logo

How to Evade Application Whitelisting Using REGSVR32

ID: 05c3404f-3676-5400-8c2d-2bd41758d3c5

STIX ID: report--05c3404f-3676-5400-8c2d-2bd41758d3c5

Feed Name: Black Hills Infosec Blog

Threat Score
60/100

Date Published: 2017-05-10

Date Updated: 2026-04-27

Author: BHIS

...
...

This report demonstrates a Windows application-whitelisting bypass technique that uses regsvr32.exe and a custom DLL exporting DllInstall() to download or read base64-encoded payloads (shellcode or PowerShell) and execute them, providing C# PoC code, example commands (msfvenom and regsvr32), and a link to the wevade repository.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.