Windows

msxsl.exemsxsl.exe

Platform
Windows
Abuse functions
6
Mapped techniques
3

Description

msxsl.exe is a Windows living-off-the-land binary catalogued by the LOLBAS Project. Documented abuse functions: Execute, AWL Bypass, Download, ADS. Mapped ATT&CK techniques (per LOLBAS / GTFOBins → MITRE crosswalk): T1105, T1218, T1564.004. Defenders should monitor execution of msxsl.exe under non-administrative or sudo contexts and alert when its arguments match the abuse-function signatures.

Abuse functions· 6

ExecuteT1220

Local execution of script stored in XSL file.

AWL BypassT1220

Local execution of script stored in XSL file.

ExecuteT1220

Local execution of remote script stored in XSL script stored as an XML file.

AWL BypassT1220

Local execution of remote script stored in XSL script stored as an XML file.

DownloadT1105

Download a file from the internet and save it to disk.

Download a file from the internet and save it to an NTFS Alternate Data Stream.

MITRE ATT&CK techniques· 3

T1220T1105T1564

Uses3

TypeTargetConfidenceTier
TechniqueXSL Script Processingt1220100%live
TechniqueIngress Tool Transfert1105100%live
TechniqueHide Artifactst1564100%live

Abuses3

TypeTargetConfidenceTier
SubTechniqueNTFS File Attributest1564.00490%live
TechniqueIngress Tool Transfert110585%live
TechniqueSystem Binary Proxy Executiont121885%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

LOLbin
xsd.exe
LOLbin
Wsl.exe
LOLbin
Excel.exe
LOLbin
Msiexec.exe
LOLbin
Msdt.exe
LOLbin
Mshta.exe
Sourced from LOLBAS Project. Curated by Adam Lundqvist, SQUR.