Executive Summary
Security researchers have identified a technique where the Windows Package Manager (WinGet) can be leveraged as a Living-off-the-Land Binary (LoLBins) to execute arbitrary code. By using the 'winget configure' command or its underlying COM API, attackers can process YAML configuration files that contain PowerShell Desired State Configuration (DSC) resources. This allows for the execution of malicious scripts without directly invoking standard PowerShell processes, potentially evading traditional EDR detections.
The attack chain involves crafting a YAML file using the 'PSDscResources/Script' resource and executing it through WinGet. Attackers can host these configuration files on remote HTTPS servers, masquerade them with non-YAML extensions (e.g., .jpg, .txt), and automate the process using tools like DSCourier. This technique is highly effective because WinGet is pre-installed on modern Windows 10, 11, and Server 2025 systems.
This threat is significant as it provides a stealthy mechanism for initial staging, reverse shells, and persistence (e.g., local account creation). Since WinGet is a legitimate administrative tool, simple execution of the binary may not trigger alerts, requiring SOC teams to implement specific behavioral monitoring of the WinGet process tree and associated network activity.
