Query.exe

Remote Desktop Services MultiUser Query Utility

Paths

  • c:\windows\system32\query.exe
  • c:\windows\syswow64\query.exe

Commands

Execute

Once executed, `query.exe` will execute `quser.exe` in the same folder. Thus, if `query.exe` is copied to a folder and an arbitrary executable is renamed to `quser.exe`, `query.exe` will spawn it. Instead of `user`, it is also possible to use `session`, `termsession` or `process` as command-line option.

Use case: Execute an arbitrary executable via trusted system executable.

Privileges: User

query.exe user

Detection