Pauldotcom - Thwarting Client Side Attacks (and how to bypass)
ID: 5384c8d5-cac1-5876-a181-fef4f55e5956
STIX ID: report--5384c8d5-cac1-5876-a181-fef4f55e5956
Feed Name: TrustedSec blog
Threat Score
This post critiques a guide on using Software Restriction Policies to stop client-side attacks and provides a proof-of-concept Python script that attempts to bypass SRP by enumerating directories, copying or renaming whitelisted executables, and executing a backdoor; it also discusses limitations of PowerShell blocking and practical considerations for deploying SRP in corporate environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
