windows security
13 TopicsTurn on Memory Integrity through Microsoft Intune
Hi, Question: How to turn on the following setting through Microsoft Intune? Windows Security > Device Security > Core isolation > Memory Integrity (It says: Memory integrity is off. Your device may be vulnerable.) Applied licenses: Microsoft Intune Suite + Microsoft Defender for Endpoint P2 Client OS: Windows 11 It has been weeks since I already applied the following through the Security Baseline Policy for Windows 10 and Later but still the Memory Integrity has not got enabled on any client: Device Guard Credential Guard: (Enabled with UEFI lock): Turns on Credential Guard with UEFI lock. Enable Virtualization Based Security: enable virtualization based security. Require Platform Security Features: Turns on VBS with Secure Boot and direct memory access (DMA). ------ Virtualization Based Technology Hypervisor Enforced Code Integrity: (Enabled with UEFI lock) Turns on Hypervisor-Protected Code Integrity with UEFI lock. The Windows Baseline Security has got applied successfully on all endpoints without any errors or conflicts. Intune Sync and device restart have been performed 100s of times but in vain. Any suggestions would be highly appreciated.52Views0likes0CommentsControl Flow Guard caused tasks to suspend on launch
I've been tracking down the cause of a really troubling problem that started 5-6 x64 canary releases ago: running some executables would lead to a delay of 20-30 seconds before the application would actually launch. Discovered they were starting but immediately going into a suspended state (viewable in Task Manager) for up to 30 seconds, then they would appear on the screen and function normally. An example is Notepad++. I could repro the issue on demand by launching the app and then terminating it and then executing again a few times in rapid succession. Disabling Control Flow Guard (CFG) in Windows Security, App & Browser, Exploit Protection seems to resolve the issue. Reported in feedback, where there were about two other reports of similar behavior. Anybody else seeing issues with CFG ?40Views1like1CommentWindows 11 Dynamic Lock Unstable
Dynamic Lock in Windows 11 is unstable. Even when phone is connected to PC via Bluetooth, Dynamic Lock says it can't detect your phone. This screenshot shows: my phone is connected but dynamic lock shows not detected. Sometimes it works if I press the Scan for Phone option manually. But its not intended to work like that.593Views0likes2CommentsWindows Security Real Time Protection can't be enabled
I am currently running Windows 11 Pro Insider Preview 23H2. I tried enabling real time protection in registry by settling real time protection key to 0, I tried to set not configured for real time protection in Local Policy Group, I have alo tried enabling it using Command prompt. However, none of the steps worked. Real time protection is still off and cannot be enabled. It just keeps on toggling off even when manually toggling it to on. I do hope that next Windows Updte would have a fix to this issue.629Views0likes1CommentWindows Unquoted Service Path Enumeration - Is this still a case in modern Windows (10, 11) ?
Hi Folks, This could be irrelevant as the issue goes back to few years and Microsoft may have already fixed it but, just wanted verify/confirm. Windows Unquoted Path Enumeration vulnerability was identified back in 2013 (or may be even earlier). In simple terms, when a service is created whose executable path contains spaces and isn’t enclosed within quotes, leads to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges (only if the vulnerable service is running with SYSTEM privilege level which most of the time it is).In Windows, if the service is not enclosed within quotes and is having spaces, it would handle the space as a break and pass the rest of the service path as an argument. Ref -https://medium.com/@SumitVerma101/windows-privilege-escalation-part-1-unquoted-service-path-c7a011a8d8ae So my question is, is this still a vulnerability in the modern versions of Windows 10,11? Appreciate any inputs/recommendations!Solved106KViews0likes5CommentsWindows security malware removal problem
Windows version:Windows 11 Insider Preview 25276.1000 (rs_prerelease) Security version:Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.381.2181.0) Windows security detected malware (VirTool:Win32/DefenderTamperingRestore) on my device; I pressed the delete button, but it failed and kept showing the alarm and an "x" on the Windows security icon. The video that shows the bug https://1drv.ms/v/s!AjBLY6cOGwhTlLtAcqdrV7zkkuuEpA?e=lkdKVS1.8KViews1like2CommentsIs there a way to PERMANENTLY disable Windows Defender withOUT installing a third party AV?
Even when real time scanning is off, Windows Defender consumes about third of 1GB of RAM. This coupled with other "essential (bloatware) like Edgewebview2 which Microsoft proponents argue it's an essential service but many of us don't need or use these "essential" services especially when they are infested with adware like Widgets can really slow down a PC.10KViews0likes7Comments