.. / Syssetup.dll
Star

Windows NT System Setup


Paths:


Resources:
https://twitter.com/pabraeken/status/994392481927258113
https://twitter.com/harr0ey/status/975350238184697857
https://twitter.com/bohops/status/975549525938135040
https://windows10dll.nirsoft.net/syssetup_dll.html

Acknowledgement:
Pierre-Alexandre Braeken (Execute) - @pabraeken
Matt harr0ey (Execute) - @harr0ey
Jimmy (Scriptlet) - @bohops


Detection:



AWL bypass

Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).
rundll32.exe syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 c:\test\shady.inf
Usecase:
Privileges required:User
OS:Windows
Mitre:T1085



Execute

Launch an executable file via the SetupInfObjectInstallAction function and .inf file section directive.
rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 c:\temp\something.inf
Usecase:
Privileges required:User
OS:Windows
Mitre:T1085