[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKY9TphdEs6lTahlz8LiDr7oe0mW68wPPRJL8JwtIOZI":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1153,"How can you check if a running process has blockdlls enabled, especially on different Windows versions?","On Windows 10, you can use the `GetProcessMitigationPolicy()` API with the `ProcessSignaturePolicy` structure to query whether `MicrosoftSignedOnly` is enabled. However, Windows 8 does not support this API for that policy; instead, you must use `NtQueryInformationProcess()` to retrieve the mitigation flags. The same approach is demonstrated in the [analysis article](\u002Fnews\u002Fanalysis-of-cobalt-strikes-blockdlls-exploitation) with open-source C code for both versions.","\u003Cp>On Windows 10, you can use the `GetProcessMitigationPolicy()` API with the `ProcessSignaturePolicy` structure to query whether `MicrosoftSignedOnly` is enabled. However, Windows 8 does not support this API for that policy; instead, you must use `NtQueryInformationProcess()` to retrieve the mitigation flags. The same approach is demonstrated in the [analysis article](\u002Fnews\u002Fanalysis-of-cobalt-strikes-blockdlls-exploitation) with open-source C code for both versions.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-cobalt-strikes-blockdlls-exploitation\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-you-check-if-a-running-process-has-blockdlls-enabled-especially-on-diffe-1777480247204","GetProcessMitigationPolicy, NtQueryInformationProcess, Windows 8, Windows 10, ProcessSignaturePolicy, blockdlls",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},280,"Analysis of Cobalt Strike's blockdlls Exploitation","analysis-of-cobalt-strikes-blockdlls-exploitation","Analysis of Cobalt Strike's blockdlls feature, covering detection, exploitation, and differences between Win8\u002FWin10 systems with code examples.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Cobalt Strike 3.14 added the blockdlls feature, restricting child processes to only load DLLs signed by Microsoft.\u003C\u002Fp>\u003Cp>This feature prevents third-party security software from injecting DLLs into child processes, thereby disabling hooks on child processes and ultimately protecting them.\u003C\u002Fp>\u003Cp>XPN also covered related content in his blog at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fprotecting-your-malware\u002F\u003C\u002Fp>\u003Cp>This article will expand on the exploitation methods of blockdlls, covering how to check if a process has blockdlls enabled and how to modify the current process to enable blockdlls, comparing differences in usage between Win8 and Win10 systems, providing open-source C code, and sharing script development details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>blockdlls in Cobalt Strike\u003C\u002Fli>\u003Cli>Methods to check if a process has blockdlls enabled\u003C\u002Fli>\u003Cli>Methods to modify the current process to enable blockdlls\u003C\u002Fli>\u003Cli>Differences in usage between Win8 and Win10 systems\u003C\u002Fli>\u003Cli>Utilization Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 blockdlls in Cobalt Strike\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>blockdlls in Cobalt Strike will create a child process and enable the blockdlls functionality\u003C\u002Fp>\u003Cp>XPN shared C code to achieve the same functionality in a blog post, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fprotecting-your-malware\u002F\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>int main()\u003Cbr>{\u003Cbr>    STARTUPINFOEXA si;\u003Cbr>    PROCESS_INFORMATION pi;\u003Cbr>    SIZE_T size = 0;\u003Cbr>    BOOL ret;\u003Cbr>\u003Cbr>    \u002F\u002F Required for a STARTUPINFOEXA\u003Cbr>    ZeroMemory(&amp;si, sizeof(si));\u003Cbr>    si.StartupInfo.cb = sizeof(STARTUPINFOEXA);\u003Cbr>    si.StartupInfo.dwFlags = EXTENDED_STARTUPINFO_PRESENT;\u003Cbr>\u003Cbr>    \u002F\u002F Get the size of our PROC_THREAD_ATTRIBUTE_LIST to be allocated\u003Cbr>    InitializeProcThreadAttributeList(NULL, 1, 0, &amp;size);\u003Cbr>\u003Cbr>    \u002F\u002F Allocate memory for PROC_THREAD_ATTRIBUTE_LIST\u003Cbr>    si.lpAttributeList = (LPPROC_THREAD_ATTRIBUTE_LIST)HeapAlloc(\u003Cbr>        GetProcessHeap(),\u003Cbr>        0,\u003Cbr>        size\u003Cbr>    );\u003Cbr>\u003Cbr>    \u002F\u002F Initialise our list \u003Cbr>    InitializeProcThreadAttributeList(si.lpAttributeList, 1, 0, &amp;size);\u003Cbr>\u003Cbr>    \u002F\u002F Enable blocking of non-Microsoft signed DLLs\u003Cbr>    DWORD64 policy = PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON;\u003Cbr>\u003Cbr>    \u002F\u002F Assign our attribute\u003Cbr>    UpdateProcThreadAttribute(si.lpAttributeList, 0, PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY, &amp;policy, sizeof(policy), NULL, NULL);\u003Cbr>\u003Cbr>    \u002F\u002F Finally, create the process\u003Cbr>    ret = CreateProcessA(\u003Cbr>        NULL,\u003Cbr>        (LPSTR)\"C:\\\\Windows\\\\System32\\\\cmd.exe\",\u003Cbr>        NULL,\u003Cbr>        NULL,\u003Cbr>        true,\u003Cbr>        EXTENDED_STARTUPINFO_PRESENT,\u003Cbr>        NULL,\u003Cbr>        NULL,\u003Cbr>        reinterpret_cast\u003Clpstartupinfoa>(&amp;si),\u003Cbr>        &amp;pi\u003Cbr>    );\u003Cbr>}\u003C\u002Flpstartupinfoa>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Specified the security policy for creating a child process through the STARTUPINFOEX structure (enabling PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON), which prevents loading non-Microsoft signed DLLs.\u003C\u002Fp>\u003Cp>After generating the child process, using ProcessHacker shows a prompt indicating the blockdlls feature is enabled, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016715605_0_72467bf0f8.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016721030_1_9d3d933fb8.jpeg\">\u003C\u002Fp>\u003Cp>After enabling the blockdlls feature, attempting DLL injection into this process, the injection code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>An error occurs during injection, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016727611_2_8b38997ff1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully reproduced the blockdlls feature in Cobalt Strike.\u003C\u002Fp>\u003Cp>Next, the details related to this feature need to be found.\u003C\u002Fp>\u003Cp>After some searching, the relevant API GetProcessMitigationPolicy() was found, which can be used to read the security policy of a process.\u003C\u002Fp>\u003Cp>Reference materials are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fprocessthreadsapi\u002Fnf-processthreadsapi-getprocessmitigationpolicy\u003C\u002Fp>\u003Cp>The structure corresponding to the signature policy is PROCESS_MITIGATION_BINARY_SIGNATURE_POLICY, with reference materials as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fwindows\u002Fwin32\u002Fapi\u002Fwinnt\u002Fns-winnt-process_mitigation_binary_signature_policy\u003C\u002Fp>\u003Cp>Documentation indicates the minimum supported system for this API is Windows 8. It is speculated that the API GetProcessMitigationPolicy() should support the same operating system versions as blockdlls.\u003C\u002Fp>\u003Cp>Testing reveals that the minimum system supported by blockdlls in Cobalt Strike is Windows 8.\u003C\u002Fp>\u003Ch2>0x03 Method to check if a process has blockdlls enabled\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enabling blockdlls is equivalent to the process enabling the security policy ProcessSignaturePolicy (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>The API GetProcessMitigationPolicy() can be used to retrieve the process's security policies and determine if the blockdlls feature is enabled.\u003C\u002Fp>\u003Cp>The API GetProcessMitigationPolicy() can query multiple security policies of a process. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fprocessthreadsapi\u002Fnf-processthreadsapi-getprocessmitigationpolicy\u003C\u002Fp>\u003Cp>Attempted to write code according to the API's calling format. The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can query all security policies of a specified process.\u003C\u002Fp>\u003Cp>Tested without issues on Windows 10, as shown in the image below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016731620_3_532c59b07d.jpeg\">\u003C\u002Fp>\u003Cp>Testing on Windows 8 (same for Server 2012) shows that information for the security policy ProcessSignaturePolicy cannot be retrieved, whereas ProcessHacker does not have this issue on Windows 8.\u003C\u002Fp>\u003Cp>By examining the source code of ProcessHacker, a solution was found:\u003C\u002Fp>\u003Cp>This requires implementation via NtQueryInformationProcess().\u003C\u002Fp>\u003Cp>The complete code usable on Windows 8 has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can query all security policies for a specified process on Windows 8. Note that Windows 8 does not support the following security policies:\u003C\u002Fp>\u003Cul>\u003Cli>ControlFlowGuardPolicy\u003C\u002Fli>\u003Cli>FontDisablePolicy\u003C\u002Fli>\u003Cli>ImageLoadPolicy\u003C\u002Fli>\u003Cli>SystemCallFilterPolicy\u003C\u002Fli>\u003Cli>PayloadRestrictionPolicy\u003C\u002Fli>\u003Cli>ChildProcessPolicy\u003C\u002Fli>\u003Cli>SideChannelIsolationPolicy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Tested on Windows 8 without issues, as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016735517_4_8d86248913.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Modifying the current process to enable blockdlls method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Modifying the current process to enable blockdlls is equivalent to modifying the security policy ProcessSignaturePolicy of the current process (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>First, use the API GetProcessMitigationPolicy() to obtain the process's security policy, then modify the security policy ProcessSignaturePolicy via the API SetProcessMitigationPolicy() (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>Attempt to write code according to the API calling format; the code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project) ForWin10_CurrentProcess.cpp\u003C\u002Fp>\u003Cp>The code can modify the security policy of the current process and enable the MicrosoftSignedOnly feature.\u003C\u002Fp>\u003Cp>Tested without issues on Windows 10 systems.\u003C\u002Fp>\u003Cp>Tested on Windows 8 systems (same for Server 2012), issues occurred and modifications failed.\u003C\u002Fp>\u003Cp>The solution is the same as above:\u003C\u002Fp>\u003Cp>Implement via NtSetInformationProcess().\u003C\u002Fp>\u003Cp>The complete code usable on Windows 8 systems has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project) ForWin8_CurrentProcess.cpp\u003C\u002Fp>\u003Cp>The code can modify the security policy of the current process on Windows 8 systems, enabling blockdlls.\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enabling blockdlls is equivalent to enabling the ProcessSignaturePolicy security policy (with MicrosoftSignedOnly functionality) for a process, which can be applied not only to child processes but also to the current process.\u003C\u002Fp>\u003Cp>Supported systems: Windows 8 to Windows 10\u003C\u002Fp>\u003Cp>After enabling blockdlls, it can prevent third-party security software from injecting DLLs into this process, thereby preventing hooks on the process and ultimately protecting it.\u003C\u002Fp>\u003Cp>On Windows 8 systems, NtQueryInformationProcess() and NtSetInformationProcess() must be used to view and modify the security policy.\u003C\u002Fp>\u003Cp>Cannot use NtSetInformationProcess() to modify the security policy of a remote process, error code c000000d (STATUS_ILLEGAL_INSTRUCTION).\u003C\u002Fp>\u003Cp>Cannot bypass blockdlls protection using 'Authenticode Signature Forgery—Forging Signatures of PE Files and Hijacking Signature Verification'\u003C\u002Fp>\u003Cp>and 'Catalog Signature Forgery—Long UNC Filename Spoofing'.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article expands on the utilization methods of blockdlls, detailing how to check if a process has blockdlls enabled and how to enable it for the current process, compares the differences in usage between Windows 8 and Windows 10 systems, provides open-source C code, shares details on script writing, and summarizes exploitation ideas.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Cobalt Strike 3.14 added the blockdlls feature, restricting child processes to only load DLLs signed by Microsoft.\u003C\u002Fp>\u003Cp>This feature prevents third-party security software from injecting DLLs into child processes, thereby disabling hooks on child processes and ultimately protecting them.\u003C\u002Fp>\u003Cp>XPN also covered related content in his blog at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fprotecting-your-malware\u002F\u003C\u002Fp>\u003Cp>This article will expand on the exploitation methods of blockdlls, covering how to check if a process has blockdlls enabled and how to modify the current process to enable blockdlls, comparing differences in usage between Win8 and Win10 systems, providing open-source C code, and sharing script development details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>blockdlls in Cobalt Strike\u003C\u002Fli>\u003Cli>Methods to check if a process has blockdlls enabled\u003C\u002Fli>\u003Cli>Methods to modify the current process to enable blockdlls\u003C\u002Fli>\u003Cli>Differences in usage between Win8 and Win10 systems\u003C\u002Fli>\u003Cli>Utilization Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 blockdlls in Cobalt Strike\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>blockdlls in Cobalt Strike will create a child process and enable the blockdlls functionality\u003C\u002Fp>\u003Cp>XPN shared C code to achieve the same functionality in a blog post, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fprotecting-your-malware\u002F\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>int main()\u003Cbr>{\u003Cbr>    STARTUPINFOEXA si;\u003Cbr>    PROCESS_INFORMATION pi;\u003Cbr>    SIZE_T size = 0;\u003Cbr>    BOOL ret;\u003Cbr>\u003Cbr>    \u002F\u002F Required for a STARTUPINFOEXA\u003Cbr>    ZeroMemory(&amp;si, sizeof(si));\u003Cbr>    si.StartupInfo.cb = sizeof(STARTUPINFOEXA);\u003Cbr>    si.StartupInfo.dwFlags = EXTENDED_STARTUPINFO_PRESENT;\u003Cbr>\u003Cbr>    \u002F\u002F Get the size of our PROC_THREAD_ATTRIBUTE_LIST to be allocated\u003Cbr>    InitializeProcThreadAttributeList(NULL, 1, 0, &amp;size);\u003Cbr>\u003Cbr>    \u002F\u002F Allocate memory for PROC_THREAD_ATTRIBUTE_LIST\u003Cbr>    si.lpAttributeList = (LPPROC_THREAD_ATTRIBUTE_LIST)HeapAlloc(\u003Cbr>        GetProcessHeap(),\u003Cbr>        0,\u003Cbr>        size\u003Cbr>    );\u003Cbr>\u003Cbr>    \u002F\u002F Initialise our list \u003Cbr>    InitializeProcThreadAttributeList(si.lpAttributeList, 1, 0, &amp;size);\u003Cbr>\u003Cbr>    \u002F\u002F Enable blocking of non-Microsoft signed DLLs\u003Cbr>    DWORD64 policy = PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON;\u003Cbr>\u003Cbr>    \u002F\u002F Assign our attribute\u003Cbr>    UpdateProcThreadAttribute(si.lpAttributeList, 0, PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY, &amp;policy, sizeof(policy), NULL, NULL);\u003Cbr>\u003Cbr>    \u002F\u002F Finally, create the process\u003Cbr>    ret = CreateProcessA(\u003Cbr>        NULL,\u003Cbr>        (LPSTR)\"C:\\\\Windows\\\\System32\\\\cmd.exe\",\u003Cbr>        NULL,\u003Cbr>        NULL,\u003Cbr>        true,\u003Cbr>        EXTENDED_STARTUPINFO_PRESENT,\u003Cbr>        NULL,\u003Cbr>        NULL,\u003Cbr>        reinterpret_cast\u003Clpstartupinfoa>(&amp;si),\u003Cbr>        &amp;pi\u003Cbr>    );\u003Cbr>}\u003C\u002Flpstartupinfoa>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Specified the security policy for creating a child process through the STARTUPINFOEX structure (enabling PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON), which prevents loading non-Microsoft signed DLLs.\u003C\u002Fp>\u003Cp>After generating the child process, using ProcessHacker shows a prompt indicating the blockdlls feature is enabled, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016715605_0_72467bf0f8-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016721030_1_9d3d933fb8-1.jpeg\">\u003C\u002Fp>\u003Cp>After enabling the blockdlls feature, attempting DLL injection into this process, the injection code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>An error occurs during injection, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016727611_2_8b38997ff1-1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully reproduced the blockdlls feature in Cobalt Strike.\u003C\u002Fp>\u003Cp>Next, the details related to this feature need to be found.\u003C\u002Fp>\u003Cp>After some searching, the relevant API GetProcessMitigationPolicy() was found, which can be used to read the security policy of a process.\u003C\u002Fp>\u003Cp>Reference materials are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fprocessthreadsapi\u002Fnf-processthreadsapi-getprocessmitigationpolicy\u003C\u002Fp>\u003Cp>The structure corresponding to the signature policy is PROCESS_MITIGATION_BINARY_SIGNATURE_POLICY, with reference materials as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fwindows\u002Fwin32\u002Fapi\u002Fwinnt\u002Fns-winnt-process_mitigation_binary_signature_policy\u003C\u002Fp>\u003Cp>Documentation indicates the minimum supported system for this API is Windows 8. It is speculated that the API GetProcessMitigationPolicy() should support the same operating system versions as blockdlls.\u003C\u002Fp>\u003Cp>Testing reveals that the minimum system supported by blockdlls in Cobalt Strike is Windows 8.\u003C\u002Fp>\u003Ch2>0x03 Method to check if a process has blockdlls enabled\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enabling blockdlls is equivalent to the process enabling the security policy ProcessSignaturePolicy (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>The API GetProcessMitigationPolicy() can be used to retrieve the process's security policies and determine if the blockdlls feature is enabled.\u003C\u002Fp>\u003Cp>The API GetProcessMitigationPolicy() can query multiple security policies of a process. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fprocessthreadsapi\u002Fnf-processthreadsapi-getprocessmitigationpolicy\u003C\u002Fp>\u003Cp>Attempted to write code according to the API's calling format. The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can query all security policies of a specified process.\u003C\u002Fp>\u003Cp>Tested without issues on Windows 10, as shown in the image below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016731620_3_532c59b07d-1.jpeg\">\u003C\u002Fp>\u003Cp>Testing on Windows 8 (same for Server 2012) shows that information for the security policy ProcessSignaturePolicy cannot be retrieved, whereas ProcessHacker does not have this issue on Windows 8.\u003C\u002Fp>\u003Cp>By examining the source code of ProcessHacker, a solution was found:\u003C\u002Fp>\u003Cp>This requires implementation via NtQueryInformationProcess().\u003C\u002Fp>\u003Cp>The complete code usable on Windows 8 has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can query all security policies for a specified process on Windows 8. Note that Windows 8 does not support the following security policies:\u003C\u002Fp>\u003Cul>\u003Cli>ControlFlowGuardPolicy\u003C\u002Fli>\u003Cli>FontDisablePolicy\u003C\u002Fli>\u003Cli>ImageLoadPolicy\u003C\u002Fli>\u003Cli>SystemCallFilterPolicy\u003C\u002Fli>\u003Cli>PayloadRestrictionPolicy\u003C\u002Fli>\u003Cli>ChildProcessPolicy\u003C\u002Fli>\u003Cli>SideChannelIsolationPolicy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Tested on Windows 8 without issues, as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016735517_4_8d86248913-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Modifying the current process to enable blockdlls method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Modifying the current process to enable blockdlls is equivalent to modifying the security policy ProcessSignaturePolicy of the current process (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>First, use the API GetProcessMitigationPolicy() to obtain the process's security policy, then modify the security policy ProcessSignaturePolicy via the API SetProcessMitigationPolicy() (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>Attempt to write code according to the API calling format; the code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project) ForWin10_CurrentProcess.cpp\u003C\u002Fp>\u003Cp>The code can modify the security policy of the current process and enable the MicrosoftSignedOnly feature.\u003C\u002Fp>\u003Cp>Tested without issues on Windows 10 systems.\u003C\u002Fp>\u003Cp>Tested on Windows 8 systems (same for Server 2012), issues occurred and modifications failed.\u003C\u002Fp>\u003Cp>The solution is the same as above:\u003C\u002Fp>\u003Cp>Implement via NtSetInformationProcess().\u003C\u002Fp>\u003Cp>The complete code usable on Windows 8 systems has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project) ForWin8_CurrentProcess.cpp\u003C\u002Fp>\u003Cp>The code can modify the security policy of the current process on Windows 8 systems, enabling blockdlls.\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enabling blockdlls is equivalent to enabling the ProcessSignaturePolicy security policy (with MicrosoftSignedOnly functionality) for a process, which can be applied not only to child processes but also to the current process.\u003C\u002Fp>\u003Cp>Supported systems: Windows 8 to Windows 10\u003C\u002Fp>\u003Cp>After enabling blockdlls, it can prevent third-party security software from injecting DLLs into this process, thereby preventing hooks on the process and ultimately protecting it.\u003C\u002Fp>\u003Cp>On Windows 8 systems, NtQueryInformationProcess() and NtSetInformationProcess() must be used to view and modify the security policy.\u003C\u002Fp>\u003Cp>Cannot use NtSetInformationProcess() to modify the security policy of a remote process, error code c000000d (STATUS_ILLEGAL_INSTRUCTION).\u003C\u002Fp>\u003Cp>Cannot bypass blockdlls protection using 'Authenticode Signature Forgery—Forging Signatures of PE Files and Hijacking Signature Verification'\u003C\u002Fp>\u003Cp>and 'Catalog Signature Forgery—Long UNC Filename Spoofing'.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article expands on the utilization methods of blockdlls, detailing how to check if a process has blockdlls enabled and how to enable it for the current process, compares the differences in usage between Windows 8 and Windows 10 systems, provides open-source C code, shares details on script writing, and summarizes exploitation ideas.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",77,"Onedaysec",5,"published","2026-02-02T07:25:19.686Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Cobalt Strike blockdlls Exploitation Analysis & Detection Methods","Cobalt Strike blockdlls, process security policy, DLL injection prevention, Windows mitigation policy, malware protection, GetProcessMitigationPolicy",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],1155,1154,1152,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.224Z","2026-07-23T16:02:36.083Z","draft","2026-07-23T16:17:03.584Z"]