certutil.exe?
Download and decode payloads, bypass security controls
44
What is the folder path for Register and unregister DLLs?
C:\Windows\System32\regsvr32.exe
45
What are the LOLBAS functions of C:\Windows\System32\regsvr32.exe?
Register and unregister DLLs
46
What is the expected use of C:\Windows\System32\regsvr32.exe?
Register or unregister DLL files
47
What are the expected parent processes for C:\Windows\System32\regsvr32.exe?
explorer.exe, cmd.exe
48
What are the expected conditions C:\Windows\System32\regsvr32.exe is created for?
DLL management, system configuration
49
What are common malicious uses of C:\Windows\System32\regsvr32.exe?
Bypass application whitelisting, execute remote payloads
50
What is the folder path for Manage BITS jobs?
C:\Windows\System32\bitsadmin.exe
51
What are the LOLBAS functions of C:\Windows\System32\bitsadmin.exe?
Manage BITS jobs
52
What is the expected use of C:\Windows\System32\bitsadmin.exe?
Create, monitor, and manage BITS jobs
53
What are the expected parent processes for C:\Windows\System32\bitsadmin.exe?
explorer.exe, cmd.exe
54
What are the expected conditions C:\Windows\System32\bitsadmin.exe is created for?
Background file transfers, software updates
55
What are common malicious uses of C:\Windows\System32\bitsadmin.exe?
Download and execute malicious files, persistence
56
What is the folder path for Registry manipulation?
C:\Windows\System32\reg.exe
57
What are the LOLBAS functions of C:\Windows\System32\reg.exe?
Registry manipulation
58
What is the expected use of C:\Windows\System32\reg.exe?
Query and modify the Windows registry
59
What are the expected parent processes for C:\Windows\System32\reg.exe?
explorer.exe, cmd.exe
60
What are the expected conditions C:\Windows\System32\reg.exe is created for?
Registry management, system configuration
61
What are common malicious uses of C:\Windows\System32\reg.exe?
Persistence, privilege escalation, system manipulation