[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxnrnjCzeTzfDXTb1nfNlt0PpYe1_gRgks55ugPKIDi0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},523,"What is the purpose of using odbcconf.exe with a response file to load a DLL that executes PowerShell commands?","NickTyrer extended odbcconf's DLL loading capability to execute PowerShell commands within the loaded DLL, using UnmanagedExports and System.Management.Automation. This allows stealthy code execution without triggering command-line detection of `regsvr` strings. For compilation instructions and details, refer to [Study Notes Weekly No.3](\u002Fnews\u002Fstudy-notes-weekly-no-3-use-odbcconf-to-load-dll-get-exports-etw-usb-keylogger). This technique fits into the broader family of application whitelisting bypasses, such as [using tracker.exe to load DLLs](\u002Fnews\u002Fstudy-notes-weekly-no-4-use-tracker-to-load-dll-use-csi-to-bypass-umci-execute-c-from-xslt-file).","\u003Cp>NickTyrer extended odbcconf&#39;s DLL loading capability to execute PowerShell commands within the loaded DLL, using UnmanagedExports and System.Management.Automation. This allows stealthy code execution without triggering command-line detection of `regsvr` strings. For compilation instructions and details, refer to [Study Notes Weekly No.3](\u002Fnews\u002Fstudy-notes-weekly-no-3-use-odbcconf-to-load-dll-get-exports-etw-usb-keylogger). This technique fits into the broader family of application whitelisting bypasses, such as [using tracker.exe to load DLLs](\u002Fnews\u002Fstudy-notes-weekly-no-4-use-tracker-to-load-dll-use-csi-to-bypass-umci-execute-c-from-xslt-file).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fstudy-notes-weekly-no-3-use-odbcconf-to-load-dll-get-exports-etw-usb-keylogger\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-purpose-of-using-odbcconfexe-with-a-response-file-to-load-a-dll-that-1777483315686","odbcconf, PowerShell, DLL, command execution, bypass, UnmanagedExports",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},129,"Study Notes Weekly No.3(Use odbcconf to load dll & Get-Exports & ETW USB Keylogger)","study-notes-weekly-no-3-use-odbcconf-to-load-dll-get-exports-etw-usb-keylogger","Learn to bypass regsvr32 interception using odbcconf, export DLL functions with PowerShell Get-Exports, and implement USB keyboard keystroke logging via ETW.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>About:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Use odbcconf to load dll\u003C\u002Fli>\u003Cli>Use powershell to get dll exports\u003C\u002Fli>\u003Cli>Use Event Tracing for Windows to log keystrokes from USB keyboards\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Contents:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to bypassing regsvr32 command-line interception via odbcconf dll loading\u003C\u002Fli>\u003Cli>ExportsToC++ - A more convenient tool than ExportsToC++ for batch exporting dll functions\u003C\u002Fli>\u003Cli>Implementing USB keyboard keystroke logging via ETW, with testing insights\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Use odbcconf to load dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F789459826367606784\u003C\u002Fp>\u003Ch3>Introduction\u003C\u002Fh3>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017971916_0_5f5ff5815b.jpeg\">\u003C\u002Fp>\u003Cp>As shown in the figure, a technique shared by Casey Smith on Twitter: if the code for executing regsvr32 to load a DLL is written in an .rsp file and then invoked via odbcconf.exe, it can bypass the interception of regsvr32 in the command line. This article will explain why this method can bypass the interception of regsvr32 in the command line.\u003C\u002Fp>\u003Cp>\u003Cstrong>odbcconf:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Used to configure ODBC drivers and data sources\u003C\u002Fp>\u003Cp>For detailed instructions, see the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fee388579(v=vs.85).aspx\u003C\u002Fp>\u003Cp>Usage as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017982893_1_2de15cc17e.jpeg\">\u003C\u002Fp>\u003Cp>It is worth noting that odbcconf includes a function to register DLLs. I have previously introduced in the article 'Code Execution of Regsvr32.exe' how to develop a DLL that can be called by regsvr32. A test DLL was written for testing (details omitted here, not repeated).\u003C\u002Fp>\u003Cp>Run in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>odbcconf.exe \u002Fa {regsvr c:\\test\\odbcconf.dll}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure, the DLL is successfully called, and a dialog box pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017987725_2_802d113684.jpeg\">\u003C\u002Fp>\u003Cp>From a defender's perspective, to prevent the abuse of using regsvr32 to call DLLs, monitoring command line inputs (e.g., creating rules via EMET) is often chosen. If the command line includes the string 'regsvr', it will be intercepted.\u003C\u002Fp>\u003Cp>Of course, the above operation contains the string 'regsvr' and will be intercepted.\u003C\u002Fp>\u003Cp>Using Process Explorer to view the command line of the odbcconf process, it contains the string 'regsvr'\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017992639_3_1a1663d433.jpeg\">\u003C\u002Fp>\u003Cp>However, another feature of odbcconf can be used to bypass this, which is the \u002FF parameter\u003C\u002Fp>\u003Cp>\u003Cstrong>Usage:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>odbcconf.exe \u002Ff my.rsp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>my.rsp is the response file, which contains the operation to be executed:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REGSVR c:\\test\\odbcconf.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The absolute path of the DLL must be provided here\u003C\u002Fp>\u003Cp>As shown in the figure, the DLL is successfully called and a dialog box pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017996395_4_e425276b41.jpeg\">\u003C\u002Fp>\u003Cp>Using Process Explorer to view the command line again shows no regsvr characters\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017999395_5_6777b6bfb3.jpeg\">\u003C\u002Fp>\u003Cp>NickTyrer shared his code based on this method, achieving the execution of PowerShell commands within the DLL. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FNickTyrer\u002F6ef02ce3fd623483137b45f65017352b\u003C\u002Fp>\u003Cp>Before compiling the project, the following settings are required:\u003C\u002Fp>\u003Cul>\u003Cli>Set the compilation platform to x86 or x64\u003C\u002Fli>\u003Cli>Install UnmanagedExports and System.Management.Automation\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In the Visual Studio control panel, select TOOLS-Library Package Manager-Package Manager Console, and enter:\u003C\u002Fp>\u003Cp>Install-Package UnmanagedExports\u003C\u002Fp>\u003Cp>Install-Package System.Management.Automation\u003C\u002Fp>\u003Ch2>0x02 Use powershell to get dll exports\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1\u003C\u002Fp>\u003Ch3>Introduction\u003C\u002Fh3>\u003Cp>In \"Study-Notes-Weekly-No.1(Monitor-WMI-ExportsToC++-Use-DiskCleanup-bypass-UAC)\", a tool for batch exporting DLL functions was introduced—ExportsToC++. Its operation requires .NET Framework 2.0 and the installation of Microsoft Visual Studio.\u003C\u002Fp>\u003Cp>b33f@FuzzySecurity has improved upon this and open-sourced Get-Exports for PowerShell. Its features include no longer requiring the Microsoft Visual Studio development environment, being more convenient and faster, and supporting both 32-bit and 64-bit DLLs.\u003C\u002Fp>\u003Cp>The test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Exports -DllPath c:\\Windows\\system32\\dimsjob.dll -ExportsToCpp C:\\test\\export.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, as shown in the figure, it displays the exported function information\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018003525_6_8a1b8dd32b.jpeg\">\u003C\u002Fp>\u003Cp>Simultaneously generates usable C++ code and saves it under C:\\test\\export.txt, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018008415_7_ebc257e982.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Use Event Tracing for Windows to log keystrokes from USB keyboards\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.cyberpointllc.com\u002Fsrt\u002Fposts\u002Fsrt-logging-keystrokes-with-event-tracing-for-windows-etw.html\u003C\u002Fp>\u003Ch3>Introduction\u003C\u002Fh3>\u003Cp>CyberPoint SRT introduced their novel application of ETW at Ruxcon, achieving keystroke logging from USB keyboards and releasing a test POC. This article will test it and analyze the testing insights.\u003C\u002Fp>\u003Cp>\u003Cstrong>ETW:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Abbreviation for Event Tracing for Windows\u003C\u002Fli>\u003Cli>Provides a mechanism for tracing and recording event objects created by user-mode applications and kernel-mode drivers\u003C\u002Fli>\u003Cli>Typically used to assist administrators and developers in troubleshooting and measuring system and application performance\u003C\u002Fli>\u003Cli>Public information shows there is currently no known method to implement keylogging using ETW\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Some learning materials about ETW:\u003C\u002Fp>\u003Cp>https:\u002F\u002Frandomascii.wordpress.com\u002F2015\u002F09\u002F24\u002Fetw-central\u002F\u003C\u002Fp>\u003Cp>POC download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCyberPoint\u002FRuxcon2016ETW\u002Ftree\u002Fmaster\u002FKeyloggerPOC\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This POC has been detected by antivirus software, testing requires whitelisting\u003C\u002Fp>\u003Cp>Requirements:\u003C\u002Fp>\u003Cul>\u003Cli>Windows 7 (USB 2.0)\u003C\u002Fli>\u003Cli>Windows 8+ (USB 2.0 and USB 3.0)\u003C\u002Fli>\u003Cli>Run with administrator privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Does not support PS\u002F2 interface keyboards\u003C\u002Fp>\u003Cp>Test environment:\u003C\u002Fp>\u003Cul>\u003Cli>Win8.1 x86\u003C\u002Fli>\u003Cli>vs2013\u003C\u002Fli>\u003Cli>Install .NET Framework 4.5.2\u003C\u002Fli>\u003Cli>Install-Package Microsoft.Diagnostics.Tracing.TraceEvent\u003C\u002Fli>\u003Cli>USB 2.0 keyboard\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Run exe with administrator privileges, record test as shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018011347_8_7d4860f446.jpeg\">\u003C\u002Fp>\u003Cp>The biggest shortcoming of the POC:\u003C\u002Fp>\u003Cul>\u003Cli>Recording has latency\u003C\u002Fli>\u003Cli>Unstable, often reports error [!] ignoring non-usb keyboard device: 0xFFFFFFFF8CFF6070\u003C\u002Fli>\u003C\u002Ful>\u003Cp>There is still a long way from POC to tool, but this approach is worth learning, the ETW utilization method is worth summarizing, looking forward to CyberPoint SRT's follow-up articles\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>About:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Use odbcconf to load dll\u003C\u002Fli>\u003Cli>Use powershell to get dll exports\u003C\u002Fli>\u003Cli>Use Event Tracing for Windows to log keystrokes from USB keyboards\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Contents:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to bypassing regsvr32 command-line interception via odbcconf dll loading\u003C\u002Fli>\u003Cli>ExportsToC++ - A more convenient tool than ExportsToC++ for batch exporting dll functions\u003C\u002Fli>\u003Cli>Implementing USB keyboard keystroke logging via ETW, with testing insights\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Use odbcconf to load dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F789459826367606784\u003C\u002Fp>\u003Ch3>Introduction\u003C\u002Fh3>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017971916_0_5f5ff5815b-1.jpeg\">\u003C\u002Fp>\u003Cp>As shown in the figure, a technique shared by Casey Smith on Twitter: if the code for executing regsvr32 to load a DLL is written in an .rsp file and then invoked via odbcconf.exe, it can bypass the interception of regsvr32 in the command line. This article will explain why this method can bypass the interception of regsvr32 in the command line.\u003C\u002Fp>\u003Cp>\u003Cstrong>odbcconf:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Used to configure ODBC drivers and data sources\u003C\u002Fp>\u003Cp>For detailed instructions, see the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fee388579(v=vs.85).aspx\u003C\u002Fp>\u003Cp>Usage as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017982893_1_2de15cc17e-1.jpeg\">\u003C\u002Fp>\u003Cp>It is worth noting that odbcconf includes a function to register DLLs. I have previously introduced in the article 'Code Execution of Regsvr32.exe' how to develop a DLL that can be called by regsvr32. A test DLL was written for testing (details omitted here, not repeated).\u003C\u002Fp>\u003Cp>Run in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>odbcconf.exe \u002Fa {regsvr c:\\test\\odbcconf.dll}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure, the DLL is successfully called, and a dialog box pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017987725_2_802d113684-1.jpeg\">\u003C\u002Fp>\u003Cp>From a defender's perspective, to prevent the abuse of using regsvr32 to call DLLs, monitoring command line inputs (e.g., creating rules via EMET) is often chosen. If the command line includes the string 'regsvr', it will be intercepted.\u003C\u002Fp>\u003Cp>Of course, the above operation contains the string 'regsvr' and will be intercepted.\u003C\u002Fp>\u003Cp>Using Process Explorer to view the command line of the odbcconf process, it contains the string 'regsvr'\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017992639_3_1a1663d433-1.jpeg\">\u003C\u002Fp>\u003Cp>However, another feature of odbcconf can be used to bypass this, which is the \u002FF parameter\u003C\u002Fp>\u003Cp>\u003Cstrong>Usage:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>odbcconf.exe \u002Ff my.rsp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>my.rsp is the response file, which contains the operation to be executed:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REGSVR c:\\test\\odbcconf.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The absolute path of the DLL must be provided here\u003C\u002Fp>\u003Cp>As shown in the figure, the DLL is successfully called and a dialog box pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017996395_4_e425276b41-1.jpeg\">\u003C\u002Fp>\u003Cp>Using Process Explorer to view the command line again shows no regsvr characters\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017999395_5_6777b6bfb3-1.jpeg\">\u003C\u002Fp>\u003Cp>NickTyrer shared his code based on this method, achieving the execution of PowerShell commands within the DLL. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FNickTyrer\u002F6ef02ce3fd623483137b45f65017352b\u003C\u002Fp>\u003Cp>Before compiling the project, the following settings are required:\u003C\u002Fp>\u003Cul>\u003Cli>Set the compilation platform to x86 or x64\u003C\u002Fli>\u003Cli>Install UnmanagedExports and System.Management.Automation\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In the Visual Studio control panel, select TOOLS-Library Package Manager-Package Manager Console, and enter:\u003C\u002Fp>\u003Cp>Install-Package UnmanagedExports\u003C\u002Fp>\u003Cp>Install-Package System.Management.Automation\u003C\u002Fp>\u003Ch2>0x02 Use powershell to get dll exports\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1\u003C\u002Fp>\u003Ch3>Introduction\u003C\u002Fh3>\u003Cp>In \"Study-Notes-Weekly-No.1(Monitor-WMI-ExportsToC++-Use-DiskCleanup-bypass-UAC)\", a tool for batch exporting DLL functions was introduced—ExportsToC++. Its operation requires .NET Framework 2.0 and the installation of Microsoft Visual Studio.\u003C\u002Fp>\u003Cp>b33f@FuzzySecurity has improved upon this and open-sourced Get-Exports for PowerShell. Its features include no longer requiring the Microsoft Visual Studio development environment, being more convenient and faster, and supporting both 32-bit and 64-bit DLLs.\u003C\u002Fp>\u003Cp>The test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Exports -DllPath c:\\Windows\\system32\\dimsjob.dll -ExportsToCpp C:\\test\\export.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, as shown in the figure, it displays the exported function information\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018003525_6_8a1b8dd32b-1.jpeg\">\u003C\u002Fp>\u003Cp>Simultaneously generates usable C++ code and saves it under C:\\test\\export.txt, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018008415_7_ebc257e982-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Use Event Tracing for Windows to log keystrokes from USB keyboards\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.cyberpointllc.com\u002Fsrt\u002Fposts\u002Fsrt-logging-keystrokes-with-event-tracing-for-windows-etw.html\u003C\u002Fp>\u003Ch3>Introduction\u003C\u002Fh3>\u003Cp>CyberPoint SRT introduced their novel application of ETW at Ruxcon, achieving keystroke logging from USB keyboards and releasing a test POC. This article will test it and analyze the testing insights.\u003C\u002Fp>\u003Cp>\u003Cstrong>ETW:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Abbreviation for Event Tracing for Windows\u003C\u002Fli>\u003Cli>Provides a mechanism for tracing and recording event objects created by user-mode applications and kernel-mode drivers\u003C\u002Fli>\u003Cli>Typically used to assist administrators and developers in troubleshooting and measuring system and application performance\u003C\u002Fli>\u003Cli>Public information shows there is currently no known method to implement keylogging using ETW\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Some learning materials about ETW:\u003C\u002Fp>\u003Cp>https:\u002F\u002Frandomascii.wordpress.com\u002F2015\u002F09\u002F24\u002Fetw-central\u002F\u003C\u002Fp>\u003Cp>POC download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCyberPoint\u002FRuxcon2016ETW\u002Ftree\u002Fmaster\u002FKeyloggerPOC\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This POC has been detected by antivirus software, testing requires whitelisting\u003C\u002Fp>\u003Cp>Requirements:\u003C\u002Fp>\u003Cul>\u003Cli>Windows 7 (USB 2.0)\u003C\u002Fli>\u003Cli>Windows 8+ (USB 2.0 and USB 3.0)\u003C\u002Fli>\u003Cli>Run with administrator privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Does not support PS\u002F2 interface keyboards\u003C\u002Fp>\u003Cp>Test environment:\u003C\u002Fp>\u003Cul>\u003Cli>Win8.1 x86\u003C\u002Fli>\u003Cli>vs2013\u003C\u002Fli>\u003Cli>Install .NET Framework 4.5.2\u003C\u002Fli>\u003Cli>Install-Package Microsoft.Diagnostics.Tracing.TraceEvent\u003C\u002Fli>\u003Cli>USB 2.0 keyboard\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Run exe with administrator privileges, record test as shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018011347_8_7d4860f446-1.jpeg\">\u003C\u002Fp>\u003Cp>The biggest shortcoming of the POC:\u003C\u002Fp>\u003Cul>\u003Cli>Recording has latency\u003C\u002Fli>\u003Cli>Unstable, often reports error [!] ignoring non-usb keyboard device: 0xFFFFFFFF8CFF6070\u003C\u002Fli>\u003C\u002Ful>\u003Cp>There is still a long way from POC to tool, but this approach is worth learning, the ETW utilization method is worth summarizing, looking forward to CyberPoint SRT's follow-up articles\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1050,"Onedaysec",4,"published","2026-02-02T07:51:00.064Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass Regsvr32 with ODBCCONF, PowerShell DLL Exports, ETW USB Keylogger","odbcconf dll loading, bypass regsvr32, PowerShell Get-Exports, ETW USB keylogger, DLL exports, Windows security, keystroke logging, red team techniques",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],524,522,521,520,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.898Z","2026-07-23T16:01:41.252Z","draft","2026-07-23T16:12:59.835Z"]