Open shmu26 opened 6 months ago
Yes, two LOLBins (WMIC.exe and wsl.exe) are blocked via WDAC policy by Microsoft's recommended rules.
Do you have any idea why cmd would spawn WMIC in normal computer usage of Windows 11? The only thing I regularly use cmd for is to shut down wsl, via the command wsl --shutdown
This is uncommon behavior. Probably some application tries to run a script. Did you look at the SWH Blocked events?
I got two blocks after enabling WDAC. The first one is wsl, which you already explained to me that it is blocked by design. But I have no idea where the second block is coming from.