Privileges required: User
OS: Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre: T1202
Used for running programs with incompatabilities with the installed version of Windows. Can be used to run a binary in a new process tree.
pcalua.exe -a C:\Tools\payload.exe
SyncAppvPublishingServer
Privileges required: User
OS: Windows 10
Mitre: T1218
The SyncAppvPublishingServer initiates the Microsoft application virtualization (App-V) publishing refresh operation. However it can be used as a non-directly method to execute commands for evasion. In the example below the execution occurs from PowerShell and the “Start-Process” cmdlet is used to run the executable.