Skip to content

Instantly share code, notes, and snippets.

@LM-CT
Last active May 20, 2023 20:47
Show Gist options
  • Save LM-CT/446b60cde600094e875a5cffae702135 to your computer and use it in GitHub Desktop.
Save LM-CT/446b60cde600094e875a5cffae702135 to your computer and use it in GitHub Desktop.
<?xml version="1.0" encoding="UTF-8"?>
<MitigationPolicy>
<SystemConfig>
<SEHOP Audit="true"/>
</SystemConfig>
<AppConfig Executable="iexplore.exe">
<ImageLoad AuditImageLoad="true"/>
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="wordpad.exe">
<DynamicCode Audit="true"/>
<SignedBinaries Audit="true"
AuditStoreSigned="false"/>
<ImageLoad AuditImageLoad="true"/>
<ChildProcess Audit="true"/>
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="notepad.exe">
<DynamicCode Audit="true"/>
<SignedBinaries Audit="true"
AuditStoreSigned="false"/>
<ImageLoad AuditImageLoad="true"/>
<ChildProcess Audit="true"/>
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="outlook.exe">
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="winword.exe">
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="excel.exe">
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="powerpnt.exe">
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="AcroRd32.exe">
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="Acrobat.exe">
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="fltldr.exe">
<DynamicCode Audit="true"/>
<ImageLoad AuditImageLoad="true"/>
<ChildProcess Audit="true"/>
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="RuntimeBroker.exe">
<ImageLoad AuditImageLoad="true"/>
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="SearchIndexer.exe">
<DynamicCode Audit="true"/>
<SignedBinaries Audit="true"
AuditStoreSigned="false"/>
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="java.exe">
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="javaws.exe">
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="javaw.exe">
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
<AppConfig Executable="EpSelfhostV1.exe">
<DynamicCode Audit="true"/>
<ImageLoad AuditImageLoad="true"/>
<ChildProcess Audit="true"/>
<Payload AuditEnableExportAddressFilter="true"
AuditEnableExportAddressFilterPlus="true"
AuditEnableImportAddressFilter="true"
AuditEnableRopStackPivot="true"
AuditEnableRopCallerCheck="true"
AuditEnableRopSimExec="true"/>
</AppConfig>
</MitigationPolicy>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment