Windows

Esentutl.exeEsentutl.exe

Platform
Windows
Abuse functions
6
Mapped techniques
3

Description

Esentutl.exe is a Windows living-off-the-land binary catalogued by the LOLBAS Project. Documented abuse functions: Copy, ADS, Download. Mapped ATT&CK techniques (per LOLBAS / GTFOBins → MITRE crosswalk): T1105, T1564.004. Defenders should monitor execution of Esentutl.exe under non-administrative or sudo contexts and alert when its arguments match the abuse-function signatures.

Abuse functions· 6

CopyT1105

Copies files from A to B

Copy file and hide it in an alternate data stream as a defensive counter measure

Extract hidden file within alternate data streams

Copy file and hide it in an alternate data stream as a defensive counter measure

DownloadT1564.004

Use to copy files from one unc path to another

Copy/extract a locked file such as the AD Database

MITRE ATT&CK techniques· 3

T1105T1564.004T1003.003

Uses3

TypeTargetConfidenceTier
TechniqueIngress Tool Transfert1105100%live
SubTechniqueNTDSt1003.003100%live
SubTechniqueNTFS File Attributest1564.004100%live

Abuses2

TypeTargetConfidenceTier
SubTechniqueNTFS File Attributest1564.00490%live
TechniqueIngress Tool Transfert110585%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

LOLbin
Extrac32.exe
LOLbin
ECMangen.exe
LOLbin
DataSvcUtil.exe
LOLbin
dtutil.exe
LOLbin
Expand.exe
LOLbin
Fsutil.exe
Sourced from LOLBAS Project. Curated by Adam Lundqvist, SQUR.