mttaggart / wtfbins

WTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
MIT License
148 stars 12 forks source link

[New WTFBin]: Fodhelper.exe #2

Closed dievus closed 2 years ago

dievus commented 2 years ago
mttaggart commented 2 years ago

Since this is a legit privesc vector that should be alerted on, we'll leave this off the WTFBins list. Although, a huge WTF for Windows allowing this to still work.

HuskyHacks commented 2 years ago

@dievus it looks like fodhelper is not on the LOLBAS project yet. https://lolbas-project.github.io/#fodhelper