अल्टीमेट WDAC बायपास सूची
पहले से प्रलेखित WDAC/Device Guard/UMCI बायपास तकनीकों के साथ-साथ WDAC नीतियों के निर्माण/प्रबंधन/परीक्षण के लिए एक केंद्रीकृत संसाधन
- नोट: WDAC (Windows Defender Application Control) को Microsoft द्वारा "Application Control" या "Application Control for Business" के रूप में पुनः ब्रांड किया गया है
*कई LOLBINs Applications that can bypass WDAC List में शामिल हैं, जिसे पहले "Microsoft Recommended Block Rules List" कहा जाता था
Pro Tip: यदि Block Rules नीति लागू कर रहे हैं, तो पहले दो फ़ाइल नियमों को हटाना न भूलें: ID_ALLOW_A_1 और ID_ALLOW_A_2
*यह रिपॉज़िटरी Oddvar Moe की Ultimate AppLocker Bypass List से प्रेरित है
*हमेशा की तरह, यह एक कार्य प्रगति पर है...
ऐसे एप्लिकेशन जो WDAC को बायपास कर सकते हैं - "LOLBIN" राइट-अप्स
addinprocess.exe
- James Forshaw (@tiraniddo) द्वारा
- DG on Windows 10 S: Executing Arbitrary Code
addinprocess32.exe
- James Forshaw (@tiraniddo) द्वारा
- DG on Windows 10 S: Executing Arbitrary Code
addinutil.exe
- अज्ञात द्वारा (दस्तावेज़ीकरण @McKinleyMike और @TheLatteri द्वारा)
- Insecure Deserialization in AddinUtil.exe
aspnet_compiler.exe
- cpl (@cpl3h) द्वारा
- The Curious Case of Aspnet_Compiler.exe
bginfo.exe
- Oddvar Moe (@Oddvarmoe) द्वारा
- Bypassing Application Whitelisting with BGInfo
cdb.exe
- Matt Graeber (@mattifestation) द्वारा
- Bypassing Application Whitelisting by using WinDbg/CDB as a Shellcode Runner
csi.exe
- Casey Smith (@subTee) द्वारा
- Application Whitelisting Bypass - CSI.EXE C# Scripting
dbghost.exe
- Casey Smith (@subTee) द्वारा
- dbghost.exe - Ghost And The Darkness
dbgsrv.exe
- Casey Smith (@subTee), Ross Wolf (@rw_access) द्वारा
- How to Bypass WDAC with dbgsrv.exe
- Fantastic Red-Team Attacks and How to Find Them
dnx.exe
- Matt Nelson (@enigma0x3) द्वारा
- BYPASSING APPLICATION WHITELISTING BY USING DNX.EXE
dotnet.exe
- Jimmy Bayne (@bohops) द्वारा
- DotNet Core: A Vector For AWL Bypass & Defense Evasion
fsi.exe
- Nick Tyrer (@NickTyrer) द्वारा [राइट-अप: Jimmy Bayne (@bohops)]
- GitHub Gist: fsi.exe inline execution
- Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
fsiAnyCpu.exe
- Nick Tyrer (@NickTyrer) द्वारा fsi.exe inline execution के माध्यम से [राइट-अप: Jimmy Bayne (@bohops)]
- GitHub Gist: fsi.exe inline execution
- Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
infdefaultinstall.exe
- Kyle Hanslovan (@KyleHanslovan), Chris Bisnett (@chrisbisnett) द्वारा
- Evading Autoruns - DerbyCon 7.0
- RE: Evading Autoruns PoCs on Windows 10
InstallUtil.exe
- James Forshaw (@tiraniddo) द्वारा
- DG on Windows 10 S: Abusing InstallUtil
IntuneWindowsAgent.exe (Microsoft.Management.Services.IntuneWindowsAgent.exe)
- Kim Oppalfens (@TheWMIGuy) द्वारा
- Intune Windows Agent Bypass Explanation
kill.exe
- @hyp3rlinx द्वारा
- Microsoft Process Kill Utility "kill.exe" - SEH Buffer Overflow
microsoft.Workflow.Compiler.exe
- Matt Graeber (@mattifestation) द्वारा
- Arbitrary, Unsigned Code Execution Vector in Microsoft.Workflow.Compiler.exe
msbuild.exe
- Casey Smith (@subTee) द्वारा
- Bypassing Application Whitelisting using MSBuild.exe - Device Guard Example and Mitigations
mshta.exe
- अज्ञात द्वारा (दस्तावेज़ीकरण @conscioushacker द्वारा)
- Application Whitelisting Bypass: mshta.exe
powershellcustomhost.exe
- Lasse Trolle Borup (@TrolleBorup) द्वारा
- A simple Device Guard bypass
rcsi.exe
- Matt Nelson (@enigma0x3) द्वारा
- BYPASSING APPLICATION WHITELISTING BY USING RCSI.EXE
runscripthelper.exe
- Matt Graeber (@mattifestation) द्वारा
- Bypassing Application Whitelisting with runscripthelper.exe
texttransform.exe
- अज्ञात द्वारा
- TextTransformer - Tool Use Case [दस्तावेज़ीकरण Casey Smith (@_subTee) द्वारा]
- TextTransform Shellcode Injection Template [दस्तावेज़ीकरण Chris Sphen (@ConsciousHacker) द्वारा]
- Placeholder reference (coming soon)
visualuiaverifynative.exe
- Lee Christensen (@tifkin_) द्वारा [राइट-अप: Jimmy Bayne (@bohops)]
- Exploring the WDAC Microsoft Recommended Block Rules: VisualUiaVerifyNative
wfc.exe
windbg.exe
- Matt Graeber (@mattifestation) द्वारा
- Bypassing Application Whitelisting by using WinDbg/CDB as a Shellcode Runner