Skip to content

Add slui.yml, fodhelper.yml, regedit.yml#401

Open
havoc3-3 wants to merge 10 commits intoLOLBAS-Project:masterfrom
havoc3-3:master
Open

Add slui.yml, fodhelper.yml, regedit.yml#401
havoc3-3 wants to merge 10 commits intoLOLBAS-Project:masterfrom
havoc3-3:master

Conversation

@havoc3-3
Copy link
Contributor

@havoc3-3 havoc3-3 commented Sep 26, 2024

Similar to my past submission (ComputerDefaults), hijacking the registry key "HKEY_CURRENT_USER\Software\Classes\exefile" allows the proxied execution of scripts/binaries via these three native binaries (slui, fodhelper, regedit).

image

@tyler-mcadam
Copy link

Looks like all 3 use ms-settings\shell\open\command and exefile\shell\open\command, probably depends on the version of Windows.
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_event/registry_event_shell_open_keys_manipulation.yml

@wietze wietze self-requested a review May 28, 2025 13:24
@wietze wietze requested a review from a team as a code owner March 16, 2026 12:59
Copy link
Member

@wietze wietze left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @havoc3-3 , thanks for your patience.
On Windows 11 25H2, regedit and slui do not seem to auto-elevate anymore. fodhelper however does.

Could you confirm this to be accurate? If so, we can remove those from the PR and the other changes can be merged. Thanks for your submission.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants