Filter:
Showing 230 binaries

code.exe

πŸͺŸ

VSCode binary, also portable (CLI) version

⚑ Execute
MITRE: T1219.001

GfxDownloadWrapper.exe

πŸͺŸ

Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.

πŸ“₯ Download
MITRE: T1105

Powershell.exe

πŸͺŸ

Powershell.exe is a a task-based command-line shell built on .NET.

⚑ Execute
MITRE: T1059.001

AddinUtil.exe

πŸͺŸ

.NET Tool used for updating cache files for Microsoft Office Add-Ins.

⚑ Execute
MITRE: T1218

AppInstaller.exe

πŸͺŸ

Tool used for installation of AppX/MSIX applications on Windows 10

πŸ“₯ Download
MITRE: T1105

Aspnet_Compiler.exe

πŸͺŸ

ASP.NET Compilation Tool

🚫 AWL
MITRE: T1127

At.exe

πŸͺŸ

Schedule periodic tasks

⚑ Execute
MITRE: T1053.002

Atbroker.exe

πŸͺŸ

Helper binary for Assistive Technology (AT)

⚑ Execute
MITRE: T1218

Bash.exe

πŸͺŸ

File used by Windows subsystem for Linux

⚑ Execute🚫 AWL
MITRE: T1202

Bitsadmin.exe

πŸͺŸ

Used for managing background intelligent transfer

⚑ ExecuteπŸ“₯ DownloadπŸ“‹ Copy
MITRE: T1564.004

CertOC.exe

πŸͺŸ

Used for installing certificates

⚑ ExecuteπŸ“₯ Download
MITRE: T1218

CertReq.exe

πŸͺŸ

Used for requesting and managing certificates

πŸ“₯ Downloadupload
MITRE: T1105

Certutil.exe

πŸͺŸ

Windows binary used for handling certificates

πŸ“₯ Download⚑ ExecuteπŸ” Encodedecode
MITRE: T1105

Change.exe

πŸͺŸ

Remote Desktop Services MultiUser Change Utility

⚑ Execute
MITRE: T1218

Cipher.exe

πŸͺŸ

File Encryption Utility

tamper
MITRE: T1485

Cmd.exe

πŸͺŸ

The command-line interpreter in Windows

⚑ ExecuteπŸ“₯ Downloadupload
MITRE: T1564.004

Cmdkey.exe

πŸͺŸ

creates, lists, and deletes stored user names and passwords or credentials.

credentials
MITRE: T1078

cmdl32.exe

πŸͺŸ

Microsoft Connection Manager Auto-Download

πŸ“₯ Download
MITRE: T1105

Cmstp.exe

πŸͺŸ

Installs or removes a Connection Manager service profile.

⚑ Execute🚫 AWL
MITRE: T1218.003

Colorcpl.exe

πŸͺŸ

Binary that handles color management

πŸ“‹ Copy
MITRE: T1036.005

ComputerDefaults.exe

πŸͺŸ

ComputerDefaults.exe is a Windows system utility for managing default applications for tasks like web browsing, emailing, and media playback.

πŸ›‘οΈ UAC
MITRE: T1548.002

ConfigSecurityPolicy.exe

πŸͺŸ

Binary part of Windows Defender. Used to manage settings in Windows Defender. You can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.

uploadπŸ“₯ Download
MITRE: T1567

Conhost.exe

πŸͺŸ

Console Window host

⚑ Execute
MITRE: T1202

Control.exe

πŸͺŸ

Binary used to launch controlpanel items in Windows

⚑ Execute
MITRE: T1218.002

Csc.exe

πŸͺŸ

Binary file used by .NET Framework to compile C# code

πŸ”¨ Compile
MITRE: T1127

Cscript.exe

πŸͺŸ

Binary used to execute scripts in Windows

⚑ Execute
MITRE: T1564.004

CustomShellHost.exe

πŸͺŸ

A host process that is used by custom shells when using Windows in Kiosk mode.

⚑ Execute
MITRE: T1218

DataSvcUtil.exe

πŸͺŸ

DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.

upload
MITRE: T1567

Desktopimgdownldr.exe

πŸͺŸ

Windows binary used to configure lockscreen/desktop image

πŸ“₯ Download
MITRE: T1105

DeviceCredentialDeployment.exe

πŸͺŸ

Device Credential Deployment

conceal
MITRE: T1564

Dfsvc.exe

πŸͺŸ

ClickOnce engine in Windows used by .NET

🚫 AWL
MITRE: T1127.002

Diantz.exe

πŸͺŸ

Binary that package existing files into a cabinet (.cab) file

⚑ ExecuteπŸ“₯ Download
MITRE: T1564.004

Diskshadow.exe

πŸͺŸ

Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).

dump⚑ Execute
MITRE: T1003.003

Dnscmd.exe

πŸͺŸ

A command-line interface for managing DNS servers

⚑ Execute
MITRE: T1543.003

Esentutl.exe

πŸͺŸ

Binary for working with Microsoft Joint Engine Technology (JET) database

πŸ“‹ Copy⚑ ExecuteπŸ“₯ Download
MITRE: T1105

Eudcedit.exe

πŸͺŸ

Private Character Editor Windows Utility

πŸ›‘οΈ UAC
MITRE: T1548.002

Eventvwr.exe

πŸͺŸ

Displays Windows Event Logs in a GUI window.

πŸ›‘οΈ UAC
MITRE: T1548.002

Expand.exe

πŸͺŸ

Binary that expands one or more compressed files

πŸ“₯ DownloadπŸ“‹ Copy⚑ Execute
MITRE: T1105

Explorer.exe

πŸͺŸ

Binary used for managing files and system components within Windows

⚑ Execute
MITRE: T1202

Extexport.exe

πŸͺŸ

Load a DLL located in the c:\test folder with a specific name.

⚑ Execute
MITRE: T1218

Extrac32.exe

πŸͺŸ

Extract to ADS, copy or overwrite a file with Extrac32.exe

⚑ ExecuteπŸ“₯ DownloadπŸ“‹ Copy
MITRE: T1564.004

Findstr.exe

πŸͺŸ

Write to ADS, discover, or download files with Findstr.exe

⚑ ExecutecredentialsπŸ“₯ Download
MITRE: T1564.004

Finger.exe

πŸͺŸ

Displays information about a user or users on a specified remote computer that is running the Finger service or daemon

πŸ“₯ Download
MITRE: T1105

fltMC.exe

πŸͺŸ

Filter Manager Control Program used by Windows

tamper
MITRE: T1562.001

Forfiles.exe

πŸͺŸ

Selects and executes a command on a file or set of files. This command is useful for batch processing.

⚑ Execute
MITRE: T1202

Fsutil.exe

πŸͺŸ

File System Utility

tamper⚑ Execute
MITRE: T1485

Ftp.exe

πŸͺŸ

A binary designed for connecting to FTP servers

⚑ ExecuteπŸ“₯ Download
MITRE: T1202

Gpscript.exe

πŸͺŸ

Used by group policy to process scripts

⚑ Execute
MITRE: T1218

Hh.exe

πŸͺŸ

Binary used for processing chm files in Windows

πŸ“₯ Download⚑ Execute
MITRE: T1105

IMEWDBLD.exe

πŸͺŸ

Microsoft IME Open Extended Dictionary Module

πŸ“₯ Download
MITRE: T1105

Ie4uinit.exe

πŸͺŸ

Executes commands from a specially prepared ie4uinit.inf file.

⚑ Execute
MITRE: T1218

iediagcmd.exe

πŸͺŸ

Diagnostics Utility for Internet Explorer

⚑ Execute
MITRE: T1218

Ieexec.exe

πŸͺŸ

The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.

πŸ“₯ Download⚑ Execute
MITRE: T1105

Ilasm.exe

πŸͺŸ

used for compile c# code into dll or exe.

πŸ”¨ Compile
MITRE: T1127

Infdefaultinstall.exe

πŸͺŸ

Binary used to perform installation based on content inside inf files

⚑ Execute
MITRE: T1218

Installutil.exe

πŸͺŸ

The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies

🚫 AWL⚑ ExecuteπŸ“₯ Download
MITRE: T1218.004

iscsicpl.exe

πŸͺŸ

Microsoft iSCSI Initiator Control Panel tool

πŸ›‘οΈ UAC
MITRE: T1548.002

Jsc.exe

πŸͺŸ

Binary file used by .NET to compile JavaScript code to .exe or .dll format

πŸ”¨ Compile
MITRE: T1127

Ldifde.exe

πŸͺŸ

Creates, modifies, and deletes LDAP directory objects.

πŸ“₯ Download
MITRE: T1105

Makecab.exe

πŸͺŸ

Binary to package existing files into a cabinet (.cab) file

⚑ ExecuteπŸ“₯ Download
MITRE: T1564.004

Mavinject.exe

πŸͺŸ

Used by App-v in Windows

⚑ Execute
MITRE: T1218.013

Microsoft.Workflow.Compiler.exe

πŸͺŸ

A utility included with .NET that is capable of compiling and executing C# or VB.net code.

⚑ Execute🚫 AWL
MITRE: T1127

Mmc.exe

πŸͺŸ

Load snap-ins to locally and remotely manage Windows systems

⚑ ExecuteπŸ›‘οΈ UACπŸ“₯ Download
MITRE: T1218.014

MpCmdRun.exe

πŸͺŸ

Binary part of Windows Defender. Used to manage settings in Windows Defender

πŸ“₯ Download⚑ Execute
MITRE: T1105

Msbuild.exe

πŸͺŸ

Used to compile and execute code

🚫 AWL⚑ Execute
MITRE: T1127.001

Msconfig.exe

πŸͺŸ

MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows

⚑ Execute
MITRE: T1218

Msdt.exe

πŸͺŸ

Microsoft diagnostics tool

⚑ Execute🚫 AWL
MITRE: T1218

Msedge.exe

πŸͺŸ

Microsoft Edge browser

πŸ“₯ Download⚑ Execute
MITRE: T1105

Mshta.exe

πŸͺŸ

Used by Windows to execute html applications. (.hta)

⚑ ExecuteπŸ“₯ Download
MITRE: T1218.005

Msiexec.exe

πŸͺŸ

Used by Windows to execute msi files

⚑ Execute
MITRE: T1218.007

Netsh.exe

πŸͺŸ

Netsh is a Windows tool used to manipulate network interface settings.

⚑ Execute
MITRE: T1546.007

Ngen.exe

πŸͺŸ

Microsoft Native Image Generator.

πŸ“₯ Download
MITRE: T1105

Odbcconf.exe

πŸͺŸ

Used in Windows for managing ODBC connections

⚑ Execute
MITRE: T1218.008

OfflineScannerShell.exe

πŸͺŸ

Windows Defender Offline Shell

⚑ Execute
MITRE: T1218

OneDriveStandaloneUpdater.exe

πŸͺŸ

OneDrive Standalone Updater

πŸ“₯ Download
MITRE: T1105

Pcalua.exe

πŸͺŸ

Program Compatibility Assistant

⚑ Execute
MITRE: T1202

Pcwrun.exe

πŸͺŸ

Program Compatibility Wizard

⚑ Execute
MITRE: T1218

Pktmon.exe

πŸͺŸ

Capture Network Packets on the windows 10 with October 2018 Update or later.

πŸ” Recon
MITRE: T1040

Pnputil.exe

πŸͺŸ

Used for installing drivers

⚑ Execute
MITRE: T1547

Presentationhost.exe

πŸͺŸ

File is used for executing Browser applications

⚑ ExecuteπŸ“₯ Download
MITRE: T1218

Print.exe

πŸͺŸ

Used by Windows to send files to the printer

⚑ ExecuteπŸ“‹ Copy
MITRE: T1564.004

PrintBrm.exe

πŸͺŸ

Printer Migration Command-Line Tool

πŸ“₯ Download⚑ Execute
MITRE: T1105

Provlaunch.exe

πŸͺŸ

Launcher process

⚑ Execute
MITRE: T1218

Psr.exe

πŸͺŸ

Windows Problem Steps Recorder, used to record screen and clicks.

πŸ” Recon
MITRE: T1113

Query.exe

πŸͺŸ

Remote Desktop Services MultiUser Query Utility

⚑ Execute
MITRE: T1218

Rasautou.exe

πŸͺŸ

Windows Remote Access Dialer

⚑ Execute
MITRE: T1218

rdrleakdiag.exe

πŸͺŸ

Microsoft Windows resource leak diagnostic tool

dump
MITRE: T1003

Reg.exe

πŸͺŸ

Used to manipulate the registry

⚑ Executecredentials
MITRE: T1564.004

Regasm.exe

πŸͺŸ

Part of .NET

🚫 AWL⚑ Execute
MITRE: T1218.009

Regedit.exe

πŸͺŸ

Used by Windows to manipulate registry

⚑ Execute
MITRE: T1564.004

Regini.exe

πŸͺŸ

Used to manipulate the registry

⚑ Execute
MITRE: T1564.004

Register-cimprovider.exe

πŸͺŸ

Used to register new wmi providers

⚑ Execute
MITRE: T1218

Regsvcs.exe

πŸͺŸ

Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies

⚑ Execute🚫 AWL
MITRE: T1218.009

Regsvr32.exe

πŸͺŸ

Used by Windows to register dlls

🚫 AWL⚑ Execute
MITRE: T1218.010

Replace.exe

πŸͺŸ

Used to replace file with another file

πŸ“‹ CopyπŸ“₯ Download
MITRE: T1105

Reset.exe

πŸͺŸ

Remote Desktop Services Reset Utility

⚑ Execute
MITRE: T1218

Rpcping.exe

πŸͺŸ

Used to verify rpc connection

credentials
MITRE: T1003

Rundll32.exe

πŸͺŸ

Used by Windows to execute dll files

⚑ Execute
MITRE: T1218.011

Runexehelper.exe

πŸͺŸ

Launcher process

⚑ Execute
MITRE: T1218

Runonce.exe

πŸͺŸ

Executes a Run Once Task that has been configured in the registry

⚑ Execute
MITRE: T1218

Runscripthelper.exe

πŸͺŸ

Execute target PowerShell script

⚑ Execute
MITRE: T1218

Sc.exe

πŸͺŸ

Used by Windows to manage services

⚑ Execute
MITRE: T1564.004

Schtasks.exe

πŸͺŸ

Schedule periodic tasks

⚑ Execute
MITRE: T1053.005

Scriptrunner.exe

πŸͺŸ

Execute binary through proxy binary to evade defensive counter measures

⚑ Execute
MITRE: T1202

Setres.exe

πŸͺŸ

Configures display settings

⚑ Execute
MITRE: T1218

SettingSyncHost.exe

πŸͺŸ

Host Process for Setting Synchronization

⚑ Execute
MITRE: T1218

Sftp.exe

πŸͺŸ

sftp.exe is a Windows command-line utility that uses the Secure File Transfer Protocol (SFTP) to securely transfer files between a local machine and a remote server.

⚑ Execute
MITRE: T1202

ssh.exe

πŸͺŸ

Ssh.exe is the OpenSSH compatible client can be used to connect to Windows 10 (build 1809 and later) and Windows Server 2019 devices.

⚑ Execute
MITRE: T1202

Stordiag.exe

πŸͺŸ

Storage diagnostic tool

⚑ Execute
MITRE: T1218

SyncAppvPublishingServer.exe

πŸͺŸ

Used by App-v to get App-v server lists

⚑ Execute
MITRE: T1218

Tar.exe

πŸͺŸ

Used by Windows to extract and create archives.

⚑ ExecuteπŸ“‹ Copy
MITRE: T1564.004

Ttdinject.exe

πŸͺŸ

Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)

⚑ Execute
MITRE: T1127

Tttracer.exe

πŸͺŸ

Used by Windows 1809 and newer to Debug Time Travel

⚑ Executedump
MITRE: T1127

Unregmp2.exe

πŸͺŸ

Microsoft Windows Media Player Setup Utility

⚑ Execute
MITRE: T1202

vbc.exe

πŸͺŸ

Binary file used for compile vbs code

πŸ”¨ Compile
MITRE: T1127

Verclsid.exe

πŸͺŸ

Used to verify a COM object before it is instantiated by Windows Explorer

⚑ Execute
MITRE: T1218.012

Wab.exe

πŸͺŸ

Windows address book manager

⚑ Execute
MITRE: T1218

wbadmin.exe

πŸͺŸ

Windows Backup Administration utility

dump
MITRE: T1003.003

wbemtest.exe

πŸͺŸ

WMI/WBEM Test Binary

⚑ Execute
MITRE: T1047

winget.exe

πŸͺŸ

Windows Package Manager tool

⚑ ExecuteπŸ“₯ Download🚫 AWL
MITRE: T1105

Wlrmdr.exe

πŸͺŸ

Windows Logon Reminder executable

⚑ Execute
MITRE: T1202

Wmic.exe

πŸͺŸ

The WMI command-line (WMIC) utility provides a command-line interface for WMI

⚑ ExecuteπŸ“‹ Copy
MITRE: T1564.004

WorkFolders.exe

πŸͺŸ

Work Folders

⚑ Execute
MITRE: T1218

Wscript.exe

πŸͺŸ

Used by Windows to execute scripts

⚑ Execute
MITRE: T1564.004

Wsreset.exe

πŸͺŸ

Used to reset Windows Store settings according to its manifest file

πŸ›‘οΈ UAC
MITRE: T1548.002

wuauclt.exe

πŸͺŸ

Windows Update Client

⚑ Execute
MITRE: T1218

Xwizard.exe

πŸͺŸ

Execute custom class that has been added to the registry or download a file with Xwizard.exe

⚑ ExecuteπŸ“₯ Download
MITRE: T1218

msedge_proxy.exe

πŸͺŸ

Microsoft Edge Browser

πŸ“₯ Download⚑ Execute
MITRE: T1105

msedgewebview2.exe

πŸͺŸ

msedgewebview2.exe is the executable file for Microsoft Edge WebView2, which is a web browser control used by applications to display web content.

⚑ Execute
MITRE: T1218.015

wt.exe

πŸͺŸ

Windows Terminal

⚑ Execute
MITRE: T1202

Advpack.dll

πŸͺŸ

Utility for installing software and drivers with rundll32.exe

🚫 AWL⚑ Execute
MITRE: T1218.011

Desk.cpl

πŸͺŸ

Desktop Settings Control Panel

⚑ Execute
MITRE: T1218.011

Dfshim.dll

πŸͺŸ

ClickOnce engine in Windows used by .NET

🚫 AWL
MITRE: T1127.002

Ieadvpack.dll

πŸͺŸ

INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.

🚫 AWL⚑ Execute
MITRE: T1218.011

Ieframe.dll

πŸͺŸ

Internet Browser DLL for translating HTML code.

⚑ Execute
MITRE: T1218.011

Mshtml.dll

πŸͺŸ

Microsoft HTML Viewer

⚑ Execute
MITRE: T1218.011

Pcwutl.dll

πŸͺŸ

Microsoft HTML Viewer

⚑ Execute
MITRE: T1218.011

PhotoViewer.dll

πŸͺŸ

Windows Photo Viewer

πŸ“₯ Download
MITRE: T1105

Scrobj.dll

πŸͺŸ

Windows Script Component Runtime

πŸ“₯ Download
MITRE: T1105

Setupapi.dll

πŸͺŸ

Windows Setup Application Programming Interface

🚫 AWL⚑ Execute
MITRE: T1218.011

Shdocvw.dll

πŸͺŸ

Shell Doc Object and Control Library.

⚑ Execute
MITRE: T1218.011

Shell32.dll

πŸͺŸ

Windows Shell Common Dll

⚑ Execute
MITRE: T1218.011

Shimgvw.dll

πŸͺŸ

Photo Gallery Viewer

πŸ“₯ Download
MITRE: T1105

Syssetup.dll

πŸͺŸ

Windows NT System Setup

🚫 AWL⚑ Execute
MITRE: T1218.011

Url.dll

πŸͺŸ

Internet Shortcut Shell Extension DLL.

⚑ Execute
MITRE: T1218.011

Zipfldr.dll

πŸͺŸ

Compressed Folder library

⚑ Execute
MITRE: T1218.011

Comsvcs.dll

πŸͺŸ

COM+ Services

dump
MITRE: T1003.001

CL_LoadAssembly.ps1

πŸͺŸ

PowerShell Diagnostic Script

⚑ Execute
MITRE: T1216

CL_Mutexverifiers.ps1

πŸͺŸ

Proxy execution with CL_Mutexverifiers.ps1

⚑ Execute
MITRE: T1216

CL_Invocation.ps1

πŸͺŸ

Aero diagnostics script

⚑ Execute
MITRE: T1216

Launch-VsDevShell.ps1

πŸͺŸ

Locates and imports a Developer PowerShell module and calls the Enter-VsDevShell cmdlet

⚑ Execute
MITRE: T1216

Manage-bde.wsf

πŸͺŸ

Script for managing BitLocker

⚑ Execute
MITRE: T1216

Pubprn.vbs

πŸͺŸ

Proxy execution with Pubprn.vbs

⚑ Execute
MITRE: T1216.001

Syncappvpublishingserver.vbs

πŸͺŸ

Script used related to app-v and publishing server

⚑ Execute
MITRE: T1216.002

UtilityFunctions.ps1

πŸͺŸ

PowerShell Diagnostic Script

⚑ Execute
MITRE: T1216

winrm.vbs

πŸͺŸ

Script used for manage Windows RM settings

⚑ Execute🚫 AWL
MITRE: T1216

Pester.bat

πŸͺŸ

Used as part of the Powershell pester

⚑ Execute
MITRE: T1216

AccCheckConsole.exe

πŸͺŸ

Verifies UI accessibility requirements

⚑ Execute🚫 AWL
MITRE: T1218

adplus.exe

πŸͺŸ

Debugging tool included with Windows Debugging Tools

dump⚑ Execute
MITRE: T1003.001

AgentExecutor.exe

πŸͺŸ

Intune Management Extension included on Intune Managed Devices

⚑ Execute
MITRE: T1218

AppLauncher.exe

πŸͺŸ

User Experience Virtualization tool that launches applications under monitoring to capture and synchronize user settings.

⚑ Execute
MITRE: T1127

AppCert.exe

πŸͺŸ

Windows App Certification Kit command-line tool.

⚑ Execute
MITRE: T1127

Appvlp.exe

πŸͺŸ

Application Virtualization Utility Included with Microsoft Office 2016

⚑ Execute
MITRE: T1218

Bcp.exe

πŸͺŸ

Microsoft SQL Server Bulk Copy Program utility for importing and exporting data between SQL Server instances and data files.

πŸ“₯ Download
MITRE: T1105

Bginfo.exe

πŸͺŸ

Background Information Utility included with SysInternals Suite

⚑ Execute🚫 AWL
MITRE: T1218

Cdb.exe

πŸͺŸ

Debugging tool included with Windows Debugging Tools.

⚑ Execute
MITRE: T1127

coregen.exe

πŸͺŸ

Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.

⚑ Execute🚫 AWL
MITRE: T1055

Createdump.exe

πŸͺŸ

Microsoft .NET Runtime Crash Dump Generator (included in .NET Core)

dump
MITRE: T1003

csi.exe

πŸͺŸ

Command line interface included with Visual Studio.

⚑ Execute
MITRE: T1127

DefaultPack.EXE

πŸͺŸ

This binary can be downloaded along side multiple software downloads on the Microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.

⚑ Execute
MITRE: T1218

Devinit.exe

πŸͺŸ

Visual Studio 2019 tool

⚑ Execute
MITRE: T1218.007

Devtoolslauncher.exe

πŸͺŸ

Binary will execute specified binary. Part of VS/VScode installation.

⚑ Execute
MITRE: T1127

dnx.exe

πŸͺŸ

.NET Execution environment file included with .NET.

⚑ Execute
MITRE: T1127

Dotnet.exe

πŸͺŸ

dotnet.exe comes with .NET Framework

🚫 AWL⚑ Execute
MITRE: T1218

dsdbutil.exe

πŸͺŸ

Dsdbutil is a command-line tool that is built into Windows Server. It is available if you have the AD LDS server role installed. Can be used as a command line utility to export Active Directory.

dump
MITRE: T1003.003

dtutil.exe

πŸͺŸ

Microsoft command line utility used to manage SQL Server Integration Services packages.

πŸ“‹ Copy
MITRE: T1105

Dump64.exe

πŸͺŸ

Memory dump tool that comes with Microsoft Visual Studio

dump
MITRE: T1003.001

DumpMinitool.exe

πŸͺŸ

Dump tool part Visual Studio 2022

dump
MITRE: T1003.001

Dxcap.exe

πŸͺŸ

DirectX diagnostics/debugger included with Visual Studio.

⚑ Execute
MITRE: T1127

ECMangen.exe

πŸͺŸ

Command-line tool for managing certificates in Microsoft Exchange Server.

πŸ“₯ Download
MITRE: T1105

Excel.exe

πŸͺŸ

Microsoft Office binary

πŸ“₯ Download
MITRE: T1105

Fsi.exe

πŸͺŸ

64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.

🚫 AWL
MITRE: T1059

FsiAnyCpu.exe

πŸͺŸ

32/64-bit FSharp (F#) Interpreter included with Visual Studio.

🚫 AWL
MITRE: T1059

IntelliTrace.exe

πŸͺŸ

Visual Studio command-line tool for collecting and managing diagnostic trace files.

⚑ Execute
MITRE: T1127

Mftrace.exe

πŸͺŸ

Trace log generation tool for Media Foundation Tools.

⚑ Execute
MITRE: T1127

Microsoft.NodejsTools.PressAnyKey.exe

πŸͺŸ

Part of the NodeJS Visual Studio tools.

⚑ Execute
MITRE: T1127

Mpiexec.exe

πŸͺŸ

Command-line tool for running Message Passing Interface (MPI) applications.

⚑ Execute
MITRE: T1127

MSAccess.exe

πŸͺŸ

Microsoft Office component

πŸ“₯ Download
MITRE: T1105

Msdeploy.exe

πŸͺŸ

Microsoft tool used to deploy Web Applications.

⚑ Execute🚫 AWLπŸ“‹ Copy
MITRE: T1218

MsoHtmEd.exe

πŸͺŸ

Microsoft Office component

πŸ“₯ Download
MITRE: T1105

Mspub.exe

πŸͺŸ

Microsoft Publisher

πŸ“₯ Download
MITRE: T1105

msxsl.exe

πŸͺŸ

Command line utility used to perform XSL transformations.

⚑ Execute🚫 AWLπŸ“₯ Download
MITRE: T1220

ntdsutil.exe

πŸͺŸ

Command line utility used to export Active Directory.

dump
MITRE: T1003.003

Ntsd.exe

πŸͺŸ

Symbolic Debugger for Windows.

⚑ Execute
MITRE: T1127

OpenConsole.exe

πŸͺŸ

Console Window host for Windows Terminal

⚑ Execute
MITRE: T1202

Pixtool.exe

πŸͺŸ

Command line utility for taking and analyzing PIX GPU captures.

⚑ Execute
MITRE: T1127

Powerpnt.exe

πŸͺŸ

Microsoft Office binary.

πŸ“₯ Download
MITRE: T1105

Procdump.exe

πŸͺŸ

SysInternals Memory Dump Tool

⚑ Execute
MITRE: T1202

ProtocolHandler.exe

πŸͺŸ

Microsoft Office binary

πŸ“₯ Download
MITRE: T1105

rcsi.exe

πŸͺŸ

Non-Interactive command line inerface included with Visual Studio.

⚑ Execute🚫 AWL
MITRE: T1127

Remote.exe

πŸͺŸ

Debugging tool included with Windows Debugging Tools

🚫 AWL⚑ Execute
MITRE: T1127

Sqldumper.exe

πŸͺŸ

Debugging utility included with Microsoft SQL.

dump
MITRE: T1003

Sqlps.exe

πŸͺŸ

Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.

⚑ Execute
MITRE: T1218

SQLToolsPS.exe

πŸͺŸ

Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+.

⚑ Execute
MITRE: T1218

Squirrel.exe

πŸͺŸ

Binary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.

πŸ“₯ Download🚫 AWL⚑ Execute
MITRE: T1218

te.exe

πŸͺŸ

Testing tool included with Microsoft Test Authoring and Execution Framework (TAEF).

⚑ Execute
MITRE: T1127

Teams.exe

πŸͺŸ

Electron runtime binary which runs the Teams application

⚑ Execute
MITRE: T1218.015

TestWindowRemoteAgent.exe

πŸͺŸ

TestWindowRemoteAgent.exe is the command-line tool to establish RPC

upload
MITRE: T1048

Tracker.exe

πŸͺŸ

Tool included with Microsoft .Net Framework.

⚑ Execute🚫 AWL
MITRE: T1127

Update.exe

πŸͺŸ

Binary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.

πŸ“₯ Download🚫 AWL⚑ Execute
MITRE: T1218

VSDiagnostics.exe

πŸͺŸ

Command-line tool used for performing diagnostics.

⚑ Execute
MITRE: T1127

VSIISExeLauncher.exe

πŸͺŸ

Binary will execute specified binary. Part of VS/VScode installation.

⚑ Execute
MITRE: T1218

Visio.exe

πŸͺŸ

Microsoft Visio Executable

πŸ“₯ Download
MITRE: T1105

VisualUiaVerifyNative.exe

πŸͺŸ

A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.

🚫 AWL
MITRE: T1218

VSLaunchBrowser.exe

πŸͺŸ

Microsoft Visual Studio browser launcher tool for web applications debugging

πŸ“₯ Download⚑ Execute
MITRE: T1105

Vshadow.exe

πŸͺŸ

VShadow is a command-line tool that can be used to create and manage volume shadow copies.

⚑ Execute
MITRE: T1202

vsjitdebugger.exe

πŸͺŸ

Just-In-Time (JIT) debugger included with Visual Studio

⚑ Execute
MITRE: T1127

WFMFormat.exe

πŸͺŸ

Command-line tool used for pretty-print a dump file generated by Message Farm Analyzer tool.

⚑ Execute
MITRE: T1127

Wfc.exe

πŸͺŸ

The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).

🚫 AWL
MITRE: T1127

WinDbg.exe

πŸͺŸ

Windows Debugger for advanced user-mode and kernel-mode debugging.

⚑ Execute
MITRE: T1127

WinProj.exe

πŸͺŸ

Microsoft Project Executable

πŸ“₯ Download
MITRE: T1105

Winword.exe

πŸͺŸ

Microsoft Office binary

πŸ“₯ Download
MITRE: T1105

Wsl.exe

πŸͺŸ

Windows subsystem for Linux executable

⚑ ExecuteπŸ“₯ Download
MITRE: T1202

XBootMgr.exe

πŸͺŸ

Windows Performance Toolkit binary used to start performance traces.

⚑ Execute
MITRE: T1202

XBootMgrSleep.exe

πŸͺŸ

Windows Performance Toolkit binary used for tracing and analyzing system performance during sleep and resume transitions.

⚑ Execute
MITRE: T1202

devtunnel.exe

πŸͺŸ

Binary to enable forwarded ports on windows operating systems.

πŸ“₯ Download
MITRE: T1105

vsls-agent.exe

πŸͺŸ

Agent for Visual Studio Live Share (Code Collaboration)

⚑ Execute
MITRE: T1218

vstest.console.exe

πŸͺŸ

VSTest.Console.exe is the command-line tool to run tests

🚫 AWL
MITRE: T1127

winfile.exe

πŸͺŸ

Windows File Manager executable

⚑ Execute
MITRE: T1202

xsd.exe

πŸͺŸ

XML Schema Definition Tool included with the Windows Software Development Kit (SDK).

πŸ“₯ Download
MITRE: T1105