{"id":8278,"date":"2022-11-19T22:53:09","date_gmt":"2022-11-19T22:53:09","guid":{"rendered":"https:\/\/www.hexacorn.com\/blog\/?p=8278"},"modified":"2022-11-19T23:05:21","modified_gmt":"2022-11-19T23:05:21","slug":"beyond-good-ol-run-key-part-139","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2022\/11\/19\/beyond-good-ol-run-key-part-139\/","title":{"rendered":"Beyond good ol\u2019 Run key, Part 139"},"content":{"rendered":"\n<p>This one is a curious one. I actually don&#8217;t know how to trigger it!<\/p>\n\n\n\n<p>Yet, I will document some bits and bobs, so that you may take these entry points into consideration, at least from a DFIR perspective.<\/p>\n\n\n\n<p>So, <em>edgehtml.dll<\/em> and <em>mshtml.dll<\/em> are monsters of a library (23-25MB+). One of the things they do is they provide functions that work in so-called Diagnostic Mode. When Browser is in that mode, it checks a number of environment variables, and if they are set, it will load a COM library specified by one of these entries (JS_DM_CLSID).<\/p>\n\n\n\n<p>And all these Java Script\/Diagnostic Mode environment variables it checks are:<\/p>\n\n\n\n<ul><li>JS_DM_CLSID<\/li><li>JS_DM_FLAGS<\/li><li>JS_DM_PATH<\/li><li>JS_DM_ID<\/li><\/ul>\n\n\n\n<p>I know it&#8217;s not a lot, but if JS_DM_CLSID is set as an environmental variable, you better check it&#8217;s value as it may be loaded by the browser. If you know more about the Diagnostic Mode, please let me know.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This one is a curious one. I actually don&#8217;t know how to trigger it! Yet, I will document some bits and bobs, so that you may take these entry points into consideration, at least from a DFIR perspective. So, edgehtml.dll &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2022\/11\/19\/beyond-good-ol-run-key-part-139\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[35],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8278"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=8278"}],"version-history":[{"count":3,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8278\/revisions"}],"predecessor-version":[{"id":8282,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8278\/revisions\/8282"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=8278"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=8278"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=8278"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}