{"id":16930964,"url":"https://github.com/notoriousrebel/find-lolbas","last_synced_at":"2025-04-11T18:32:21.323Z","repository":{"id":127622228,"uuid":"193973796","full_name":"NotoriousRebel/Find-LOLBAS","owner":"NotoriousRebel","description":"Simple powershell script to find living off land binaries and scripts on a system.","archived":false,"fork":false,"pushed_at":"2019-08-24T01:28:17.000Z","size":24,"stargazers_count":20,"open_issues_count":0,"forks_count":10,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-03-25T14:21:46.605Z","etag":null,"topics":["blueteam","living-off-the-land","powershell","redteam"],"latest_commit_sha":null,"homepage":null,"language":"PowerShell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/NotoriousRebel.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2019-06-26T20:33:28.000Z","updated_at":"2025-03-24T05:36:23.000Z","dependencies_parsed_at":null,"dependency_job_id":"d9019342-ac54-473b-88f0-dde01dd8c544","html_url":"https://github.com/NotoriousRebel/Find-LOLBAS","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/NotoriousRebel%2FFind-LOLBAS","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/NotoriousRebel%2FFind-LOLBAS/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/NotoriousRebel%2FFind-LOLBAS/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/NotoriousRebel%2FFind-LOLBAS/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/NotoriousRebel","download_url":"https://codeload.github.com/NotoriousRebel/Find-LOLBAS/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248458697,"owners_count":21107129,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["blueteam","living-off-the-land","powershell","redteam"],"created_at":"2024-10-13T20:42:54.623Z","updated_at":"2025-04-11T18:32:21.308Z","avatar_url":"https://github.com/NotoriousRebel.png","language":"PowerShell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Find-LOLBAS\r\n\r\nA simple Powershell script for enumerating living off the land binaries and scripts on a system.\r\n\r\n## Why\r\n\r\nManually verifying if the binaries or scripts are on the system \u003cbr\u003e\r\nwould take a while, with automating the process this increases overall productivity\r\nof redteamers \u003cbr\u003e\r\nwho need to quickly bypass applocker or need to execute code in unique ways.\r\n\r\n## How to Use?\r\n\r\nBy simply running the script the rest is taken care of! \u003cbr\u003e\r\nThe output will be on the screen for you to assess, it will be in the format \u003cbr\u003e\r\nof the Binary or Script name, path, and an example command utilizing it.\r\n\r\n## License\r\n\r\nThis project is licensed under the BSD 3-Clause License -\r\nsee the [License](LICENSE) file for details\r\n\r\n## Acknowledgments\r\n\r\nThis project wouldn't be possible without the [LOLBAS](https://github.com/LOLBAS-Project/LOLBAS) project.\r\n\r\n### Roadmap\r\n\r\n- [ ] Add option to run script by executing C# code in Powershell\r\n- [ ] Add option to allow user to encode payload by loading Crypt32.dll\r\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnotoriousrebel%2Ffind-lolbas","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnotoriousrebel%2Ffind-lolbas","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnotoriousrebel%2Ffind-lolbas/lists"}