Skip to content

Commit

Permalink
Update cryptbase.yml
Browse files Browse the repository at this point in the history
Add Microsoft.BDD.Catalog35.exe
  • Loading branch information
wsummerhill authored Nov 22, 2024
1 parent 73f4101 commit 065594b
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions yml/microsoft/built-in/cryptbase.yml
Original file line number Diff line number Diff line change
Expand Up @@ -223,15 +223,24 @@ VulnerableExecutables:
Type: Authenticode
SHA256:
- 6511ef24c41cf20f707119dd40971420f1cd6f97f0e888b7d24b5e0dec9d5495
- Path: 'C:\Program Files\Microsoft Deployment Toolkit\Bin\Microsoft.BDD.Catalog35.exe'
Type: Sideloading
ExpectedSignatureInformation:
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Type: Catalog
Resources:
- https://wietze.github.io/blog/hijacking-dlls-in-windows
- https://securityintelligence.com/posts/windows-features-dll-sideloading/
- https://github.com/xforcered/WFH
- https://twitter.com/AndrewOliveau/status/1682185200862625792
- https://x.com/BSummerz/status/1860045985919205645
Acknowledgements:
- Name: Wietze
Twitter: '@wietze'
- Name: Chris Spehn
Twitter: '@ConsciousHacker'
- Name: Andrew Oliveau
Twitter: '@AndrewOliveau'
- Name: Will Summerhill
Twitter: '@BSummerz'

0 comments on commit 065594b

Please sign in to comment.