logo

Pauldotcom - Thwarting Client Side Attacks (and how to bypass)

ID: 5384c8d5-cac1-5876-a181-fef4f55e5956

STIX ID: report--5384c8d5-cac1-5876-a181-fef4f55e5956

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This post critiques a guide on using Software Restriction Policies to stop client-side attacks and provides a proof-of-concept Python script that attempts to bypass SRP by enumerating directories, copying or renaming whitelisted executables, and executing a backdoor; it also discusses limitations of PowerShell blocking and practical considerations for deploying SRP in corporate environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.