.. /write.exe
Star

Execute (EXE, Registry Change)

Windows Write

Paths:

Resources:

Acknowledgements:

Detections:

Execute

  1. Executes a binary provided in default value of HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths\wordpad.exe.

    write.exe
    Use case

    Execute binary through legitimate proxy. This might be utilized to confuse detection solutions that rely on parent-child relationships.

    Privileges required
    User
    Operating systems
    Windows 10, Windows 11 (before 24H2)
    ATT&CK® technique
    T1218
    Tags
    Execute: EXE
    Requires: Registry Change