Just ServiceUI.exe
The Microsoft Deployment Toolkit MSI contains ServiceUI.exe, but you don’t need the whole installer to see how that signed Microsoft binary can be used as a tiny execution cradle. Nice and convenient for attackers, annoying for defenders.
Watch the full breakdown on the channel: https://youtu.be/4caJw0JJZTQ?si=MRURypK1eW2O5LMuJohn HammondRead More