Poll Do you use Smart App Control? I know, not many of you!

Do you use Smart App Control? Why? Why not? WTF?


  • Total voters
    51
F

ForgottenSeer 97327

By "replaced" I did not mean worse. Both SAC and your setup "WDAC + ISG" cover slightly different attack surfaces.

"WDAC + ISG" is vulnerable to some popular attack vectors that SAC covers. These attack vectors have become more dangerous since the year 2023 due to some improvements in transferring MOTW from disk images (ISO, IMG, VHD, VHDX) to their content. Similar improvements will be applied soon to archives (7-Zip, Gz, and RAR). As we know, ISG and SmartScreen are vulnerable to the attack vector via benign/vulnerable EXE + malicious DLL, when the EXE has got MOTW. It is a very simplistic attack when EXE + DLL is contained in the disk image or archive.

SAC can be "bypassed" by some signed malware samples, that can be blocked by "WDAC + ISG".

WDAC without ISG is more comprehensive than SAC and "WDAC + ISG". So yes, Microsoft advises Administrators to use WDAC over SAC. Another reason is that SAC cannot use Managed Installer which automatically allows applications installed by a designated software distribution solution, such as Microsoft Configuration Manager (MEMCM) or Microsoft Intune. WDAC does have several convenient features for Administrators - SAC does not.

Both SAC and "WDAC + ISG" cannot be strong protection against targeted attacks and lateral movement, but can be good protection at home and small business.
The setup "WDAC + ISG" can be improved by blocking execution in folders where users download files from the Internet, and by blocking execution from removable drives.
Some links with real in the wild bypasses would substatiate your story.

For people unable to run SAC, WDAC-ISG is a great alternative
 
Last edited by a moderator:
  • Like
Reactions: Nevi and Andy Ful

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,458
Some links with real in the wild bypasses would substatiate your story.

I have seen this attack vector several times, for example:

1694994093359.png

Figure 6. Viewing ISO image with “show hidden files” enabled.​

In the most popular version, the attackers use shortcuts to run the benign/reputable EXE file. It is easy to change the shortcut icon, so it looks like a document, media file, etc. The intention of such an attack is not to bypass ISG (it is a side effect), but to bypass SmartScreen and fool AVs.
SAC can block such attacks in 2 ways:
  1. Before the year 2023, the malicious DLL could be blocked (if it was unsigned).​
  2. Since the year 2023, the shortcut can be blocked (if the disk image was downloaded from the Internet).​
Unfortunately, the MOTW improvements from the year 2023 work to the advantage of SAC but are not good for WDAC ISG.
Similar attacks can be performed via flash drives. It is also possible to use archives via CVE-2023-40477 vulnerability if the archiver applications are not updated.
 
Last edited:
F

ForgottenSeer 97327

Last time i tried using SAC it blocked some stuff like razer synapse so i did not bother with it

Nowadays its more mature, not blocking razer stuff anymore so im using SAC nowadays
Did you reinstall or use the registry hack trick to enable SAC again?
 
  • Like
Reactions: Moonhorse

Freki123

Level 16
Verified
Top Poster
Aug 10, 2013
753
Rofl SAC blocked starfield for me. Any takers: How many hundred thousands of this game has been sold :D ? My outlook account will consist of only fp reports for SAC till I get to annoyed and disable it :D
Untitled.jpg
 
  • HaHa
Reactions: Nevi and oldschool

oldschool

Level 84
Thread author
Verified
Top Poster
Well-known
Mar 29, 2018
7,577
Rofl SAC blocked starfield for me. Any takers: How many hundred thousands of this game has been sold :D ? My outlook account will consist of only fp reports for SAC till I get to annoyed and disable it :D
View attachment 278764
But my question is: was it blocked completely or was it still usable? Looks like the former according to your pic.
 
  • Like
Reactions: Freki123

Freki123

Level 16
Verified
Top Poster
Aug 10, 2013
753
But my question is: was it blocked completely or was it still usable? Looks like the former according to your pic.
Of course Smart *Irony tag of* AC blocked the whole exe and the game is not usable. MS allows people to be guinea pigs for their insider build why not offer them a button to test a exe? Funfact: Bethesda (the starfield company) was acquired by Microsoft. Either the reported fp from yesterday will result in solving the problem or I have to get rid of it sooner than thought.
Edit:
I disabled SAC.
Support wrote back they say it's not SAC on there part. Maybe I can file it again under another category they say. After some try and error (DISM repair and such) I gave up. Not in the mood to find out what the problem is when support say it's not SAC when my pc says SAC blocked...
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top