Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
UltimateWDACBypassList — これまでに文書化されたWDACバイパス手法の集中リソース | Kitploit
ツール/GitHubGitHub/bohops/ultimatewdacbypasslist
防御ツールエクスプロイト構成監査論文と研究学習と教育レッドチーミング厳選リソース
GitHubbohops/ultimatewdacbypasslist

UltimateWDACBypassList

これまでに文書化されたWDACバイパス手法の集中リソース

リポジトリを見る
631852713日前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

究極のWDACバイパスリスト

これまでに文書化されたWDAC/Device Guard/UMCIバイパス手法、およびWDACポリシーの構築/管理/テストのための集中リソース

  • 注: WDAC (Windows Defender Application Control) はMicrosoftによって「Application Control」または「Application Control for Business」に改名されました

*多くのLOLBINは、以前は「Microsoft推奨ブロックルールリスト」と呼ばれていたWDACをバイパスできるアプリケーションリストに含まれています

  • Pro Tip: ブロックルールポリシーを適用する場合、最初の2つのファイルルール ID_ALLOW_A_1 と ID_ALLOW_A_2 を削除することを忘れないでください

*このリポジトリはOddvar Moe氏のUltimate AppLocker Bypass Listに触発されました

*いつものように、これは進行中の作業です...


WDACをバイパスできるアプリケーション - 「LOLBIN」解説記事

addinprocess.exe

  • 著者: James Forshaw (@tiraniddo)
  • DG on Windows 10 S: Executing Arbitrary Code
    • https://www.tiraniddo.dev/2017/07/dg-on-windows-10-s-executing-arbitrary.html

addinprocess32.exe

  • 著者: James Forshaw (@tiraniddo)
  • DG on Windows 10 S: Executing Arbitrary Code
    • https://www.tiraniddo.dev/2017/07/dg-on-windows-10-s-executing-arbitrary.html

addinutil.exe

  • 著者: 不明 (文書化: @McKinleyMike および @TheLatteri)
  • Insecure Deserialization in AddinUtil.exe
    • https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html

aspnet_compiler.exe

  • 著者: cpl (@cpl3h)
  • The Curious Case of Aspnet_Compiler.exe
    • https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/

bginfo.exe

  • 著者: Oddvar Moe (@Oddvarmoe)
  • Bypassing Application Whitelisting with BGInfo
    • https://msitpros.com/?p=3831

cdb.exe

  • 著者: Matt Graeber (@mattifestation)
  • Bypassing Application Whitelisting by using WinDbg/CDB as a Shellcode Runner
    • http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html

csi.exe

  • 著者: Casey Smith (@subTee)
  • Application Whitelisting Bypass - CSI.EXE C# Scripting
    • https://web.archive.org/web/20161008143428/http://subt0x10.blogspot.com/2016/09/application-whitelisting-bypass-csiexe.html

dbghost.exe

  • 著者: Casey Smith (@subTee)
  • dbghost.exe - Ghost And The Darkness
    • https://web.archive.org/web/20170926164017/http://subt0x10.blogspot.com/2017/09/dbghostexe-ghost-in-darkness.html

dbgsrv.exe

  • 著者: Casey Smith (@subTee), Ross Wolf (@rw_access)
  • How to Bypass WDAC with dbgsrv.exe
    • https://fortynorthsecurity.com/blog/how-to-bypass-wdac-with-dbgsrv-exe/
  • Fantastic Red-Team Attacks and How to Find Them
    • https://i.blackhat.com/USA-19/Thursday/us-19-Smith-Fantastic-Red-Team-Attacks-And-How-To-Find-Them.pdf

dnx.exe

  • 著者: Matt Nelson (@enigma0x3)
  • BYPASSING APPLICATION WHITELISTING BY USING DNX.EXE
    • https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/

dotnet.exe

  • 著者: Jimmy Bayne (@bohops)
  • DotNet Core: A Vector For AWL Bypass & Defense Evasion
    • https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/

fsi.exe

  • 著者: Nick Tyrer (@NickTyrer) [解説: Jimmy Bayne (@bohops)]
  • GitHub Gist: fsi.exe inline execution
    • https://gist.github.com/NickTyrer/51eb8c774a909634fa69b4d06fc79ae1
    • https://twitter.com/NickTyrer/status/904273264385589248
  • Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
    • https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/

fsiAnyCpu.exe

  • 著者: Nick Tyrer (@NickTyrer) via fsi.exe inline execution [解説: Jimmy Bayne (@bohops)]
  • GitHub Gist: fsi.exe inline execution
    • https://gist.github.com/NickTyrer/51eb8c774a909634fa69b4d06fc79ae1
    • https://twitter.com/bohops/status/1319096336441090050
  • Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
    • https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/

infdefaultinstall.exe

  • 著者: Kyle Hanslovan (@KyleHanslovan), Chris Bisnett (@chrisbisnett)
  • Evading Autoruns - DerbyCon 7.0
    • https://github.com/huntresslabs/evading-autoruns
  • RE: Evading Autoruns PoCs on Windows 10
    • https://medium.com/@KyleHanslovan/re-evading-autoruns-pocs-on-windows-10-dd810d7e8a3f

InstallUtil.exe

  • 著者: James Forshaw (@tiraniddo)
  • DG on Windows 10 S: Abusing InstallUtil
    • https://www.tiraniddo.dev/2017/08/dg-on-windows-10-s-abusing-installutil.html

IntuneWindowsAgent.exe (Microsoft.Management.Services.IntuneWindowsAgent.exe)

  • 著者: Kim Oppalfens (@TheWMIGuy)
  • Intune Windows Agent Bypass Explanation
    • https://github.com/bohops/UltimateWDACBypassList/issues/1

kill.exe

  • 著者: @hyp3rlinx
  • Microsoft Process Kill Utility "kill.exe" - SEH Buffer Overflow
    • http://hyp3rlinx.altervista.org/advisories/MS-KILL-UTILITY-BUFFER-OVERFLOW.txt
    • https://twitter.com/bohops/status/1324563760967753730

microsoft.Workflow.Compiler.exe

  • 著者: Matt Graeber (@mattifestation)
  • Arbitrary, Unsigned Code Execution Vector in Microsoft.Workflow.Compiler.exe
    • https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb

msbuild.exe

  • 著者: Casey Smith (@subTee)
  • Bypassing Application Whitelisting using MSBuild.exe - Device Guard Example and Mitigations
    • https://web.archive.org/web/20160920161634/http://subt0x10.blogspot.com/2016/09/bypassing-application-whitelisting.html

mshta.exe

  • 著者: 不明 (文書化: @conscioushacker)
  • Application Whitelisting Bypass: mshta.exe
    • https://web.archive.org/web/20171118145940/http://blog.conscioushacker.io/index.php/2017/11/17/application-whitelisting-bypass-mshta-exe/

powershellcustomhost.exe

  • 著者: Lasse Trolle Borup (@TrolleBorup)
  • A simple Device Guard bypass
    • https://danishcyberdefence.dk/blog/device-guard-powershellcustomhost

rcsi.exe

  • 著者: Matt Nelson (@enigma0x3)
  • BYPASSING APPLICATION WHITELISTING BY USING RCSI.EXE
    • https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/

runscripthelper.exe

  • 著者: Matt Graeber (@mattifestation)
  • Bypassing Application Whitelisting with runscripthelper.exe
    • https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc

texttransform.exe

  • 著者: 不明
  • TextTransformer - Tool Use Case [文書化: Casey Smith (@_subTee)]
    • https://github.com/secdev02/TextTransformer
  • TextTransform Shellcode Injection Template [文書化: Chris Sphen (@ConsciousHacker)]
    • https://gist.github.com/ConsciousHacker/40dfd14b9ecefec49803c509712346a9
  • プレースホルダー参照 (近日公開)

visualuiaverifynative.exe

  • 著者: Lee Christensen (@tifkin_) [解説: Jimmy Bayne (@bohops)]
  • Exploring the WDAC Microsoft Recommended Block Rules: VisualUiaVerifyNative
    • https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/

wfc.exe

  • 情報提供: MSRC および Matt Graeber (@mattifestation) [解説: Jimmy Bayne (@bohops)]
  • Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
  • https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/

windbg.exe

  • 著者: Matt Graeber (@mattifestation)
  • Bypassing Application Whitelisting by using WinDbg/CDB as a Shellcode Runner
    • http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html

wmic.exe

  • 著者: Casey Smith (@subTee)
  • WMIC.EXE Whitelisting Bypass - Hacking with Style, Stylesheets
    • https://web.archive.org/web/20190814201250/https://subt0x11.blogspot.com/2018/04/wmicexe-whitelisting-bypass-hacking.html

WSLファミリー - bash.exe, lxrun.exe, wsl.exe, wslconfig.exe, wslhost.exe

  • 著者: Alex Ionescu (@aionescu)
  • Fun with the Windows Subsystem for Linux
    • https://github.com/ionescu007/lxss

ブロックリスト掲載 - まだ文書化されていない...

ツールをダウンロード