03 : /Privilege-escalation Windows#

~/ cat Devtoolslauncher.exe.md

Binary will execute specified binary. Part of VS/VScode installation.

Paths:

c:\windows\system32\devtoolslauncher.exe

Detection: DeveloperToolsSvc.exe spawned an unknown process

Execute

The above binary will execute other binary.

devtoolslauncher.exe LaunchForDeploy [PATH_TO_BIN] "argument here" test

The above binary will execute other binary.

devtoolslauncher.exe LaunchForDebug [PATH_TO_BIN] "argument here" test