1 repository
Techniques to execute binaries by leveraging trusted parents, including renamed or masked binaries.
Distinct from Local Binary Execution: Focuses on evading detection via renamed binaries and proxy processes, rather than general local execution.
Explore 1 awesome GitHub repository matching development tools & productivity · Bypass Execution. Refine with filters or upvote what's useful.
LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro
Identifies signed tools that can be used to launch renamed binaries as child processes to evade security controls.