.. /CL_LoadAssembly.ps1
Star

Execute (DLL)

PowerShell Diagnostic Script

Paths:

Resources:

Acknowledgements:

Detections:

Execute

  1. Proxy execute Managed DLL with PowerShell

    powershell.exe -ep bypass -command "set-location -path C:\Windows\diagnostics\system\Audio; import-module .\CL_LoadAssembly.ps1; LoadAssemblyFromPath ..\..\..\..\testing\fun.dll;[Program]::Fun()"
    Use case
    Execute proxied payload with Microsoft signed binary
    Privileges required
    User
    Operating systems
    Windows 10 21H1 (likely other versions as well), Windows 11
    ATT&CK® technique
    T1216
    Tags
    Execute: DLL
    This LOLBAS executes Dynamic-Link Libraries (DLLs).