.. /Regsvcs.exe
Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
Paths:
- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\RegSvcs.exe
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegSvcs.exe
- C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
Execute
-
Loads the target .NET DLL file and executes the RegisterClass function.
regsvcs.exe {PATH:.dll}
- Use case
- Execute dll file and bypass Application whitelisting
- Privileges required
- User
- Operating systems
- Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
- ATT&CK® technique
- T1218.009
- Tags
Execute: DLL (.NET)
AWL bypass
-
Loads the target .NET DLL file and executes the RegisterClass function.
regsvcs.exe {PATH:.dll}
- Use case
- Execute dll file and bypass Application whitelisting
- Privileges required
- Local Admin
- Operating systems
- Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
- ATT&CK® technique
- T1218.009
- Tags
Execute: DLL (.NET)