Ssh.exe is the OpenSSH compatible client can be used to connect to Windows 10 (build 1809 and later) and Windows Server 2019 devices.
Executes specified command on host machine. The prompt for password can be eliminated by adding the host’s public key in the user’s authorized_keys file. Adversaries can do the same for execution on remote machines.
ssh localhost "{CMD}"
Execute specified command, can be used for defense evasion.
Executes specified command from ssh.exe
ssh -o ProxyCommand="{CMD}" .
Performs execution of specified file, can be used as a defensive evasion.
Executes a DLL from an SMB share by abusing the PKCS11Provider option. The payload executes upon DLL load (DllMain) and requires exporting C_GetFunctionList to prevent premature termination by ssh.exe. Note that all backslashes should be escaped (i.e. every \ should be turned into \\).
ssh -o PKCS11Provider="\\\\127.0.0.1\\Temp\\example.dll" win@github.com
Performs indirect execution of a specified DLL from a remote share, can be used for defense evasion.