终极 WDAC 绕过列表
一个集中资源,汇集了此前记录的 WDAC/Device Guard/UMCI 绕过技术,以及用于构建/管理/测试 WDAC 策略的资料
- 注意:WDAC(Windows Defender 应用程序控制)已被 Microsoft 更名为“应用程序控制”或“企业应用程序控制”
*许多 LOLBIN 都包含在可绕过 WDAC 的应用程序列表中,该列表以前称为“Microsoft 推荐阻止规则列表”
专业提示:如果应用阻止规则策略,别忘了删除前两条文件规则:ID_ALLOW_A_1 和 ID_ALLOW_A_2
*本仓库的灵感来自 Oddvar Moe 的 终极 AppLocker 绕过列表
*一如既往,这仍在不断完善中……
可绕过 WDAC 的应用程序 - “LOLBIN” 技术文章
addinprocess.exe
- 作者:James Forshaw (@tiraniddo)
- Windows 10 S 上的 DG:执行任意代码
addinprocess32.exe
- 作者:James Forshaw (@tiraniddo)
- Windows 10 S 上的 DG:执行任意代码
addinutil.exe
- 作者:未知(由 @McKinleyMike 和 @TheLatteri 记录)
- AddinUtil.exe 中的不安全反序列化
aspnet_compiler.exe
- 作者:cpl (@cpl3h)
- Aspnet_Compiler.exe 的奇特案例
bginfo.exe
- 作者:Oddvar Moe (@Oddvarmoe)
- 使用 BGInfo 绕过应用程序白名单
cdb.exe
- 作者:Matt Graeber (@mattifestation)
- 使用 WinDbg/CDB 作为 Shellcode 运行器绕过应用程序白名单
csi.exe
- 作者:Casey Smith (@subTee)
- 应用程序白名单绕过 - CSI.EXE C# 脚本
dbghost.exe
- 作者:Casey Smith (@subTee)
- dbghost.exe - 幽灵与黑暗
dbgsrv.exe
- 作者:Casey Smith (@subTee)、Ross Wolf (@rw_access)
- 如何使用 dbgsrv.exe 绕过 WDAC
- 精彩的红队攻击及如何发现它们
dnx.exe
- 作者:Matt Nelson (@enigma0x3)
- 使用 DNX.EXE 绕过应用程序白名单
dotnet.exe
- 作者:Jimmy Bayne (@bohops)
- DotNet Core:AWL 绕过与防御规避的载体
fsi.exe
- 作者:Nick Tyrer (@NickTyrer) [技术文章:Jimmy Bayne (@bohops)]
- GitHub Gist:fsi.exe 内联执行
- 探索 WDAC Microsoft 推荐阻止规则(第二部分):Wfc.exe、Fsi.exe 和 FsiAnyCpu.exe
fsiAnyCpu.exe
- 作者:Nick Tyrer (@NickTyrer),通过 fsi.exe 内联执行 [技术文章:Jimmy Bayne (@bohops)]
- GitHub Gist:fsi.exe 内联执行
- 探索 WDAC Microsoft 推荐阻止规则(第二部分):Wfc.exe、Fsi.exe 和 FsiAnyCpu.exe
infdefaultinstall.exe
- 作者:Kyle Hanslovan (@KyleHanslovan)、Chris Bisnett (@chrisbisnett)
- 规避 Autoruns - DerbyCon 7.0
- 回复:在 Windows 10 上规避 Autoruns PoC
InstallUtil.exe
- 作者:James Forshaw (@tiraniddo)
- Windows 10 S 上的 DG:滥用 InstallUtil
IntuneWindowsAgent.exe (Microsoft.Management.Services.IntuneWindowsAgent.exe)
- 作者:Kim Oppalfens (@TheWMIGuy)
- Intune Windows Agent 绕过说明
kill.exe
- 作者:@hyp3rlinx
- Microsoft 进程终止工具 “kill.exe” - SEH 缓冲区溢出
microsoft.Workflow.Compiler.exe
- 作者:Matt Graeber (@mattifestation)
- Microsoft.Workflow.Compiler.exe 中的任意未签名代码执行载体
msbuild.exe
- 作者:Casey Smith (@subTee)
- 使用 MSBuild.exe 绕过应用程序白名单 - Device Guard 示例与缓解措施
mshta.exe
- 作者:未知(由 @conscioushacker 记录)
- 应用程序白名单绕过:mshta.exe
powershellcustomhost.exe
- 作者:Lasse Trolle Borup (@TrolleBorup)
- 一个简单的 Device Guard 绕过
rcsi.exe
- 作者:Matt Nelson (@enigma0x3)
- 使用 RCSI.EXE 绕过应用程序白名单
runscripthelper.exe
- 作者:Matt Graeber (@mattifestation)
- 使用 runscripthelper.exe 绕过应用程序白名单
texttransform.exe
- 作者:未知
- TextTransformer - 工具用例 [由 Casey Smith (@_subTee) 记录]
- TextTransform Shellcode 注入模板 [由 Chris Sphen (@ConsciousHacker) 记录]
- 占位符参考(即将推出)
visualuiaverifynative.exe
- 作者:Lee Christensen (@tifkin_) [技术文章:Jimmy Bayne (@bohops)]
- 探索 WDAC Microsoft 推荐阻止规则:VisualUiaVerifyNative
wfc.exe
windbg.exe
- 作者:Matt Graeber (@mattifestation)
- 使用 WinDbg/CDB 作为 Shellcode 运行器绕过应用程序白名单
wmic.exe
- 作者:Casey Smith (@subTee)
- WMIC.EXE 白名单绕过 - 有风格的入侵,样式表
WSL 系列 - bash.exe、lxrun.exe、wsl.exe、wslconfig.exe、wslhost.exe
- 作者:Alex Ionescu (@aionescu)
- 玩转 Windows Subsystem for Linux
在阻止列表中 - 尚未记录……
- dbgsvc.exe
- kd.exe
- ntkd.exe
- ntsd.exe
- HVCIScan.exe
列表中的库(独立使用可能/可能不有趣)
- Microsoft.Build.dll
- Microsoft.Build.Framework.dll
- msbuild.dll
- lxssmanager.dll
- system.management.automation.dll
- webclnt.dll/davsvc.dll
- mfc40.dll
其他“未签名代码执行” LOLBIN/PowerShell(不在列表中)
texttransformcore.exe
microsoft.xsldebugger.host.exe
WinDbgX.exe
- 作者:Cerbersec (@cerbersec)
- 绕过 WDAC WinDbg 预览版
PSNativeCmdDevKit (PowerShell)
PowerShell