.. /Fsi.exe
Star

AWL bypass

64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.


Paths:

Resources:
Acknowledgements:

Detection:

AWL bypass

  1. Execute F# code via script file

    fsi.exe c:\path\to\test.fsscript
    Use case
    Execute payload with Microsoft signed binary to bypass WDAC policies
    Privileges required
    User
    Operating systems
    Windows 10 2004 (likely previous and newer versions as well)
    ATT&CK® technique
    T1059
  2. Execute F# code via interactive command line

    fsi.exe
    Use case
    Execute payload with Microsoft signed binary to bypass WDAC policies
    Privileges required
    User
    Operating systems
    Windows 10 2004 (likely previous and newer versions as well)
    ATT&CK® technique
    T1059