22 Commits

Author SHA1 Message Date
Nicholas Brower
1ae3f0b230 Merged PR 4822: "msdate update (generated from most recent commit date)"
"msdate update (generated from most recent commit date)"
2017-12-05 22:36:05 +00:00
Matt Graeber
937db704b9 Adding runscripthelper.exe to the blacklist ruleset
Reference for the runscripthelper.exe bypass:
https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc

Also giving credit to Lee Christensen for his visualuiaverifynative.exe
bypass contribution.
2017-11-02 10:30:11 -07:00
Justin Hall
df69bf5c65 revised app control 2017-10-20 14:20:39 -07:00
Justin Hall
9c758d577f revised vbs steps 2017-10-11 15:58:37 -07:00
Justin Hall
ee1818e9dd replaced golden with reference 2017-10-11 11:04:24 -07:00
Justin Hall
27118c7115 added that only RSA is supported 2017-10-10 17:19:08 -07:00
Justin Hall
7d724f7979 added visualuiaverifynative.exe 2017-10-10 11:32:05 -07:00
Your Name
0f7ccbfe98 Fix typo 2017-10-10 10:17:41 -07:00
Your Name
4f8b3beca8 Updated deny rules 2017-10-10 10:02:53 -07:00
John Tobin
6376a76a3d Correct Cred Guard CI File Rule for KD_KMCI 2017-09-14 16:06:58 -07:00
John Tobin
ec31357472 Add dbghost and dbgsvc to block list 2017-09-14 09:59:08 -07:00
John Tobin
9e5d566b30 Re-branding for It-client Cred Guard/Device Guard/Remote CG/Firewall docs 2017-08-17 13:47:11 -07:00
Nick Landers
811657802e Update to include SyncAppVPublishingServer 2017-08-09 10:22:55 -06:00
Brian Lich
b21f821649 updating localizationpriority metadata name 2017-07-27 10:43:50 -07:00
John Tobin
58f4978b31 Update note on BGInfo to announce vulnerability fix 2017-07-25 14:23:29 -07:00
Elizabeth Ross
c5564b2179 Merge pull request #212 from enigma0x3/credit_fix
Updated to include Alex Ionescu credit
2017-06-28 16:19:27 -07:00
Matt Nelson
d12d7affec added ntkd debugger
kernel debugger, nearly identical to kd.exe
2017-06-28 11:18:18 -07:00
Matt Nelson
34e135859f Updated to include Alex Ionescu credit
Alex contributed to the bash.exe and lxssmanager.dll findings. Reference: https://twitter.com/aionescu/status/876226982534565889
2017-06-20 12:01:19 -04:00
Matt Nelson
2436f248fb Updated to include fsiAnyCpu.exe
Same as FSI.exe, has different fileName.
2017-06-20 11:07:09 -04:00
John Tobin
c304d1940f Revision to CI policies:steps 2017-06-16 09:50:20 -07:00
John Tobin
a0fe6b1c15 Add and remove content from Deploy CI policies:steps 2017-06-16 09:24:58 -07:00
Brian Lich
33c3fb2e74 New TOC for docs.microsoft.com 2017-04-19 14:12:47 -07:00