How to Evade Application Whitelisting Using REGSVR32
ID: 05c3404f-3676-5400-8c2d-2bd41758d3c5
STIX ID: report--05c3404f-3676-5400-8c2d-2bd41758d3c5
Feed Name: Black Hills Infosec Blog
Threat Score
This report demonstrates a Windows application-whitelisting bypass technique that uses regsvr32.exe and a custom DLL exporting DllInstall() to download or read base64-encoded payloads (shellcode or PowerShell) and execute them, providing C# PoC code, example commands (msfvenom and regsvr32), and a link to the wevade repository.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
