Researchers reported that Microsoft WinGet can be abused as a living-off-the-land binary to execute arbitrary PowerShell logic through its winget configure feature and Desired State Configuration (DSC) resources. The technique uses YAML configuration files supplied from local storage or remote URLs, which are processed by ConfigurationRemotingServer.exe; WinGet can also download DSC modules into %LOCALAPPDATA%\Microsoft\WinGet\Configuration\Modules. Because the activity does not require directly launching powershell.exe, it may reduce defender visibility even though execution still flows through System.Management.Automation and AMSI.
Follow-on research showed the same execution path can be triggered more stealthily through the WinGet COM API, avoiding a visible WinGet.exe process while still enabling offensive actions such as reverse shells and persistence through local administrator creation. The reports said some EDR tools may not classify the behavior as malicious and urged defenders to monitor WinGet-related process creation, child process activity from ConfigurationRemotingServer.exe, network connections, DLL loads, registry changes, AMSI telemetry, and forensic artifacts including WinGet’s config.db history database.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
An ipurple.team article published offensive examples of WinGet abuse, including a reverse shell and local administrator creation for persistence, and provided detection guidance focused on process creation, network connections, DLL loads, and forensic review of WinGet's config.db history database.
Dylan Davis and Matthew Schramm demonstrated invoking the WinGet configuration engine through an API instead of WinGet.exe, producing a process tree where WindowsPackageManagerServer.exe parents ConfigurationRemotingServer.exe. The ipurple article identifies DSCourier as a proof-of-concept for this technique.
A researcher using the handle TwoSevenOneThree showed that Microsoft WinGet can execute PowerShell code embedded in YAML configuration files through Desired State Configuration resources, including fetching configurations from remote HTTPS locations and disguising them with non-.yaml extensions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.