Proxy Execution with Microsoft Edge WebView2 - Matthew Eidelberg
How do sideloading techniques work in today’s runtime environment?
Join us for a free one-hour BHIS webcast with Matthew Eidelberg on proxy execution via Microsoft Edge WebView2.
Matthew will break down techniques that blur the line between legitimate app behavior and malicious activity, showing how shared runtime components are changing execution and detection boundaries.
You’ll learn how traditional sideloading concepts apply in modern environments, how WebView2 is increasingly embedded across the ecosystem, and how attackers can exploit it to bypass common detection methods.
🛝 Webcast Slides
https://www.blackhillsinfosec.com/wp-content/uploads/2026/04/Proxy-Execution-with-Microsoft-Edge-Webview2.pdf
Chapters
Chat with your fellow attendees in the BHIS Discord server:
https://discord.gg/bhis
in the #🔴live-event-chat channel
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
https://poweredbybhis.com
Click here to watch a video of this episode.
Brought to you by:
Join us for a free one-hour BHIS webcast with Matthew Eidelberg on proxy execution via Microsoft Edge WebView2.
Matthew will break down techniques that blur the line between legitimate app behavior and malicious activity, showing how shared runtime components are changing execution and detection boundaries.
You’ll learn how traditional sideloading concepts apply in modern environments, how WebView2 is increasingly embedded across the ecosystem, and how attackers can exploit it to bypass common detection methods.
🛝 Webcast Slides
https://www.blackhillsinfosec.com/wp-content/uploads/2026/04/Proxy-Execution-with-Microsoft-Edge-Webview2.pdf
Chapters
- (00:00) - Intro - Proxy Execution with Microsoft Edge WebView2 - Matthew Eidelberg
- (00:49) - Agenda
- (01:31) - DLL Hijacking
- (04:48) - DLL Proxy Attacks
- (06:05) - Execution Flow
- (07:17) - Windows Apps
- (12:05) - What is WebView2?
- (13:21) - Webview Security Issue
- (16:42) - Domain_action.dll
- (20:01) - Weaponizing the Flaw
- (22:38) - Tooling - FaceDancer
- (24:11) - FaceDancer - Usage
- (25:32) - FaceDancer - Examples
- (27:06) - FaceDancer - Common Questions
- (30:00) - FaceDancer - Caveats
- (30:44) - Microsoft's Response Timeline
- (34:04) - Microsoft's Disclosure Process
- (36:29) - Defensive View
- (38:37) - Wrap Up
- (39:49) - Q&A
Chat with your fellow attendees in the BHIS Discord server:
https://discord.gg/bhis
in the #🔴live-event-chat channel
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
https://poweredbybhis.com
Click here to watch a video of this episode.
Brought to you by:
Black Hills Information Security
☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/
Antisyphon Training
Active Countermeasures
Wild West Hackin Fest
Episode Video
Creators and Guests
Guest
Ashley Knowles
Ashley Knowles joined Black Hills Information Security (BHIS) in Fall 2021. As a Security Consultant, Ashley’s role is to perform network (internal/external), social engineering, and cloud penetration tests, as well as participating in red team assessments. Since joining the infosec community in 2013, she has developed and taught hacking classes, worked as a security consultant, and been a team lead on a red team. Ashley serves as a mentor at a local high school’s cyber security class and, as someone who loves to learn and teach, she looks forward to developing and teaching classes that add to BHIS’s educational catalogue. In her free time, Ashely enjoys photography, hiking and exploring new places with her kids, and building Legos.
Guest
Matthew Eidelberg
Matthew Eidelberg became part of Black Hills Information Security (BHIS) in August 2023. He works as a Red Teamer and Researcher on the continuous testing team. Matthew previously ran the red team at Optiv and the research initiative for Threat. He chose to join BHIS hearing great things from friends and started reading and watching the content BHIS produces. He most enjoys the community and working with like-minded security folks who are passionate about infosec and love to help each other out. When he’s not working, Matthew can be found cooking (mainly barbequing experimentation), reading comics, and, admittedly, creating payload tools.
Producer
Ryan Poirier
Ryan Poirier began his time at Black Hills Information Security (BHIS) as the Video Producer and Editor in August 2020. Ryan polishes and perfects every webcast, podcast, and workshop on the BHIS, ACM, and WWHF YouTube Channels. Prior to Ryan’s time at BHIS, he worked for one of the largest public schools in the United States, conducting their video production and live broadcasting. He joined the BHIS team because he felt like it would be a great group of people to work with, and he couldn’t pass up the perfect next step in his career. Outside of his time with BHIS, Ryan does freelance photography, attends Cars & Coffee events, and expands his knowledge of audio and videos.
Guest
Tom Smith
Tom Smith joined the Black Hills Information Security (BHIS) team in 2021 as a Business Consultant. He works with clients to identify their correct testing solution needs and proposal requests. Prior to his time at BHIS, he directed a business operations team in real estate. He decided it was time to make the switch when he realized he could work from home and fell in love with the energy at BHIS. Outside his time at work, he is a father to seven children, enjoys reading, playing guitar, and home improvement projects.