In this session, we will cover a variety of techniques to gain code execution on Microsoft IIS servers, ranging from simple webshells to reflectively loading .NET assemblies via exploits. After performing each attack, we will conduct an incident response to determine what happened and discuss remediation options for recovering from this attack as well as ensuring we can better detect the technique next time.