Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CrowdStrike has published a two-part research series revealing how Microsoft’s ClickOnce deployment technology, a framework present on virtually every modern Windows system, can be weaponized for initial access, payload delivery, and persistent footholds without requiring administrator privileges. Because execution runs inside legitimate Microsoft process trees (dfsvc.exe, rundll32.exe), most signature-based endpoint tools will not flag the activity. This research signals a broader attacker trend toward living off the land (LOTL) techniques that abuse trusted deployment infrastructure, where the attack surface is not a flaw to patch but a design feature to detect around.

Author

Tech Jacks Solutions