.. /Regsvcs.exe
Star

Execute (DLL (.NET))
AWL bypass (DLL (.NET))

Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies

Paths:

Resources:

Acknowledgements:

Detections:

Execute

  1. Loads the target .NET DLL file and executes the RegisterClass function.

    regsvcs.exe {PATH:.dll}
    Use case
    Execute dll file and bypass Application whitelisting
    Privileges required
    User
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1218.009
    Tags
    Execute: DLL (.NET)

AWL bypass

  1. Loads the target .NET DLL file and executes the RegisterClass function.

    regsvcs.exe {PATH:.dll}
    Use case
    Execute dll file and bypass Application whitelisting
    Privileges required
    Local Admin
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1218.009
    Tags
    Execute: DLL (.NET)