Microsoft Store and WinGet: Security Risks for Corporate Environments
ID: 444619f4-e780-5a64-a3f3-b45faae5c162
STIX ID: report--444619f4-e780-5a64-a3f3-b45faae5c162
Feed Name: Black Hills Infosec Blog
This report explains how Microsoft Store and WinGet enable installation of dual-use utilities and interpreters that attackers or malicious employees can leverage for remote access, credential theft, lateral movement, and covert tunneling (examples: Quick Assist, DBeaver/xp_dirtree, Sysinternals, Dev Tunnel). It highlights abuse scenarios, demonstrates attack workflows, and recommends blocking Store/WinGet and enforcing application control to prevent unauthorized installation and execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
