.. / CL_LoadAssembly.ps1
Star

PowerShell Diagnostic Script


Paths:

Resources:
Acknowledgements:

Execute

Proxy execute Managed DLL with PowerShell
ā€¯powershell.exe -command "set-location -path C:\Windows\diagnostics\system\Audio; import-module .\CL_LoadAssembly.ps1; LoadAssemblyFromPath ..\..\..\..\testing\fun.dll;[Program]::Fun()
Usecase: Execute proxied payload with Microsoft signed binary
Privileges required: User
OS: Windows 10 21H1 (likely other versions as well)
MITRE ATT&CK®: T1216