Videos / Defcon / Nick Powers and Steven Flores: ClickOnce as a Trusted Code Execution Vector

Nick Powers and Steven Flores: ClickOnce as a Trusted Code Execution Vector

Duration: 44min 24sec Type: Presentation (lecture) Playlist: 135 of 146 in Defcon
A DEF CON 30 talk exploring ClickOnce as an underused yet powerful initial access technique. The speakers demonstrate how this deployment technology can be leveraged to bypass Windows defenses such as SmartScreen, application whitelisting, and other security controls.

The presentation focuses on turning ClickOnce into an effective initial access vector without relying on expensive EV code-signing certificates. As traditional phishing techniques (including Office macros) face increasing restrictions, the speakers show how attackers can abuse trust in signed .NET assemblies to evade security mechanisms.

Two core techniques are demonstrated: sideloading existing signed ClickOnce deployments, and creating custom ClickOnce manifests around trusted .NET applications

The talk dives deep into manifest structures, integrity validation mechanisms, UAC nuances, and practical exploitation workflows — including live demonstrations.

Finally, the speakers introduce automation tools, discuss detection opportunities, and outline defensive strategies. A hands-on exploration of both offensive and defensive tradecraft around a little-known but highly capable Windows execution mechanism.