Infdefaultinstall.exe
Binary used to perform installation based on content inside inf files
Full path
C:\Windows\System32\Infdefaultinstall.exe
C:\Windows\SysWOW64\Infdefaultinstall.exeCommands
Code execution
InfDefaultInstall.exe {PATH:.inf}Executes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.
os: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
Detection
- Sigma https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_infdefaultinstall_execute_sct_scripts.yml
- BlockRule https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules
Code samples
Resources
acknowledgement: Kyle Hanslovan @kylehanslovan