.. /OfflineScannerShell.exe
Star

Execute (DLL)

Windows Defender Offline Shell


Paths:

Acknowledgements:

Detection:

Execute

  1. Execute mpclient.dll library in the current working directory

    OfflineScannerShell
    Use case
    Can be used to evade defensive countermeasures or to hide as a persistence mechanism
    Privileges required
    Administrator
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1218
    Tags
    Execute: DLL
    This LOLBAS executes Dynamic-Link Libraries (DLLs).