.. / Register-cimprovider.exe
Star

Used to register new wmi providers


Paths:


Resources:
https://twitter.com/PhilipTsukerman/status/992021361106268161

Acknowledgement:
Philip Tsukerman - @PhilipTsukerman


Detection:



Execute

Load the target .DLL.
Register-cimprovider -path "C:\folder\evil.dll"
Usecase:Execute code within dll file
Privileges required:User
OS:Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1218