Wfc.exe

The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).

Paths

  • C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\wfc.exe

Commands

AWL Bypass

Execute arbitrary C# code embedded in a XOML file.

Use case: Execute proxied payload with Microsoft signed binary to bypass WDAC policies

Privileges: User

wfc.exe {PATH_ABSOLUTE:.xoml}

Detection

Resources