4 ms·
That is what Windows Defender Application Control does. It's probably the most cutting edge solution on the market actually. It's a pure whitelisting solution
by noinsight 6y ago
That is what Windows Defender Application Control does. It's probably the most cutting edge solution on the market actually.
It's a pure whitelisting solution where every single executable and kernel driver needs to have an approved digital signature or matching hash value or they won't be permitted to run.
It's virtualization assisted and can't be disabled without rebooting and if you use a digitally signed policy and someone tries to remove it, the machine will refuse to boot.
The coolest thing is, it even expands to the scripting languages built-in to Windows so PowerShell execution is restricted according to policy etc.
In practice of course, it's a big pain in the ass to manage - many software are not digitally signed etc.
Every single artifact of every program needs to be digitally signed or have a matching hash in the policy or they won't be permitted to run.
For example, suppose a software installer: the .msi itself is digitally signed so can easily be permitted to run... But then, during installation it unpacks an .exe into %temp% that isn't digitally signed and attempts to run that - oops, won't run. I've come across even Microsoft software that does this.
https://docs.microsoft.com/en-us/windows/security/threat-protection/device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control https://docs.microsoft.com/en-us/windows/security/threat-pro...
- sydd 6y agoHow does it handle scripts? E.g. my virus is a python script bundled with the known and clean python executable
- noinsight 6y agoIt doesn't. Python would need to add support for it. The built-in scripting languages do, PowerShell enters constrained language mode and IIRC something also happens to VBScript/JScript, haven't even looked at those.