It is possible as a low privileged user to parse the Windows event logs for any ASR exclusion

https://primusinterp.com/posts/WindowsASR/

#infosec #cybersecurity #redteam #pentest

Cheesing Microsoft Attack Surface Reduction rules

While working on varying engagements i have been messing with Microsoft Attack Surface Reduction (ASR) quite a bit, since clients often use it to make the life of adversaries(and red teamers) just a tad harder. While working on these engagements i have compiled some tips and tricks in order to bypass/evade some of the rules that ASR offers. In this post i will dive into what ASR is and some of tips and tricks that i often use to bypass/cheese my way around said rules… So strap in and lets get going with some basic ASR understanding.

. .\Primusinterp