.. /Register-cimprovider.exe
Used to register new wmi providers
Paths:
- C:\Windows\System32\Register-cimprovider.exe
- C:\Windows\SysWOW64\Register-cimprovider.exe
Execute
-
Load the target .DLL.
Register-cimprovider -path "C:\folder\evil.dll"
- Use case
- Execute code within dll file
- Privileges required
- User
- Operating systems
- Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
- ATT&CK® technique
- T1218
- Tags
Execute: DLL