If I download an Exe, and Smartscreen appears as unrecognized file. And I click run anyway, it will bypass Wdac. Is this a normal behavior?
If I download an Exe, and Smartscreen appears as unrecognized file. And I click run anyway, it will bypass Wdac. Is this a normal behavior?
Scripts and many more file types are already blocked by < SWH > settings. These files can be selectively whitelisted in WHHLight (except PowerShell scripts). This is far better protection compared to SAC.Much like SAC can you add wdac policy that blocks scripts that have the mark of the web?
Using Win 11 21H2, my network connection partially crippled shortly after enabling "Block sponsors" in H_C, although I couldn't find any evidence in Events that H_C caused it, and neither did restoring Windows defaults fix it, nor even uninstalling H_C, with several reboots in between.
You are most likely rightIt was most probably a time coincidence, unrelated to H_C. You can find several examples of such coincidences in this thread, that finally turned out completely unrelated.
Issue still persisted after all those steps, and there was no evidence of Firewall blocks or blocked Sponsors found in any of the Event logs. Only after doing a "Network reset" did the issue disappear, which is why I think it was not caused by H_C or CFIf the issue disappears after restoring Windows default settings (including ConfigureDefender and FirewallHardening) and restarting the system, then you should consider H_C to be involved. In such a case the connection could be impacted by the FirewallHardening or some blocked Sponsors.
Thanks, will do. Actually the more compelling reasons for me switching to WHHLight is I embrace the simplicity of it, while being highly effective, and that it's a current project of yours in active developmentBe safe.
Please let me know if you encounter any problems with WHHLight.
@Andy Ful
When doing a Google search on "Andy Ful" one comes to the following site: AndyFul - Overview. It is the Top alternative. It is like a home site for your products since they are all there, except 1 - WHHLight.
What do you say, does not these 2 actions seems good, make sence?
Now your site and the programs are known to just a small group of users, and mostly discussed here on MT and little else. With the above actions the spreed will be a bit better and it will be easier for my followers on the site i recommend the programs to get a better overview
The WHHLight is part of a broad Hard_Configurator project, so it is contained in the Hard_Configurator on GitHub.
But in the future, I do not exclude the possibility of making it an independent project.
Yes.
WHHLight is in the early development stage. So for now, a small group of users is OK.
The WHHLight is part of a broad Hard_Configurator project, so it is contained in the Hard_Configurator on GitHub.
But in the future, I do not exclude the possibility of making it an independent project.
Yes.
WHHLight is in the early development stage. So for now, a small group of users is OK.
So that is my aim with this, but for now i will wait until WHHL is not so much "in the early development stage".
The WHHLight is part of a broad Hard_Configurator project, so it is contained in the Hard_Configurator on GitHub.
But in the future, I do not exclude the possibility of making it an independent project.
Yes.
WHHLight is in the early development stage. So for now, a small group of users is OK.
Hm. I just downloaded H_C and i could not find WHHL in it. Neither SWH, which i thought would be in it.
Guidance please.
@Andy Ful two questions
What is the difference in protection between WDAC-ISG and ConfigureDefender on MAX? (the information I can find is that they share the same backbone infrastructure without explaining differences)
When I run WHHL I get this error (and an usigned program runs fine, even after removing all user space folders), does this mean that WDAC is not installed?
View attachment 281618
@Andy Ful
(I have one unsigned app, which user folder I added to the whitelist. I removed write/delete rights of that folder with ACL for everyone except admins).
Thanks for this explanation, I will remove it from the whitelist. I had not realized this. It is a simple application to print restaurant menu's. It stores the user preferences in an ini file (old school Windows 3.1 like) but those settings are set and forget.If you removed the write/delete rights of that folder except for admins, then the app should work even if removed from the whitelist (the application folder is Non-writable).
The cons of removing write/delete rights are that this app cannot write anything in the folder. Anyway, many applications can still work well.
the best solution is installing applications in Program Files (if there is such an option).