{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/infdefaultinstall/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["living-off-the-land","execution","windows","infdefaultinstall"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eInfDefaultInstall.exe is a legitimate Microsoft-signed Windows binary designed for the installation of INF (Information) files. Threat actors can abuse this utility as a Living-off-the-Land (LotL) technique to bypass security controls. By creating a malformed or specially prepared INF file containing references to script components (SCT) via scrobj.dll, an attacker can force the system to execute arbitrary code. Because the process is signed by Microsoft, this technique is frequently utilized to evade signature-based detection mechanisms that rely on process reputation. This behavior is documented in the LOLBAS (Living Off the Land Binaries and Scripts) project and has been validated by Atomic Red Team exercises. Defenders should monitor for the execution of InfDefaultInstall.exe with arguments pointing to suspicious or user-writable INF files, as this is a known vector for initial access or persistence.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker prepares a malicious INF file containing an InstallSection that references a remote or local SCT file.\u003c/li\u003e\n\u003cli\u003eAttacker crafts the INF file to utilize the RegisterOCX directive or similar hooks to load scrobj.dll.\u003c/li\u003e\n\u003cli\u003eAttacker delivers the malicious INF file to the victim endpoint through phishing or shared drive access.\u003c/li\u003e\n\u003cli\u003eAttacker executes InfDefaultInstall.exe from the command line, passing the path to the malicious INF file as an argument.\u003c/li\u003e\n\u003cli\u003eThe Windows utility parses the INF, triggers the registration of the specified SCT script, and executes the payload.\u003c/li\u003e\n\u003cli\u003eThe malicious payload runs within the context of the InfDefaultInstall.exe process, potentially leading to further compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution, which can be leveraged for lateral movement, credential theft, or the deployment of secondary malware. While InfDefaultInstall.exe is a built-in utility, its misuse allows an attacker to hide malicious activity under a trusted process identity, complicating incident response and forensic analysis.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious command-line invocations of InfDefaultInstall.exe.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline of legitimate use of InfDefaultInstall.exe within the organization; alert on any unexpected paths or execution from user-writable directories (e.g., C:\\Users\\Public).\u003c/li\u003e\n\u003cli\u003eEnable Sysmon process-creation logging (Event ID 1) and command-line auditing to capture the arguments passed to InfDefaultInstall.exe.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T13:45:50Z","date_published":"2026-09-03T13:45:50Z","id":"https://feed.craftedsignal.io/briefs/2026-09-infdefaultinstall-sct-execution/","summary":"Adversaries leverage the native Windows utility InfDefaultInstall.exe to execute malicious script content embedded within specially crafted INF files.","title":"Abuse of InfDefaultInstall.exe for SCT Script Execution","url":"https://feed.craftedsignal.io/briefs/2026-09-infdefaultinstall-sct-execution/"}],"language":"en","title":"CraftedSignal Threat Feed - Infdefaultinstall","version":"https://jsonfeed.org/version/1.1"}