Forfiles Indirect Command Execution
Defense Evasion
PreviousUsing MSBuild to Execute Shellcode in C#NextApplication Whitelisting Bypass with WMIC and XSL
Last updated
Defense Evasion
Last updated
This technique launches an executable without a cmd.exe.
Defenders can monitor for process creation/commandline logs to detect this activity: