Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
UltimateWDACBypassList — 一个集中收录此前已记录的 WDAC 绕过技术的资源 | Kitploit
工具/GitHubGitHub/bohops/ultimatewdacbypasslist
防御工具漏洞利用配置审计论文与研究学习与教育红队精选资源
GitHubbohops/ultimatewdacbypasslist

UltimateWDACBypassList

一个集中收录此前已记录的 WDAC 绕过技术的资源

查看仓库
631852713天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

终极 WDAC 绕过列表

一个集中资源,汇集了此前记录的 WDAC/Device Guard/UMCI 绕过技术,以及用于构建/管理/测试 WDAC 策略的资料

  • 注意:WDAC(Windows Defender 应用程序控制)已被 Microsoft 更名为“应用程序控制”或“企业应用程序控制”

*许多 LOLBIN 都包含在可绕过 WDAC 的应用程序列表中,该列表以前称为“Microsoft 推荐阻止规则列表”

  • 专业提示:如果应用阻止规则策略,别忘了删除前两条文件规则:ID_ALLOW_A_1 和 ID_ALLOW_A_2

*本仓库的灵感来自 Oddvar Moe 的 终极 AppLocker 绕过列表

*一如既往,这仍在不断完善中……


可绕过 WDAC 的应用程序 - “LOLBIN” 技术文章

addinprocess.exe

  • 作者:James Forshaw (@tiraniddo)
  • Windows 10 S 上的 DG:执行任意代码
    • https://www.tiraniddo.dev/2017/07/dg-on-windows-10-s-executing-arbitrary.html

addinprocess32.exe

  • 作者:James Forshaw (@tiraniddo)
  • Windows 10 S 上的 DG:执行任意代码
    • https://www.tiraniddo.dev/2017/07/dg-on-windows-10-s-executing-arbitrary.html

addinutil.exe

  • 作者:未知(由 @McKinleyMike 和 @TheLatteri 记录)
  • AddinUtil.exe 中的不安全反序列化
    • https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html

aspnet_compiler.exe

  • 作者:cpl (@cpl3h)
  • Aspnet_Compiler.exe 的奇特案例
    • https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/

bginfo.exe

  • 作者:Oddvar Moe (@Oddvarmoe)
  • 使用 BGInfo 绕过应用程序白名单
    • https://msitpros.com/?p=3831

cdb.exe

  • 作者:Matt Graeber (@mattifestation)
  • 使用 WinDbg/CDB 作为 Shellcode 运行器绕过应用程序白名单
    • http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html

csi.exe

  • 作者:Casey Smith (@subTee)
  • 应用程序白名单绕过 - CSI.EXE C# 脚本
    • https://web.archive.org/web/20161008143428/http://subt0x10.blogspot.com/2016/09/application-whitelisting-bypass-csiexe.html

dbghost.exe

  • 作者:Casey Smith (@subTee)
  • dbghost.exe - 幽灵与黑暗
    • https://web.archive.org/web/20170926164017/http://subt0x10.blogspot.com/2017/09/dbghostexe-ghost-in-darkness.html

dbgsrv.exe

  • 作者:Casey Smith (@subTee)、Ross Wolf (@rw_access)
  • 如何使用 dbgsrv.exe 绕过 WDAC
    • https://fortynorthsecurity.com/blog/how-to-bypass-wdac-with-dbgsrv-exe/
  • 精彩的红队攻击及如何发现它们
    • https://i.blackhat.com/USA-19/Thursday/us-19-Smith-Fantastic-Red-Team-Attacks-And-How-To-Find-Them.pdf

dnx.exe

  • 作者:Matt Nelson (@enigma0x3)
  • 使用 DNX.EXE 绕过应用程序白名单
    • https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/

dotnet.exe

  • 作者:Jimmy Bayne (@bohops)
  • DotNet Core:AWL 绕过与防御规避的载体
    • https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/

fsi.exe

  • 作者:Nick Tyrer (@NickTyrer) [技术文章:Jimmy Bayne (@bohops)]
  • GitHub Gist:fsi.exe 内联执行
    • https://gist.github.com/NickTyrer/51eb8c774a909634fa69b4d06fc79ae1
    • https://twitter.com/NickTyrer/status/904273264385589248
  • 探索 WDAC Microsoft 推荐阻止规则(第二部分):Wfc.exe、Fsi.exe 和 FsiAnyCpu.exe
    • https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/

fsiAnyCpu.exe

  • 作者:Nick Tyrer (@NickTyrer),通过 fsi.exe 内联执行 [技术文章:Jimmy Bayne (@bohops)]
  • GitHub Gist:fsi.exe 内联执行
    • https://gist.github.com/NickTyrer/51eb8c774a909634fa69b4d06fc79ae1
    • https://twitter.com/bohops/status/1319096336441090050
  • 探索 WDAC Microsoft 推荐阻止规则(第二部分):Wfc.exe、Fsi.exe 和 FsiAnyCpu.exe
    • https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/

infdefaultinstall.exe

  • 作者:Kyle Hanslovan (@KyleHanslovan)、Chris Bisnett (@chrisbisnett)
  • 规避 Autoruns - DerbyCon 7.0
    • https://github.com/huntresslabs/evading-autoruns
  • 回复:在 Windows 10 上规避 Autoruns PoC
    • https://medium.com/@KyleHanslovan/re-evading-autoruns-pocs-on-windows-10-dd810d7e8a3f

InstallUtil.exe

  • 作者:James Forshaw (@tiraniddo)
  • Windows 10 S 上的 DG:滥用 InstallUtil
    • https://www.tiraniddo.dev/2017/08/dg-on-windows-10-s-abusing-installutil.html

IntuneWindowsAgent.exe (Microsoft.Management.Services.IntuneWindowsAgent.exe)

  • 作者:Kim Oppalfens (@TheWMIGuy)
  • Intune Windows Agent 绕过说明
    • https://github.com/bohops/UltimateWDACBypassList/issues/1

kill.exe

  • 作者:@hyp3rlinx
  • Microsoft 进程终止工具 “kill.exe” - SEH 缓冲区溢出
    • http://hyp3rlinx.altervista.org/advisories/MS-KILL-UTILITY-BUFFER-OVERFLOW.txt
    • https://twitter.com/bohops/status/1324563760967753730

microsoft.Workflow.Compiler.exe

  • 作者:Matt Graeber (@mattifestation)
  • Microsoft.Workflow.Compiler.exe 中的任意未签名代码执行载体
    • https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb

msbuild.exe

  • 作者:Casey Smith (@subTee)
  • 使用 MSBuild.exe 绕过应用程序白名单 - Device Guard 示例与缓解措施
    • https://web.archive.org/web/20160920161634/http://subt0x10.blogspot.com/2016/09/bypassing-application-whitelisting.html

mshta.exe

  • 作者:未知(由 @conscioushacker 记录)
  • 应用程序白名单绕过:mshta.exe
    • https://web.archive.org/web/20171118145940/http://blog.conscioushacker.io/index.php/2017/11/17/application-whitelisting-bypass-mshta-exe/

powershellcustomhost.exe

  • 作者:Lasse Trolle Borup (@TrolleBorup)
  • 一个简单的 Device Guard 绕过
    • https://danishcyberdefence.dk/blog/device-guard-powershellcustomhost

rcsi.exe

  • 作者:Matt Nelson (@enigma0x3)
  • 使用 RCSI.EXE 绕过应用程序白名单
    • https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/

runscripthelper.exe

  • 作者:Matt Graeber (@mattifestation)
  • 使用 runscripthelper.exe 绕过应用程序白名单
    • https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc

texttransform.exe

  • 作者:未知
  • TextTransformer - 工具用例 [由 Casey Smith (@_subTee) 记录]
    • https://github.com/secdev02/TextTransformer
  • TextTransform Shellcode 注入模板 [由 Chris Sphen (@ConsciousHacker) 记录]
    • https://gist.github.com/ConsciousHacker/40dfd14b9ecefec49803c509712346a9
  • 占位符参考(即将推出)

visualuiaverifynative.exe

  • 作者:Lee Christensen (@tifkin_) [技术文章:Jimmy Bayne (@bohops)]
  • 探索 WDAC Microsoft 推荐阻止规则:VisualUiaVerifyNative
    • https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/

wfc.exe

  • 由 MSRC 和 Matt Graeber (@mattifestation) 提供线索 [技术文章:Jimmy Bayne (@bohops)]
  • 探索 WDAC Microsoft 推荐阻止规则(第二部分):Wfc.exe、Fsi.exe 和 FsiAnyCpu.exe
  • https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/

windbg.exe

  • 作者:Matt Graeber (@mattifestation)
  • 使用 WinDbg/CDB 作为 Shellcode 运行器绕过应用程序白名单
    • http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html

wmic.exe

  • 作者:Casey Smith (@subTee)
  • WMIC.EXE 白名单绕过 - 有风格的入侵,样式表
    • https://web.archive.org/web/20190814201250/https://subt0x11.blogspot.com/2018/04/wmicexe-whitelisting-bypass-hacking.html

WSL 系列 - bash.exe、lxrun.exe、wsl.exe、wslconfig.exe、wslhost.exe

  • 作者:Alex Ionescu (@aionescu)
  • 玩转 Windows Subsystem for Linux
    • https://github.com/ionescu007/lxss

在阻止列表中 - 尚未记录……

  • dbgsvc.exe
  • kd.exe
  • ntkd.exe
  • ntsd.exe
  • HVCIScan.exe

列表中的库(独立使用可能/可能不有趣)

  • Microsoft.Build.dll
  • Microsoft.Build.Framework.dll
  • msbuild.dll
  • lxssmanager.dll
  • system.management.automation.dll
  • webclnt.dll/davsvc.dll
  • mfc40.dll

其他“未签名代码执行” LOLBIN/PowerShell(不在列表中)

texttransformcore.exe

  • https://github.com/LOLBAS-Project/LOLBAS/pull/496(即将推出)

microsoft.xsldebugger.host.exe

  • https://github.com/LOLBAS-Project/LOLBAS/pull/496(即将推出)

WinDbgX.exe

  • 作者:Cerbersec (@cerbersec)
  • 绕过 WDAC WinDbg 预览版
    • https://cerbersec.com/2025/04/07/bypass-wdac-windbg-preview.html

PSNativeCmdDevKit (PowerShell)

  • 作者:Matt Nelson (@enigma0x3)
  • https://gist.github.com/enigma0x3/22d6fc84956f154faf338966cd6d9bb0
  • https://x.com/enigma0x3/status/2100628652664787319

PowerShell

下载工具