.. /Runscripthelper.exe
Star

Execute

Execute target PowerShell script


Paths:

Resources:
Acknowledgements:

Detection:

Execute

  1. Execute the PowerShell script named test.txt

    runscripthelper.exe surfacecheck \\?\C:\Test\Microsoft\Diagnosis\scripts\test.txt C:\Test
    Use case
    Bypass constrained language mode and execute Powershell script
    Privileges required
    User
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
    ATT&CK® technique
    T1218