api0cradle / UltimateAppLockerByPassList

The goal of this repository is to document the most common techniques to bypass AppLocker.
1.91k stars 353 forks source link

Verified presentationhost.exe #9

Closed jpginc closed 6 years ago

jpginc commented 6 years ago

updating just the yaml file now :-)

I setup default applocker rules and verified that an xbap run from the file system (or any UNC path) can execute arbitrary c# code. I've added a link to a blog post with the steps to reproduce.

You can reproduce the bypass by cloning https://github.com/jpginc/xbapAppWhitelistBypassPOC and running the xbap in the /powershell/bin/Debug/ folder