Полный список обходов WDAC
Централизованный ресурс по ранее задокументированным техникам обхода WDAC/Device Guard/UMCI, а также для создания/управления/тестирования политик WDAC
- Примечание: WDAC (Windows Defender Application Control) был переименован Microsoft в "Application Control" или "Application Control for Business"
*Многие из LOLBIN включены в Applications that can bypass WDAC List, ранее называвшийся "Microsoft Recommended Block Rules List"
Pro Tip: Если применяете политику Block Rules, не забудьте удалить первые два правила для файлов: ID_ALLOW_A_1 и ID_ALLOW_A_2
*Этот репозиторий был вдохновлён Ultimate AppLocker Bypass List от Oddvar Moe
*Как всегда, это работа в процессе...
Приложения, которые могут обойти WDAC — разборы "LOLBIN"
addinprocess.exe
- Автор: James Forshaw (@tiraniddo)
- DG on Windows 10 S: Executing Arbitrary Code
addinprocess32.exe
- Автор: James Forshaw (@tiraniddo)
- DG on Windows 10 S: Executing Arbitrary Code
addinutil.exe
- Автор: Unknown (задокументировано @McKinleyMike и @TheLatteri)
- Insecure Deserialization in AddinUtil.exe
aspnet_compiler.exe
- Автор: cpl (@cpl3h)
- The Curious Case of Aspnet_Compiler.exe
bginfo.exe
- Автор: Oddvar Moe (@Oddvarmoe)
- Bypassing Application Whitelisting with BGInfo
cdb.exe
- Автор: Matt Graeber (@mattifestation)
- Bypassing Application Whitelisting by using WinDbg/CDB as a Shellcode Runner
csi.exe
- Автор: Casey Smith (@subTee)
- Application Whitelisting Bypass - CSI.EXE C# Scripting
dbghost.exe
- Автор: Casey Smith (@subTee)
- dbghost.exe - Ghost And The Darkness
dbgsrv.exe
- Автор: Casey Smith (@subTee), Ross Wolf (@rw_access)
- How to Bypass WDAC with dbgsrv.exe
- Fantastic Red-Team Attacks and How to Find Them
dnx.exe
- Автор: Matt Nelson (@enigma0x3)
- BYPASSING APPLICATION WHITELISTING BY USING DNX.EXE
dotnet.exe
- Автор: Jimmy Bayne (@bohops)
- DotNet Core: A Vector For AWL Bypass & Defense Evasion
fsi.exe
- Автор: Nick Tyrer (@NickTyrer) [разбор: Jimmy Bayne (@bohops)]
- GitHub Gist: fsi.exe inline execution
- Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
fsiAnyCpu.exe
- Автор: Nick Tyrer (@NickTyrer) через fsi.exe inline execution [разбор: Jimmy Bayne (@bohops)]
- GitHub Gist: fsi.exe inline execution
- Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
infdefaultinstall.exe
- Автор: Kyle Hanslovan (@KyleHanslovan), Chris Bisnett (@chrisbisnett)
- Evading Autoruns - DerbyCon 7.0
- RE: Evading Autoruns PoCs on Windows 10
InstallUtil.exe
- Автор: James Forshaw (@tiraniddo)
- DG on Windows 10 S: Abusing InstallUtil
IntuneWindowsAgent.exe (Microsoft.Management.Services.IntuneWindowsAgent.exe)
- Автор: Kim Oppalfens (@TheWMIGuy)
- Intune Windows Agent Bypass Explanation
kill.exe
- Автор: @hyp3rlinx
- Microsoft Process Kill Utility "kill.exe" - SEH Buffer Overflow
microsoft.Workflow.Compiler.exe
- Автор: Matt Graeber (@mattifestation)
- Arbitrary, Unsigned Code Execution Vector in Microsoft.Workflow.Compiler.exe
msbuild.exe
- Автор: Casey Smith (@subTee)
- Bypassing Application Whitelisting using MSBuild.exe - Device Guard Example and Mitigations
mshta.exe
- Автор: Unknown (задокументировано @conscioushacker)
- Application Whitelisting Bypass: mshta.exe
powershellcustomhost.exe
- Автор: Lasse Trolle Borup (@TrolleBorup)
- A simple Device Guard bypass
rcsi.exe
- Автор: Matt Nelson (@enigma0x3)
- BYPASSING APPLICATION WHITELISTING BY USING RCSI.EXE
runscripthelper.exe
- Автор: Matt Graeber (@mattifestation)
- Bypassing Application Whitelisting with runscripthelper.exe
texttransform.exe
- Автор: Unknown
- TextTransformer - Tool Use Case [задокументировано Casey Smith (@_subTee)]
- TextTransform Shellcode Injection Template [задокументировано Chris Sphen (@ConsciousHacker)]
- Placeholder reference (coming soon)
visualuiaverifynative.exe
- Автор: Lee Christensen (@tifkin_) [разбор: Jimmy Bayne (@bohops)]
- Exploring the WDAC Microsoft Recommended Block Rules: VisualUiaVerifyNative
wfc.exe
windbg.exe
- Автор: Matt Graeber (@mattifestation)
- Bypassing Application Whitelisting by using WinDbg/CDB as a Shellcode Runner