.. /Regasm.exe
Star

AWL bypass (DLL (.NET))
Execute (DLL (.NET))

Part of .NET

Paths:

Resources:

Acknowledgements:

Detections:

AWL bypass

  1. Loads the target .NET DLL file and executes the RegisterClass function.

    regasm.exe {PATH:.dll}
    Use case
    Execute code and bypass Application whitelisting
    Privileges required
    Local Admin
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1218.009
    Tags
    Execute: DLL (.NET)

Execute

  1. Loads the target .DLL file and executes the UnRegisterClass function.

    regasm.exe /U {PATH:.dll}
    Use case
    Execute code and bypass Application whitelisting
    Privileges required
    User
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1218.009
    Tags
    Execute: DLL (.NET)