正在加载视频...

视频加载失败

Dismantling Smart App Control (And SmartScreen) - 4 new initial access techniques with no security warnings or popups - including LNK mark-of-the-web bypass with over 5 years of ITW use Article: POC: #rephijack #lnkstomping

21,052 次观看 • 1 年前 •via X (Twitter)

3 条评论

HotCakeX ✡︎ סגול 的头像
HotCakeX ✡︎ סגול1 年前

Few notes for readers 1) SAC is for home users, App control for Business is the enterprise ver 2) WDAC cannot be bypassed like this. 3) Using legit certificate to sign malware doesn't end up good for the person acquired the cert. 4) Windows has a lot more than 2 security layers

Squiblydoo 的头像
Squiblydoo1 年前

Thanks for calling out code signing certs. :) Would you mind uploading a compiled copy of rep-check? It just makes it a little more accessible.

Joe Desimone 的头像
Joe Desimone1 年前

done,

相关视频