redcanaryco / surveyor

A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.
MIT License
170 stars 59 forks source link

Create vuln-drivers.json #61

Open pmichaudrc opened 2 years ago

pmichaudrc commented 2 years ago

Based off of Microsoft's recommended driver block list for WDAC https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules

rc-abodkins commented 1 year ago

This leverages the key hash which is not yet supported in Surveyor. Support for that needs to be included in Surveyor before this PR can be merged.