AppLocker

Trusted Folders

need administrator cmd

and tools from sysinternalsSuite

copy the binary to allowed directory. then run that binary.

Bypass with DLL

Alternate Data Stream

save this to shell.js

Find the TRUSTED FOLDER that able to W & X by current user

Execute the alternate data stream

Other technique

check third party script execution which is must be pre-installed in the compromised computer:

  • Python

Still Problem?

use this:

reference:

https://securitycafe.ro/2023/05/02/bypassing-application-whitelisting/

Last updated