Skip to content

Latest commit

 

History

History
28 lines (16 loc) · 555 Bytes

t1202-forfiles-indirect-command-execution.md

File metadata and controls

28 lines (16 loc) · 555 Bytes
description
Defense Evasion

Forfiles Indirect Command Execution

This technique launches an executable without a cmd.exe.

Execution

forfiles /p c:\windows\system32 /m notepad.exe /c calc.exe

Observations

Defenders can monitor for process creation/commandline logs to detect this activity:

References

{% embed url="https://attack.mitre.org/wiki/Technique/T1202" %}