New Update Smart App Control - Windows 11 22H2 feature promises significant protection from malware

Microsoft Defender
225 Replies 49,173 Views
Can you live with blocked the main program for productivity (your bread and butter)?

The main problem can be when using unsigned & non-prevalent applications. However, in most cases, there are as good but signed & prevalent alternatives. Of course, SAC can be useless for many users, too.
One can also submit files to Microsoft:

1760199558756.png
 
SAC​
WDAC​
False positive block: +​
False positive block: +++​
Cloud whitelisting: More rapid​
Cloud whitelisting: More slow​
Bypassed by lack of MoTW for LNK and Reg files, and scripts: Yes​
Bypassed by lack of MoTW for LNK and Reg files: No​
Bypassed by SmartScreen: No​
Bypassed by SmartScreen: Yes​
Script block: strict​
Script block: less strict (constrained language mode)​
Exclusions: No​
Exclusions: Yes​
OS impact: +​
OS impact: ++​
 
​
SAC​
WDAC​
False positive block: +​
False positive block: +++​
Cloud whitelisting: More rapid​
Cloud whitelisting: More slow​
Bypassed by lack of MoTW for LNK and Reg files, and scripts: Yes​
Bypassed by lack of MoTW for LNK and Reg files: No​
Bypassed by SmartScreen: No​
Bypassed by SmartScreen: Yes​
Script block: strict​
Script block: less strict (constrained language mode)​
Exclusions: No​
Exclusions: Yes​
OS impact: +​
OS impact: ++​

Some positions are incorrect.
SAC can block many file types (like .reg, .lnk, .chm, .iso, etc.) via MotW, and those files are not blocked by WDAC at all (even with MotW).
Both SAC and WDAC, with the ISG option, primarily allow unsigned files with a good SmartScreen reputation. Additionally, SAC permits signed files with an unknown SmartScreen reputation.
 
Both SAC and WDAC, with the ISG option, primarily allow unsigned files with a good SmartScreen reputation
I have faced files unsigned files with a good SmartScreen reputation blocked by WDAC if unblocked (removed motw) before execution; both are unpredictable; it is hit and try until you know which one will pass.
 
I have faced files unsigned files with a good SmartScreen reputation blocked by WDAC if unblocked (removed motw) before execution; both are unpredictable; it is hit and try until you know which one will pass.

I referred to those two entries SAC vs. WDAC:
Bypassed by SmartScreen: NoBypassed by SmartScreen: Yes

This category is incorrect because SAC and WDAC use SmartScreen reputation differently.
SAC most probably uses positive SmartScreen reputation even when EXE/MSI files have no MotW, but only for unsigned files. Signed EXE/MSI files with unknown reputation in SmartScreen and ISG are allowed.
WDAC ISG uses SmartScreen reputation only when EXE/MSI files (signed and unsigned) have MotW.
 
Just manually remove motw (unblock) and SAC will allow to pass, even reg files modifying Windows explorer context menu.

Yes. That is how it works for such files. However, WDAC totally ignores such files (with or without MotW).
WDAC and SAC work differently. SAC is designed to protect home users.
 
I referred to those two entries SAC vs. WDAC:
​
Bypassed by SmartScreen: NoBypassed by SmartScreen: Yes


This category is incorrect because SAC and WDAC use SmartScreen reputation differently.
SAC most probably uses positive SmartScreen reputation even when EXE/MSI files have no MotW, but only for unsigned files. Signed EXE/MSI files with unknown reputation in SmartScreen and ISG are allowed.
WDAC ISG uses SmartScreen reputation only when EXE/MSI files (signed and unsigned) have MotW.
"Bypassed by SmartScreen: Yes" for WDAC means, as you already know of course, if I try to execute a file after removing motw, WDAC blocks it, but if I try execution without removing motw, it executes, because motw provoked smartscreen which allowed it, and consequently WDAC did not block.
 
Yes. That is how it works for such files. However, WDAC totally ignores such files (with or without MotW).
WDAC and SAC work differently. SAC is designed to protect home users.
so only SAC is bypassable regarding those files, as WDAC does not deal with, and removing motw does not make a difference (no bypassable) 🙂
 
Yes. SAC is sometimes bypassable, and WDAC does not protect against those files.
I do not find it a bad feature, on the contrary, it may be considered as a partial "exclusion" feature which SAC lacks compared to WDAC.
As long as all donwloaded files have MoTW, then removing it manually is not bad, as malware cannot do that, or it can?
 
I do not find it a bad feature, on the contrary, it may be considered as a partial "exclusion" feature which SAC lacks compared to WDAC.

WDAC "automatically makes exclusions" for such files.:)

As long as all donwloaded files have MoTW, then removing it manually is not bad, as malware cannot do that, or it can?

Yes and No.
It is not bad, because many web-based attacks can be prevented. Such attacks mainly start from files with MotW.
However, if you run a signed EXE malware with an unknown reputation, it can download script payloads with no MotW, and SAC will not block either the EXE malware or the script payloads.
 
WDAC "automatically makes exclusions" for such files.:)



Yes and No.
It is not bad, because many web-based attacks can be prevented. Such attacks mainly start from files with MotW.
However, if you run a signed EXE malware with an unknown reputation, it can download script payloads with no MotW, and SAC will not block either the EXE malware or the script payloads.
Of course I will not remove motw except when dead sure the file is safe; previously SAC was blocking 7-zip exe downloaded from the official website; it is not smart all the time.
 

The article is slightly outdated, although it still contains some useful information. We also talked about this here:

If the attacker wants to bypass SAC, it will be bypassed. However, most of the techniques used in non-targeted attacks are covered.
The simplest bypass is using signed FUD.
 
The article is slightly outdated, although it still contains some useful information. We also talked about this here:

If the attacker wants to bypass SAC, it will be bypassed. However, most of the techniques used in non-targeted attacks are covered.
The simplest bypass is using signed FUD.
SAC has two blind spots, signature and MotW.
 
SAC has two blind spots, signature and MotW.

It is more complex. The signatures are unimportant here. Furthermore, MotW is used by SAC only when the initial attack vector is fileless. This happens rarely, and if it does, it is rarely bypassed, resulting in very sporadic infection events.
The intentional blind spot is fresh, properly signed malware.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top