1. A Study on .NET Framework for Red Team –
Part I
@ 若渴 2019.10.20
<ajblane0612@gmail.com>
AjMaChInE
2. Reference
[0] 2019, IronPython… OMFG Introducing BYOI
Payloads (Bring Your Own Interpreter)
[1] 2019, Common Language Runtime Hook for
Persistence
[2] 2019, .NET Manifesto
[3] 2019, Executing C# Assemblies from Jscript and
wscript with DotNetToJscript
[4] 2017, .NET HIJACKING to DEFEND POWERSHELL
[5] 2014, .NET Framework Rootkits
3. WSH – Window Script Host
DLR – Dynamic Language Runtime
CLR – Common Language Runtime
BYOI – Bring Your Own Interpreter
ADM – Application Domain Manager
MSIL – Microsoft Intermediate Language