wizard

Winsage
March 18, 2025
Microsoft's Windows Defender Application Control (WDAC) has become a target for cybersecurity researchers, with bug bounty payouts for successful bypasses. IBM's X-Force team reported various outcomes from WDAC bypass submissions, including successful bypasses that lead to potential bounties, those added to the WDAC recommended block list, and submissions without recognition. Notable contributors like Jimmy Bayne and Casey Smith have made significant discoveries, while the LOLBAS Project has documented additional bypasses, including the Microsoft Teams application. The X-Force team successfully bypassed WDAC during Red Team Operations using techniques such as utilizing known LOLBINs, DLL side-loading, exploiting custom exclusion rules, and identifying new execution chains in trusted applications. Electron applications, which can execute JavaScript and interact with the operating system, present unique vulnerabilities, as demonstrated by a supply-chain attack on the MiMi chat application. In preparation for a Red Team operation, Bobby Cooke's team explored the legacy Microsoft Teams application, discovering vulnerabilities in signed Node modules that allowed them to execute shellcode without triggering WDAC restrictions. They developed a JavaScript-based C2 framework called Loki C2, designed to operate within WDAC policies and facilitate reconnaissance and payload deployment. A demonstration of Loki C2 showcased its ability to bypass strict WDAC policies by modifying resources of the legitimate Teams application, allowing undetected code execution. The ongoing development of techniques and tools by the X-Force team reflects the evolving cybersecurity landscape and the continuous adaptation required to counter emerging threats.
Winsage
March 16, 2025
NTLite has received updates that enhance its functionality and security features, including support for Windows UEFI CA 2023 certificates and Microsoft Pluton. The update improves compatibility with Windows 11 24H2 and reintroduces the unattended Windows product key activation option, with caution advised against using generic keys. Key components added include the Image Mastering API (IMAPIv2), InstallShield WOW64, and various tools for 32 and 64-bit systems. The update also includes enhancements to the downloader and cumulative update compatibility. The latest version, 2025.03.10349, is available for download on Neowin and the official NTLite website.
Winsage
March 11, 2025
The search functionality in Windows 11 has been improved, but users may still experience slow performance or difficulty finding files. An alternative is Everything, a free utility by Voidtools that efficiently finds files and folders by indexing their names and continuously tracking changes. It has a lightweight design that minimizes resource usage, making it suitable for older PCs. Everything provides almost instantaneous search results by indexing the entire local drive, displays hidden files by default, and offers easy installation. It features real-time indexing, allowing immediate updates when files are modified, and has a portable version for use on different computers. Additionally, Everything can index network drives for efficient searches across shared devices. It is free to use, ad-free, and does not contain bloatware, with donations accepted to support the developer.
Winsage
March 10, 2025
Most modern games rely on real-time asset loading, making storage choice crucial for optimal gaming. A slow SSD or HDD can lead to long loading times and performance issues. 1. Disabling NTFS Last Access Time can improve loading speeds by reducing disk overhead. This can be done via Command Prompt with the command: fsutil behavior set disablelastaccess 1. 2. Enabling Large System Cache can enhance performance for games with substantial assets, requiring at least 16 GB of RAM and editing the Windows Registry. 3. Disabling antivirus scanning for the game folder can reduce loading times by preventing real-time scans. This can be done through Windows Security settings. 4. Using an exFAT drive can efficiently process large files, which may benefit games with sizable assets. This involves creating a new volume in Disk Management. 5. Disabling Full-Screen Optimizations can reduce input lag and improve performance by changing settings in the game's executable properties. 6. Increasing Shader Cache Size can improve loading times, with Nvidia users advised to set it to 10 GB or Unlimited in the Nvidia Control Panel. 7. Using a third-party cache management program like PrimoCache can enhance loading times by reserving RAM for caching frequently used programs.
Search