Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
UltimateWDACBypassList — पूर्व में प्रलेखित WDAC बायपास तकनीकों के लिए एक केंद्रीकृत संसाधन | Kitploit
उपकरण/GitHubGitHub/bohops/ultimatewdacbypasslist
रक्षात्मक उपकरणशोषणकॉन्फ़िगरेशन ऑडिटिंगपेपर और शोधलर्निंग और शिक्षारेड टीमिंगचयनित संसाधन
GitHubbohops/ultimatewdacbypasslist

UltimateWDACBypassList

पूर्व में प्रलेखित WDAC बायपास तकनीकों के लिए एक केंद्रीकृत संसाधन

रिपॉजिटरी देखें
631852714 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

अल्टीमेट WDAC बायपास सूची

पहले से प्रलेखित WDAC/Device Guard/UMCI बायपास तकनीकों के साथ-साथ WDAC नीतियों के निर्माण/प्रबंधन/परीक्षण के लिए एक केंद्रीकृत संसाधन

  • नोट: WDAC (Windows Defender Application Control) को Microsoft द्वारा "Application Control" या "Application Control for Business" के रूप में पुनः ब्रांड किया गया है

*कई LOLBINs Applications that can bypass WDAC List में शामिल हैं, जिसे पहले "Microsoft Recommended Block Rules List" कहा जाता था

  • Pro Tip: यदि Block Rules नीति लागू कर रहे हैं, तो पहले दो फ़ाइल नियमों को हटाना न भूलें: ID_ALLOW_A_1 और ID_ALLOW_A_2

*यह रिपॉज़िटरी Oddvar Moe की Ultimate AppLocker Bypass List से प्रेरित है

*हमेशा की तरह, यह एक कार्य प्रगति पर है...


ऐसे एप्लिकेशन जो WDAC को बायपास कर सकते हैं - "LOLBIN" राइट-अप्स

addinprocess.exe

  • James Forshaw (@tiraniddo) द्वारा
  • DG on Windows 10 S: Executing Arbitrary Code
    • https://www.tiraniddo.dev/2017/07/dg-on-windows-10-s-executing-arbitrary.html

addinprocess32.exe

  • James Forshaw (@tiraniddo) द्वारा
  • DG on Windows 10 S: Executing Arbitrary Code
    • https://www.tiraniddo.dev/2017/07/dg-on-windows-10-s-executing-arbitrary.html

addinutil.exe

  • अज्ञात द्वारा (दस्तावेज़ीकरण @McKinleyMike और @TheLatteri द्वारा)
  • Insecure Deserialization in AddinUtil.exe
    • https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html

aspnet_compiler.exe

  • cpl (@cpl3h) द्वारा
  • The Curious Case of Aspnet_Compiler.exe
    • https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/

bginfo.exe

  • Oddvar Moe (@Oddvarmoe) द्वारा
  • Bypassing Application Whitelisting with BGInfo
    • https://msitpros.com/?p=3831

cdb.exe

  • Matt Graeber (@mattifestation) द्वारा
  • Bypassing Application Whitelisting by using WinDbg/CDB as a Shellcode Runner
    • http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html

csi.exe

  • Casey Smith (@subTee) द्वारा
  • Application Whitelisting Bypass - CSI.EXE C# Scripting
    • https://web.archive.org/web/20161008143428/http://subt0x10.blogspot.com/2016/09/application-whitelisting-bypass-csiexe.html

dbghost.exe

  • Casey Smith (@subTee) द्वारा
  • dbghost.exe - Ghost And The Darkness
    • https://web.archive.org/web/20170926164017/http://subt0x10.blogspot.com/2017/09/dbghostexe-ghost-in-darkness.html

dbgsrv.exe

  • Casey Smith (@subTee), Ross Wolf (@rw_access) द्वारा
  • How to Bypass WDAC with dbgsrv.exe
    • https://fortynorthsecurity.com/blog/how-to-bypass-wdac-with-dbgsrv-exe/
  • Fantastic Red-Team Attacks and How to Find Them
    • https://i.blackhat.com/USA-19/Thursday/us-19-Smith-Fantastic-Red-Team-Attacks-And-How-To-Find-Them.pdf

dnx.exe

  • Matt Nelson (@enigma0x3) द्वारा
  • BYPASSING APPLICATION WHITELISTING BY USING DNX.EXE
    • https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/

dotnet.exe

  • Jimmy Bayne (@bohops) द्वारा
  • DotNet Core: A Vector For AWL Bypass & Defense Evasion
    • https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/

fsi.exe

  • Nick Tyrer (@NickTyrer) द्वारा [राइट-अप: Jimmy Bayne (@bohops)]
  • GitHub Gist: fsi.exe inline execution
    • https://gist.github.com/NickTyrer/51eb8c774a909634fa69b4d06fc79ae1
    • https://twitter.com/NickTyrer/status/904273264385589248
  • Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
    • https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/

fsiAnyCpu.exe

  • Nick Tyrer (@NickTyrer) द्वारा fsi.exe inline execution के माध्यम से [राइट-अप: Jimmy Bayne (@bohops)]
  • GitHub Gist: fsi.exe inline execution
    • https://gist.github.com/NickTyrer/51eb8c774a909634fa69b4d06fc79ae1
    • https://twitter.com/bohops/status/1319096336441090050
  • Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
    • https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/

infdefaultinstall.exe

  • Kyle Hanslovan (@KyleHanslovan), Chris Bisnett (@chrisbisnett) द्वारा
  • Evading Autoruns - DerbyCon 7.0
    • https://github.com/huntresslabs/evading-autoruns
  • RE: Evading Autoruns PoCs on Windows 10
    • https://medium.com/@KyleHanslovan/re-evading-autoruns-pocs-on-windows-10-dd810d7e8a3f

InstallUtil.exe

  • James Forshaw (@tiraniddo) द्वारा
  • DG on Windows 10 S: Abusing InstallUtil
    • https://www.tiraniddo.dev/2017/08/dg-on-windows-10-s-abusing-installutil.html

IntuneWindowsAgent.exe (Microsoft.Management.Services.IntuneWindowsAgent.exe)

  • Kim Oppalfens (@TheWMIGuy) द्वारा
  • Intune Windows Agent Bypass Explanation
    • https://github.com/bohops/UltimateWDACBypassList/issues/1

kill.exe

  • @hyp3rlinx द्वारा
  • Microsoft Process Kill Utility "kill.exe" - SEH Buffer Overflow
    • http://hyp3rlinx.altervista.org/advisories/MS-KILL-UTILITY-BUFFER-OVERFLOW.txt
    • https://twitter.com/bohops/status/1324563760967753730

microsoft.Workflow.Compiler.exe

  • Matt Graeber (@mattifestation) द्वारा
  • Arbitrary, Unsigned Code Execution Vector in Microsoft.Workflow.Compiler.exe
    • https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb

msbuild.exe

  • Casey Smith (@subTee) द्वारा
  • Bypassing Application Whitelisting using MSBuild.exe - Device Guard Example and Mitigations
    • https://web.archive.org/web/20160920161634/http://subt0x10.blogspot.com/2016/09/bypassing-application-whitelisting.html

mshta.exe

  • अज्ञात द्वारा (दस्तावेज़ीकरण @conscioushacker द्वारा)
  • Application Whitelisting Bypass: mshta.exe
    • https://web.archive.org/web/20171118145940/http://blog.conscioushacker.io/index.php/2017/11/17/application-whitelisting-bypass-mshta-exe/

powershellcustomhost.exe

  • Lasse Trolle Borup (@TrolleBorup) द्वारा
  • A simple Device Guard bypass
    • https://danishcyberdefence.dk/blog/device-guard-powershellcustomhost

rcsi.exe

  • Matt Nelson (@enigma0x3) द्वारा
  • BYPASSING APPLICATION WHITELISTING BY USING RCSI.EXE
    • https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/

runscripthelper.exe

  • Matt Graeber (@mattifestation) द्वारा
  • Bypassing Application Whitelisting with runscripthelper.exe
    • https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc

texttransform.exe

  • अज्ञात द्वारा
  • TextTransformer - Tool Use Case [दस्तावेज़ीकरण Casey Smith (@_subTee) द्वारा]
    • https://github.com/secdev02/TextTransformer
  • TextTransform Shellcode Injection Template [दस्तावेज़ीकरण Chris Sphen (@ConsciousHacker) द्वारा]
    • https://gist.github.com/ConsciousHacker/40dfd14b9ecefec49803c509712346a9
  • Placeholder reference (coming soon)

visualuiaverifynative.exe

  • Lee Christensen (@tifkin_) द्वारा [राइट-अप: Jimmy Bayne (@bohops)]
  • Exploring the WDAC Microsoft Recommended Block Rules: VisualUiaVerifyNative
    • https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/

wfc.exe

  • MSRC और Matt Graeber (@mattifestation) द्वारा सुझाव [राइट-अप: Jimmy Bayne (@bohops)]
  • Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
  • https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/

windbg.exe

  • Matt Graeber (@mattifestation) द्वारा
  • Bypassing Application Whitelisting by using WinDbg/CDB as a Shellcode Runner
    • http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html
टूल डाउनलोड करें