.. /Regsvcs.exe
Star

Execute (DLL (.NET))
AWL bypass (DLL (.NET))

Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies

Paths:

Resources:

Acknowledgements:

Detections:

Execute

  1. Loads the target .Net DLL file and executes the RegisterClass function.

    regsvcs.exe AllTheThingsx64.dll
    Use case
    Execute dll file and bypass Application whitelisting
    Privileges required
    User
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1218.009
    Tags
    Execute: DLL (.NET)

AWL bypass

  1. Loads the target .Net DLL file and executes the RegisterClass function.

    regsvcs.exe AllTheThingsx64.dll
    Use case
    Execute dll file and bypass Application whitelisting
    Privileges required
    Local Admin
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1218.009
    Tags
    Execute: DLL (.NET)