Forum Discussion
NitinRangannavar
Bronze I
2 months agoWindows Exploitation: Bypassing AppLocker Allowed Paths
Hello,
I need a assistance with a lab on Windows Exploitation: Bypassing AppLocker Allowed Paths . I have tried to clear this lab but I'm unable to run powershell.exe. I have tried to locate other installations of Powershell on the Windows Machine but even those executables within C:\Windows\WinSxS are getting blocked.
Please help me on this to crack down.
4 Replies
- barney
Bronze II
Don't overthink it. Check the path allowed rule - what's the name and location of the binary you can run?
- NitinRangannavar
Bronze I
I have tried everyway but cant get through this.
- barney
Bronze II
The path rule allows a binary called python.exe to run from the specified location - doesn't mean it actually has to be python.
Remember that you also have to bypass the publisher rule as well (in the same way as the hash rule bypass).