Environment
- EDR Server: All Supported
- EDR Sensor: All Supported
Question
Unintended binary file execution
Answer
- The Live Repsonse execfg and exec commands use the Microsoft CreateProcess API on the sensor
- If an absolute path is not provided to the binary a different binary of the same name may be executed
Additional Notes
For Example:
If the following command is executed in the Live Response session
c:\Windows\Carbonblack> execfg powershell.exe Get-Host
- If Powershell.exe does not existed by default in the c:\Windows\CarbonBlack directory
- The above command will cause Windows to use the search order behavior
- Powershell.exe will be executed and the results returned to the Live Response console session, but it may not be the version expected
Related Content