Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

some case did not list #1

Open
wmliang opened this issue Feb 5, 2018 · 2 comments
Open

some case did not list #1

wmliang opened this issue Feb 5, 2018 · 2 comments
Assignees

Comments

@wmliang
Copy link

wmliang commented Feb 5, 2018

some case from https://pentestlab.blog did not list

https://pentestlab.blog/2017/06/12/applocker-bypass-file-extensions/
https://pentestlab.blog/2017/06/06/applocker-bypass-assembly-load/
https://pentestlab.blog/2017/05/22/applocker-bypass-weak-path-rules/
https://pentestlab.blog/2017/07/07/applocker-bypass-createrestrictedtoken/

does it mean they work against the non-default rules ?

@api0cradle
Copy link
Owner

Hi. Sorry for the late reply. I literally just noticed this message. I will look into the bypasses. The Ultimate AppLocker bypass list is a work in progress project and there certainly are bypasses that are not listet yet. Thanks for pointing these ones out. 👍

@api0cradle api0cradle self-assigned this Mar 6, 2018
@api0cradle
Copy link
Owner

https://pentestlab.blog/2017/06/12/applocker-bypass-file-extensions/ - I need to look into this further

https://pentestlab.blog/2017/06/06/applocker-bypass-assembly-load/ - Only works if Scripting rules are not applied.
https://pentestlab.blog/2017/05/22/applocker-bypass-weak-path-rules/ - Added this to the generic section
https://pentestlab.blog/2017/07/07/applocker-bypass-createrestrictedtoken/ - Patch is in most operating systems so I consider this very unlikely.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants