.. / Explorer.exe
Star

Binary used for managing files and system components within Windows


Paths:


Resources:
https://twitter.com/CyberRaiju/status/1273597319322058752?s=20

Acknowledgement:
Jai Minton - @CyberRaiju


Detection:
Multiple instances of explorer.exe or explorer.exe using the /root command line can help to detect this.



Execute

Execute calc.exe with the parent process spawning from a new instance of explorer.exe
explorer.exe /root,"C:\Windows\System32\calc.exe"
Usecase:Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.
Privileges required:User
OS:Windows XP, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1218