WinGet DSC Arbitrary Code Execution and Proxying
Score: 9/10

WinGet DSC Arbitrary Code Execution and Proxying

Threat actors can abuse the Windows Package Manager (WinGet) configuration feature and its COM API to execute arbitrary PowerShell scripts via YAML files, bypassing standard process monitoring.

Executive Summary

Security researchers have identified a technique where the Windows Package Manager (WinGet) can be leveraged as a Living-off-the-Land Binary (LoLBins) to execute arbitrary code. By using the 'winget configure' command or its underlying COM API, attackers can process YAML configuration files that contain PowerShell Desired State Configuration (DSC) resources. This allows for the execution of malicious scripts without directly invoking standard PowerShell processes, potentially evading traditional EDR detections.

The attack chain involves crafting a YAML file using the 'PSDscResources/Script' resource and executing it through WinGet. Attackers can host these configuration files on remote HTTPS servers, masquerade them with non-YAML extensions (e.g., .jpg, .txt), and automate the process using tools like DSCourier. This technique is highly effective because WinGet is pre-installed on modern Windows 10, 11, and Server 2025 systems.

This threat is significant as it provides a stealthy mechanism for initial staging, reverse shells, and persistence (e.g., local account creation). Since WinGet is a legitimate administrative tool, simple execution of the binary may not trigger alerts, requiring SOC teams to implement specific behavioral monitoring of the WinGet process tree and associated network activity.

Key Details

Threat Name

WinGet DSC Arbitrary Code Execution

Affects

—

Adversary

—

Malware/Tools

DSCourier

Report Score

9out of 10
Quality Score
Excellent
IOC Quality6
TTP Details9
Detection Guidance10
Enterprise Relevance9
Clarity & Structure8
Technical Depth9

Sources