Regsvr32
ID: T1117 Tactic: Defense Evasion, Execution
This technique uses a SCT file loaded remotely.
SCT: Script used to create a Component Object Model (.COM) component, may be written in various scripting languages such as VBScript, JavaScript, or JScript; runs itself in Windows if the Windows Scripting Host is installed.
A very basic SCT file that will execute calc.exe
:
I will host this on my Kali box using python3
Now let's call it from our Victim Box.
And execute
Demo:
Last updated