Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Does anyone know how to lock down powershell on student machines?

 

At the moment the students are just creating a batch file to launch it.

 

start powershell.exe

 

We even ban .bat using FSRM but they seem to still be able to transfer it to their user drives somehow.

 

Any ways to prevent it?

Posted

- - - Updated - - -

 

Does anyone know how to lock down powershell on student machines?

 

At the moment the students are just creating a batch file to launch it.

 

start powershell.exe

 

We even ban .bat using FSRM but they seem to still be able to transfer it to their user drives somehow.

 

Any ways to prevent it?

 

You could use group policy software restrictions to block .bat on the USB.

 

http://www.mechbgon.com/srp/

  • Thanks 1
Posted

AppLocker + PowerShell >5.0

 

Detecting Offensive PowerShell Attack Tools

 

PowerShell v5 also supports automatic lock-down when AppLocker is deployed in “Allow” mode. Applocker Allow mode is true whitelisting and can prevent any unauthorized binary from being executed. PowerShell v5 detects when Applocker Allow mode is in effect and sets the PowerShell language to Constrained Mode, severely limiting the attack surface on the system. With Applocker in Allow mode and PowerShell running in Constrained Mode, it is not possible for an attacker to change the PowerShell language mode to full in order to run attack tools. When AppLocker is configured in “Allow Mode”, PowerShell reduces its functionality to “Constrained Mode” for interactive input and user-authored scripts. Constrained PowerShell only allows core PowerShell functionality and prevents execution of the extended language features often used by offensive PowerShell tools (direct .NET scripting, invocation of Win32 APIs via the Add-Type cmdlet, and interaction with COM objects).

 

Note that scripts allowed by AppLocker policy such as enterprise signed code or in a trusted directory are executed in full PowerShell mode and not the Constrained PowerShell environment. This can’t be easily bypassed by an attacker, even with admin rights.

 

Blacklisting the PowerShell EXEs and .ps1 scripts isn't enough...

 

http://www.sixdub.net/?p=367

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...