.. / Installutil.exe
Star

The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies


Paths:


Resources:
https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/
https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12
https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1118/T1118.md
https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/
https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/
https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool

Acknowledgement:
Casey Smith - @subtee


Detection:



AWL bypass

Execute the target .NET DLL or EXE.
InstallUtil.exe /logfile= /LogToConsole=false /U AllTheThings.dll
Usecase:Use to execute code and bypass application whitelisting
Privileges required:User
OS:Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1118



Execute

Execute the target .NET DLL or EXE.
InstallUtil.exe /logfile= /LogToConsole=false /U AllTheThings.dll
Usecase:Use to execute code and bypass application whitelisting
Privileges required:User
OS:Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1118