Catalog LOLBAS

LOL · Binary

iediagcmd.exe

1 technique WindowsLOLBAS GPL-3.0

Execute

Execution Windows

Executes binary that is pre-planted at C:\test\system32\netsh.exe.

Use Spawn a pre-planted executable from iediagcmd.exe.

set windir=c:\test& cd "C:\Program Files\Internet Explorer\" & iediagcmd.exe /out:{PATH_ABSOLUTE:.cab}
Context
user
Native
Execute
MITRE
T1218
Detection
IOC: Sysmon Event ID 1
IOC: Execution of process iediagcmd.exe with /out could be suspicious