[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f659f1WnwCi98pwc5QlTI_7w8dkghsfrWAy06DCdHrAs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":38,"aiConfidence":38,"updatedAt":57,"createdAt":57,"_status":56},1274,"Does the Logon Scripts technique allow execution before antivirus software starts?","Yes, the article demonstrates that Logon Scripts execute before certain antivirus software like 360, allowing malicious scripts to perform restricted operations (e.g., creating environment variables via WMI) without being blocked. This was tested by writing a value to the registry within the logon script and confirming it succeeded. For details, check the [Logon Scripts persistence article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).","\u003Cp>Yes, the article demonstrates that Logon Scripts execute before certain antivirus software like 360, allowing malicious scripts to perform restricted operations (e.g., creating environment variables via WMI) without being blocked. This was tested by writing a value to the registry within the logon script and confirming it succeeded. For details, check the [Logon Scripts persistence article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","does-the-logon-scripts-technique-allow-execution-before-antivirus-software-start-1777479956767","Logon Scripts, antivirus bypass, execution order, 360",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":20,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":40,"qaPairs":41,"meta":53,"updatedAt":54,"createdAt":55,"_status":56},298,"Use Logon Scripts to maintain persistence","use-logon-scripts-to-maintain-persistence","Learn how Logon Scripts execute before antivirus, enabling persistence and bypassing security. Includes WMI bypass and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article continues the series on backdoor exploitation methods, focusing on the use of Logon Scripts. During my research, I discovered a particular technique where scripts execute before antivirus software, allowing them to bypass antivirus interception of sensitive operations. This article will detail this technique.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some antivirus software can start before Logon Scripts.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Usage of Logon Scripts\u003C\u002Fli>\u003Cli>Bypassing 360's interception of WMI calls\u003C\u002Fli>\u003Cli>Special Techniques\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of Logon Scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The idea originates from Adam@Hexacorn, with the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2014\u002F11\u002F14\u002Fbeyond-good-ol-run-key-part-18\u002F\u003C\u002Fp>\u003Ch3>Brief introduction to the usage of Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCU\\Environment\\\u003C\u002Fp>\u003Cp>Create string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set key value to absolute path of bat: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016714386_0_81861fd612.jpeg\">\u003C\u002Fp>\u003Cp>The content of the bat is as follows:\u003C\u002Fp>\u003Cp>start calc.exe\u003C\u002Fp>\u003Cp>Log off, log on\u003C\u002Fp>\u003Cp>Execute script 11.bat, calculator pops up\u003C\u002Fp>\u003Ch2>0x03 Bypass 360's interception of modifying environment variables via WMI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article 'Use CLR to maintain persistence', the method of using wmic to modify environment variables\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, 360 will intercept WMI operations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016717261_1_b0cdc42c34.jpeg\">\u003C\u002Fp>\u003Cp>In fact, adding environment variables via WMI is equivalent to creating key-values in the registry HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Therefore, WMI operations can be replaced by writing to the registry\u003C\u002Fp>\u003Cp>The above WMI command can be replaced with the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Special Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Originating from a unique idea of mine\u003C\u002Fp>\u003Cp>During my research on this technique, I had an interesting thought: Do Logon Scripts start before other programs?\u003C\u002Fp>\u003Cp>If so, do they also start before antivirus software?\u003C\u002Fp>\u003Cp>Now, let's begin my test:\u003C\u002Fp>\u003Ch3>1. Enter the following code in cmd:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As expected, it was blocked\u003C\u002Fp>\u003Ch3>2. Setting Logon Scripts\u003C\u002Fh3>\u003Cp>The code for 11.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003Cbr>reg query HKEY_CURRENT_USER\\Environment \u002FV test\u003Cbr>pause\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enabling Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Create a string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set the key value to the absolute path of the bat file: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>Since calling WMI will be blocked, it can be implemented via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" UserInitMprLogonScript -value \"c:\\test\\11.bat\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log off, log back in, and test\u003C\u002Fh3>\u003Cp>If the registry HKCR\\Environment\\ is successfully written with the key value test REG_SZ I run faster!, it indicates that Logon Scripts execute before antivirus software, bypassing its restrictions\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016723345_2_d09ecdd162.png\">\u003C\u002Fp>\u003Cp>Test successful, verifying our conclusion\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor registry key HKCR\\Environment\\UserInitMprLogonScript\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the usage of Logon Scripts and introduces a special application: Logon Scripts can execute before antivirus software, bypassing its interception of sensitive operations.\u003C\u002Fp>\u003Cp>From a defensive perspective, vigilance should be maintained against this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article continues the series on backdoor exploitation methods, focusing on the use of Logon Scripts. During my research, I discovered a particular technique where scripts execute before antivirus software, allowing them to bypass antivirus interception of sensitive operations. This article will detail this technique.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some antivirus software can start before Logon Scripts.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Usage of Logon Scripts\u003C\u002Fli>\u003Cli>Bypassing 360's interception of WMI calls\u003C\u002Fli>\u003Cli>Special Techniques\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of Logon Scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The idea originates from Adam@Hexacorn, with the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2014\u002F11\u002F14\u002Fbeyond-good-ol-run-key-part-18\u002F\u003C\u002Fp>\u003Ch3>Brief introduction to the usage of Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCU\\Environment\\\u003C\u002Fp>\u003Cp>Create string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set key value to absolute path of bat: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016714386_0_81861fd612-1.jpeg\">\u003C\u002Fp>\u003Cp>The content of the bat is as follows:\u003C\u002Fp>\u003Cp>start calc.exe\u003C\u002Fp>\u003Cp>Log off, log on\u003C\u002Fp>\u003Cp>Execute script 11.bat, calculator pops up\u003C\u002Fp>\u003Ch2>0x03 Bypass 360's interception of modifying environment variables via WMI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article 'Use CLR to maintain persistence', the method of using wmic to modify environment variables\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, 360 will intercept WMI operations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016717261_1_b0cdc42c34-1.jpeg\">\u003C\u002Fp>\u003Cp>In fact, adding environment variables via WMI is equivalent to creating key-values in the registry HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Therefore, WMI operations can be replaced by writing to the registry\u003C\u002Fp>\u003Cp>The above WMI command can be replaced with the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Special Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Originating from a unique idea of mine\u003C\u002Fp>\u003Cp>During my research on this technique, I had an interesting thought: Do Logon Scripts start before other programs?\u003C\u002Fp>\u003Cp>If so, do they also start before antivirus software?\u003C\u002Fp>\u003Cp>Now, let's begin my test:\u003C\u002Fp>\u003Ch3>1. Enter the following code in cmd:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As expected, it was blocked\u003C\u002Fp>\u003Ch3>2. Setting Logon Scripts\u003C\u002Fh3>\u003Cp>The code for 11.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003Cbr>reg query HKEY_CURRENT_USER\\Environment \u002FV test\u003Cbr>pause\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enabling Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Create a string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set the key value to the absolute path of the bat file: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>Since calling WMI will be blocked, it can be implemented via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" UserInitMprLogonScript -value \"c:\\test\\11.bat\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log off, log back in, and test\u003C\u002Fh3>\u003Cp>If the registry HKCR\\Environment\\ is successfully written with the key value test REG_SZ I run faster!, it indicates that Logon Scripts execute before antivirus software, bypassing its restrictions\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016723345_2_d09ecdd162-1.png\">\u003C\u002Fp>\u003Cp>Test successful, verifying our conclusion\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor registry key HKCR\\Environment\\UserInitMprLogonScript\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the usage of Logon Scripts and introduces a special application: Logon Scripts can execute before antivirus software, bypassing its interception of sensitive operations.\u003C\u002Fp>\u003Cp>From a defensive perspective, vigilance should be maintained against this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","Onedaysec",3,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":38,"canonicalUrl":38,"noIndex":39},"Logon Scripts Persistence: Bypass Antivirus with Pre-Execution","logon scripts, persistence, bypass antivirus, WMI interception, registry exploit, backdoor techniques, security evasion",null,false,[],{"docs":42,"hasNextPage":52},[43,4,44,45,46,47,48,49,50,51],1275,1273,1272,1271,1270,1269,1268,1267,1266,true,{"title":38,"description":38,"image":38},"2026-07-24T15:37:08.719Z","2026-07-23T16:02:42.266Z","draft","2026-07-23T16:17:48.716Z"]