D
D
Dmitry2020-04-14 15:30:22
Windows
Dmitry, 2020-04-14 15:30:22

How to create a whitelist for booting OS Windows 10 / 2016+?

Good afternoon,
tell me how you can make a list of trusted files (of the OS itself) and boot / work on it?
Throw articles or who did share experience.

Answer the question

In order to leave comments, you need to log in

4 answer(s)
K
Karpion, 2020-04-14
@Karpion

Explain the problem - where do files that can not be downloaded come from. And where to download?

D
Dmitry, 2020-04-16
@Gladspir

Scripts, actions of persons, modification of files involved in the operation of the OS.
OS somehow determines what it needs to work?

M
Maxim Yaroshevich, 2020-04-23
@YMax

The task is not clear. Protection of system files is in the system "out of the box" - why fence the garden?

A
Alex, 2020-05-11
@asilonos

you can decide from the reverse - enable protection for the creation / modification of executable files at the driver level. StaffCounter DLP has such a feature (for a fee). In this case, it is impossible to create \ copy \ save new EXE DLL SYS OCX on the disk, etc. all with PE header. (and Windows stops updating because the DLP module does not allow writing PE header ). In general, there will be no new binaries.
+ You also need to "cut" the PowerShell engine by hand yourself.
Theoretically, a dropper can live in memory for a long time and try to save a Packed Payload to disk, and only some script can run it. Well, either if this is a new type of malware that works exclusively in memory - in this case, there are no options for protection by ensuring the Integrity of the OS\Files.
Correct me if I missed something).

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question