This page holds the location of my research within ClickOnce and AppLaunch.exe. This was presented at Defcon34 at Red Team Village!
The below whitepaper describes the attack in great detail. It’s not an academic paper but more of an explination of the attack, but fully written out and edited. Access it through:
https://nathan2.com/files/clicktools.pdf
A link will later be added here for the talk.
Finally, the github link with the repository is at: