title: Use of Remote.exe id: 4eddc365-79b4-43ff-a9d7-99422dc34b93 status: experimental description: Remote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files. references: - https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/ - https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/ author: 'Christopher Peacock @SecurePeacock, SCYTHE @scythe_io' date: 2022/06/02 tags: - attack.defense_evasion - attack.t1127 logsource: category: process_creation product: windows detection: selection: - Image|endswith: '\remote.exe' - OriginalFileName: 'remote.exe' condition: selection falsepositives: - Approved installs of Windows SDK with Debugging Tools for Windows (WinDbg). level: medium