Unified Knowledge Base

LOLBins & Execution Catalog

Browse, filter, and discover weaponized binaries across Windows LOLBAS, Linux GTFOBins, and macOS LOOBins.

Cross-Platform Coverage
OS:
Tactic:
Privileges:
Showing 303 of 303 Living-off-the-Land binariesPage 1 of 13
Windows2 execution modes

certutil.exe

Certutil.exe is a command-line program installed as part of Certificate Services. Attackers frequently abuse it to download arbitrary files from remote URLs, encode/decode Base64 payloads to evade detection, and hash files.

C:\Windows\System32\certutil.exe
T1105T1140
Windows2 execution modes

mshta.exe

Microsoft HTML Application (MSHTA) host executes .hta files and scripts embedded inside web pages. Attackers abuse mshta to execute malicious inline VBScript or JScript directly from the command line or remote HTTP servers.

C:\Windows\System32\mshta.exe
T1218.005
Windows2 execution modes

rundll32.exe

The Rundll32 program loads and runs 32-bit and 64-bit Dynamic Link Libraries (DLLs). Threat actors use it to execute exported functions from arbitrary DLLs, run scriptlets, or execute code via MSHTML protocol handlers.

C:\Windows\System32\rundll32.exe
T1218.011
Windows1 execution modes

bitsadmin.exe

Background Intelligent Transfer Service (BITS) administrator tool manages asynchronous, throttled background transfers. Attackers use BITS to stage remote downloads that survive reboots and evade conventional network monitoring.

C:\Windows\System32\bitsadmin.exe
T1197T1105
Windows1 execution modes

regsvr32.exe

Regsvr32 registers and unregisters OLE controls, such as DLLs and ActiveX controls in the Windows Registry. When passed the /i switch pointing to an HTTP/HTTPS URL and scrobj.dll, regsvr32 downloads and executes remote COM scriptlets in memory (the classic Squiblydoo technique).

C:\Windows\System32\regsvr32.exe
T1218.010
Windows2 execution modes

powershell.exe

PowerShell is a powerful task automation framework and scripting engine. Widely abused by threat actors for in-memory execution (fileless malware), credential dumping, remote command execution, and AMSI bypasses.

C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
T1059.001T1105
Windows1 execution modes

wmic.exe

Windows Management Instrumentation Command-line (WMIC) provides a command-line interface for WMI. Abused for process execution, remote lateral movement, process creation, and running XSL stylesheets.

C:\Windows\System32\wbem\WMIC.exe
T1047
Windows1 execution modes

cscript.exe

CScript.exe is a command-line version of the Windows Script Host that facilitates running VBScript and JScript scripts. Frequently abused to run dropped scripts, execute obfuscated VBScript files, and perform defense evasion.

C:\Windows\System32\cscript.exe
T1059.005
Windows1 execution modes

AddinUtil.exe

.NET Tool used for updating cache files for Microsoft Office Add-Ins.

C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddinUtil.exe
T1218
Windows1 execution modes

AppInstaller.exe

Tool used for installation of AppX/MSIX applications on Windows 10

C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\AppInstaller.exe
T1105
Windows1 execution modes

Applaunch.exe

Microsoft .NET ClickOnce Launch Utility.

C:\Windows\Microsoft.NET\Framework\v2.0.50727\Applaunch.exe
T1127.002
Windows1 execution modes

Aspnet_Compiler.exe

ASP.NET Compilation Tool

c:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
T1127
Windows1 execution modes

At.exe

Schedule periodic tasks

C:\WINDOWS\System32\At.exe
T1053.002
Windows1 execution modes

Atbroker.exe

Helper binary for Assistive Technology (AT)

C:\Windows\System32\Atbroker.exe
T1218
Windows5 execution modes

Bash.exe

File used by Windows subsystem for Linux

C:\Windows\System32\bash.exe
T1202T1218
Windows2 execution modes

CertOC.exe

Used for installing certificates

c:\windows\system32\certoc.exe
T1218T1105
Windows2 execution modes

CertReq.exe

Used for requesting and managing certificates

C:\Windows\System32\certreq.exe
T1105
Windows1 execution modes

Change.exe

Remote Desktop Services MultiUser Change Utility

c:\windows\system32\change.exe
T1218
Windows2 execution modes

Cipher.exe

File Encryption Utility

c:\windows\system32\cipher.exe
T1485T1562
Windows4 execution modes

Cmd.exe

The command-line interpreter in Windows

C:\Windows\System32\cmd.exe
T1564.004T1059.003T1105T1048.003
Windows1 execution modes

Cmdkey.exe

creates, lists, and deletes stored user names and passwords or credentials.

C:\Windows\System32\cmdkey.exe
T1078
Windows1 execution modes

cmdl32.exe

Microsoft Connection Manager Auto-Download

C:\Windows\System32\cmdl32.exe
T1105
Windows3 execution modes

Cmstp.exe

Installs or removes a Connection Manager service profile.

C:\Windows\System32\cmstp.exe
T1218.003
Windows1 execution modes

Colorcpl.exe

Binary that handles color management

C:\Windows\System32\colorcpl.exe
T1036.005
Showing 124 of 303 binaries