.. / Runscripthelper.exe
Star


Paths:


Resources:
https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc

Acknowledgement:
Matt Graeber - @mattifestation


Detection:
Event 4014 - Powershell logging
Event 400



Execute

Execute the PowerShell script named test.txt
runscripthelper.exe surfacecheck \\?\C:\Test\Microsoft\Diagnosis\scripts\test.txt C:\Test
Usecase:Bypass constrained language mode and execute Powershell script
Privileges required:User
OS:Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1218