Meta tags:
description= Runscripthelper.exe is a living-of-the-land file containing unexpected functionality that can be abused by attackers; this page lists all its use cases.;
Headings (most frequently used words):
runscripthelper, exe, star, execute, paths, resources, acknowledgements, detections,
Text of the page (most frequently used words):
windows (14), powershell (7), execute (6), runscripthelper (6), exe (5), #script (3), microsoft (3), https (3), path_absolute (2), txt (2), with (2), ioc (2), event (2), com (2), application (2), rules (2), sigma (2), winsxs (2), amd64_microsoft (2), telemetry (2), client_31bf3856ad364e35_10 (2), 16299 (2), tags, t1218, att, technique, vista, operating, systems, user, privileges, required, bypass, constrained, language, mode, and, use, case, surfacecheck, folder, the, extension, 400, 4104, operational, blockrule, docs, security, threat, protection, defender, control, recommended, block, github, sigmahq, blob, c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba, process_creation, proc_creation_win_lolbin_runscripthelper, yml, detections, matt, graeber, mattifestation, acknowledgements, posts, specterops, bypassing, whitelisting, 1906923658fc, resources, 192_none_ad4699b571e00c4a, 15_none_c2df1bba78111118, paths, target, star, lolbas,
Text of the page (random words):
runscripthelper lolbas runscripthelper exe star execute powershell execute target powershell script paths c windows winsxs amd64_microsoft windows u ed telemetry client_31bf3856ad364e35_10 0 16299 15_none_c2df1bba78111118 runscripthelper exe c windows winsxs amd64_microsoft windows u ed telemetry client_31bf3856ad364e35_10 0 16299 192_none_ad4699b571e00c4a runscripthelper exe resources https posts specterops io bypassing application whitelisting with runscripthelper exe 1906923658fc acknowledgements matt graeber mattifestation detections sigma https github com sigmahq sigma blob c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba rules windows process_creation proc_creation_win_lolbin_runscripthelper yml blockrule https docs microsoft com en us windows security threat protection windows defender application control microsoft recommended block rules ioc event id 4104 microsoft windows powershell operational ioc event id 400 windows powershell execute execute the powershell script with txt extension runscripthelper exe surfacecheck path_absolute txt path_absolute folder use case bypass constrained language mode and execute powershell script privileges required user operating systems windows vista windows 7 windows 8 windows 8 1 windows 10 att ck technique t1218 tags execute powershell
|