.. /Reset.exe
Star

Execute (EXE, Rename)

Remote Desktop Services Reset Utility

Paths:

Acknowledgements:

Detections:

Execute

  1. Once executed, reset.exe will execute rwinsta.exe in the same folder. Thus, if reset.exe is copied to a folder and an arbitrary executable is renamed to rwinsta.exe, reset.exe will spawn it.

    reset.exe session
    Use case

    Execute an arbitrary executable via trusted system executable.

    Privileges required
    User
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1218
    Tags
    Execute: EXE
    Requires: Rename