windows 10
9 TopicsWDAC How to allow .tmp.node file by Electron app?
Hi all, I'm facing an issue with .tmp.node file that executed by an application called Ledger Live and written by Electron. This application generated a temporary file with random filename in user's Temp folder and then executed. I tried to allow the application's folder (C:\Program Files\Ledger Live\*) and even whitelist *.tmp.node in the WDAC policy XML. But the WDAC was still blocked this .temp.node file execute as the below screenshot. Is there a way to allow it to run or skip the Enterprise signing level check? Thanks.2.6KViews0likes2CommentsWindows Unquoted Service Path Enumeration - Is this still a case in modern Windows (10, 11) ?
Hi Folks, This could be irrelevant as the issue goes back to few years and Microsoft may have already fixed it but, just wanted verify/confirm. Windows Unquoted Path Enumeration vulnerability was identified back in 2013 (or may be even earlier). In simple terms, when a service is created whose executable path contains spaces and isn’t enclosed within quotes, leads to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges (only if the vulnerable service is running with SYSTEM privilege level which most of the time it is). In Windows, if the service is not enclosed within quotes and is having spaces, it would handle the space as a break and pass the rest of the service path as an argument. Ref - https://medium.com/@SumitVerma101/windows-privilege-escalation-part-1-unquoted-service-path-c7a011a8d8ae So my question is, is this still a vulnerability in the modern versions of Windows 10,11? Appreciate any inputs/recommendations!Solved111KViews0likes5CommentsLocal Administrator Password Solution locks my domain administrator
Hi everyone, We deployed LAPS in our environment, I installed the management on our domain controller. My problem is, if I need to login to a managed computer with the local administrator it locks my domain administrator account... I don't understand why. Googling this didn't help me. Can anyone help? Rahamim.782Views0likes0CommentsIntune Bitlocker for USB/external drive (Missing policy for Azure AD Join scenario)
When we enable intune policy: Block write access to devices configured in another organization in Intune Bitlocker policy We also need to deploy an Onprem GPO policy: Provide unique identifier for your organization. This will allow the PC to differentiate the Org it belongs to. GPO policy: Provide unique identifier for your organization is missing in Intune. Because of this we cannot use Intune policy: Block write access to devices configured in another organization. Looking for suggestions how we implement Block write access to devices configured in another organization in Intune for Azure AD Join (not hybrid domain join)?1.2KViews0likes0CommentsWhy is MsMpEng.exe still scanning excluded directories
THe MsMpEng.exe process is very active in our environment. Checking with Process Monitor filtered on MsMpEng.exe i can see it is very busy scanning my ISO directory, but i have excluded that directory in real-time scanning in Defender long ago. Why is it still scanning that directory, and i see many others i excluded it is also scanning? Will Azure Intune rules overwrite local configurations? if so wouldn't it gray them out? I am able to set exclusions.3.2KViews1like1CommentRun a windows defender scan in windows 10 using POWERSHELL
Folks, Windows 10 by default doesnt have periodic scanning enabled, to enable that i have to toggle the switch then i am able to scan. I am looking for a powershell command that can flip this on and another command to get scan results once the scan is finished.3.5KViews0likes1Commentwindow security
hi, I have just tried to open a file which I previously encrypted some months ago and for the first time I thought a message saying. I am operating with W10. "Está cerrando un archivo o tener acceso a Un archivo cifrado usando una tarjeta inteligente. Escriba el pin de su tarjeta inteligente"1.3KViews0likes1Commentfeature request: Windows Defender Antivirus - add "scan running processes"
feature request: Windows Defender Antivirus - add "scan running processes" scan for dead/multiple or dangerous processes or clean memory... most virus scanners only check files on drive, not running processes within memory.. and maybe add a rule to block a dangerous process.. André2.5KViews0likes1Comment