PowerShell ScriptBlock Logging Bypass

Discussion in 'other security issues & news' started by hdwydgw534, Nov 17, 2017.

  1. guest

    guest Guest

    Read more here

    so red teams/hackers have still some time to play with powershell :p
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Hopefully, attackers will take note of the following to fully "cover their tracks" when employing the bypasses :-*:
     
  3. guest

    guest Guest

    lol sure they will take note... :p

    if you knew all the Windows' bypasses i read about lately...even an researcher showing that ASLR was better implemented on Win7 than the one in Win10's Exploit Guard...o_O
     
  4. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Nothing really new in that regard. Exploit Guard is just a "re-bagged" version of EMET built into WIN CEF. EMET has been bypassed multiple times in the past.
     
  5. guest

    guest Guest

  6. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    As noted there:
    It is disabled by default in Win 10 CFE.

    Then there is the question of if it is really needed. Viewing my active processes in Process Explorer, ASLR is enabled for almost all processes except an old third party USB 3.0 driver and likewise Realtek audio manager process. Also almost if not all drivers in Win 10 are kernel mode drivers. As such they are protected by Patchguard.
     
  7. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Appears the .reg key patch needs to be applied after all.

    Although system-wide Mandatory ASLR is disabled by default in main WD Security Center GUI, it is enabled in a number of individual Windows apps such as IE11 and I assume Edge to name a few.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.