cryps1s / DARKSURGEON

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.
https://darksurgeon.io
MIT License
463 stars 68 forks source link

Enable ASR. #28

Open cedws opened 6 years ago

cedws commented 6 years ago

Describe the solution you'd like Windows comes with a security feature named ASR (Attack Surface Reduction) which is a set of security restrictions that should be applied to various Microsoft software and the operating system. It doesn't look like this is enabled by default in Windows 10, but I might be wrong. I also could not find anything pertaining to it already in DARKSURGEON. See here for more info.

Thanks.

cedws commented 6 years ago

Oh, just saw in the README that "High security mode" is still under development. Looks like ASR will be enabled by this.

cryps1s commented 6 years ago

Thanks for the issue! Yep, it's definitely still in development and I absolutely intend to include ASR. I'll leave this issue open until I merge to master.