.. /Regasm.exe
Star

AWL bypass (DLL, Custom Format)
Execute (DLL, Custom Format)

Part of .NET


Paths:

Resources:
Acknowledgements:

Detection:

AWL bypass

  1. Loads the target .DLL file and executes the RegisterClass function.

    regasm.exe AllTheThingsx64.dll
    Use case
    Execute code and bypass Application whitelisting
    Privileges required
    Local Admin
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1218.009
    Tags
    Execute: DLL
    This LOLBAS executes Dynamic-Link Libraries (DLLs).
    Input: Custom Format
    This LOLBAS expects the input file to follow a set structure; check the description and linked resources for more details.

Execute

  1. Loads the target .DLL file and executes the UnRegisterClass function.

    regasm.exe /U AllTheThingsx64.dll
    Use case
    Execute code and bypass Application whitelisting
    Privileges required
    User
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1218.009
    Tags
    Execute: DLL
    This LOLBAS executes Dynamic-Link Libraries (DLLs).
    Input: Custom Format
    This LOLBAS expects the input file to follow a set structure; check the description and linked resources for more details.