[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fP1fvJJz9_zB3WHO58IWQMU2eYQpKoqsuA0Ru9R1d7NQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1152,"What is the purpose of Cobalt Strike's blockdlls feature and how does it protect child processes?","Cobalt Strike's blockdlls feature restricts child processes to only load DLLs signed by Microsoft, preventing third-party security software from injecting DLLs and disabling hooks. As detailed in [Analysis of Cobalt Strike's blockdlls Exploitation](\u002Fnews\u002Fanalysis-of-cobalt-strikes-blockdlls-exploitation), it uses the `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` policy via the `STARTUPINFOEX` structure to enforce this restriction at process creation.","\u003Cp>Cobalt Strike&#39;s blockdlls feature restricts child processes to only load DLLs signed by Microsoft, preventing third-party security software from injecting DLLs and disabling hooks. As detailed in [Analysis of Cobalt Strike&#39;s blockdlls Exploitation](\u002Fnews\u002Fanalysis-of-cobalt-strikes-blockdlls-exploitation), it uses the `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` policy via the `STARTUPINFOEX` structure to enforce this restriction at process creation.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-cobalt-strikes-blockdlls-exploitation\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-purpose-of-cobalt-strikes-blockdlls-feature-and-how-does-it-protect--1777480247121","blockdlls, Cobalt Strike, process mitigation policy, DLL injection, Microsoft signature",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},280,"Analysis of Cobalt Strike's blockdlls Exploitation","analysis-of-cobalt-strikes-blockdlls-exploitation","Analysis of Cobalt Strike's blockdlls feature, covering detection, exploitation, and differences between Win8\u002FWin10 systems with code examples.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Cobalt Strike 3.14 added the blockdlls feature, restricting child processes to only load DLLs signed by Microsoft.\u003C\u002Fp>\u003Cp>This feature prevents third-party security software from injecting DLLs into child processes, thereby disabling hooks on child processes and ultimately protecting them.\u003C\u002Fp>\u003Cp>XPN also covered related content in his blog at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fprotecting-your-malware\u002F\u003C\u002Fp>\u003Cp>This article will expand on the exploitation methods of blockdlls, covering how to check if a process has blockdlls enabled and how to modify the current process to enable blockdlls, comparing differences in usage between Win8 and Win10 systems, providing open-source C code, and sharing script development details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>blockdlls in Cobalt Strike\u003C\u002Fli>\u003Cli>Methods to check if a process has blockdlls enabled\u003C\u002Fli>\u003Cli>Methods to modify the current process to enable blockdlls\u003C\u002Fli>\u003Cli>Differences in usage between Win8 and Win10 systems\u003C\u002Fli>\u003Cli>Utilization Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 blockdlls in Cobalt Strike\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>blockdlls in Cobalt Strike will create a child process and enable the blockdlls functionality\u003C\u002Fp>\u003Cp>XPN shared C code to achieve the same functionality in a blog post, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fprotecting-your-malware\u002F\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>int main()\u003Cbr>{\u003Cbr>    STARTUPINFOEXA si;\u003Cbr>    PROCESS_INFORMATION pi;\u003Cbr>    SIZE_T size = 0;\u003Cbr>    BOOL ret;\u003Cbr>\u003Cbr>    \u002F\u002F Required for a STARTUPINFOEXA\u003Cbr>    ZeroMemory(&amp;si, sizeof(si));\u003Cbr>    si.StartupInfo.cb = sizeof(STARTUPINFOEXA);\u003Cbr>    si.StartupInfo.dwFlags = EXTENDED_STARTUPINFO_PRESENT;\u003Cbr>\u003Cbr>    \u002F\u002F Get the size of our PROC_THREAD_ATTRIBUTE_LIST to be allocated\u003Cbr>    InitializeProcThreadAttributeList(NULL, 1, 0, &amp;size);\u003Cbr>\u003Cbr>    \u002F\u002F Allocate memory for PROC_THREAD_ATTRIBUTE_LIST\u003Cbr>    si.lpAttributeList = (LPPROC_THREAD_ATTRIBUTE_LIST)HeapAlloc(\u003Cbr>        GetProcessHeap(),\u003Cbr>        0,\u003Cbr>        size\u003Cbr>    );\u003Cbr>\u003Cbr>    \u002F\u002F Initialise our list \u003Cbr>    InitializeProcThreadAttributeList(si.lpAttributeList, 1, 0, &amp;size);\u003Cbr>\u003Cbr>    \u002F\u002F Enable blocking of non-Microsoft signed DLLs\u003Cbr>    DWORD64 policy = PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON;\u003Cbr>\u003Cbr>    \u002F\u002F Assign our attribute\u003Cbr>    UpdateProcThreadAttribute(si.lpAttributeList, 0, PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY, &amp;policy, sizeof(policy), NULL, NULL);\u003Cbr>\u003Cbr>    \u002F\u002F Finally, create the process\u003Cbr>    ret = CreateProcessA(\u003Cbr>        NULL,\u003Cbr>        (LPSTR)\"C:\\\\Windows\\\\System32\\\\cmd.exe\",\u003Cbr>        NULL,\u003Cbr>        NULL,\u003Cbr>        true,\u003Cbr>        EXTENDED_STARTUPINFO_PRESENT,\u003Cbr>        NULL,\u003Cbr>        NULL,\u003Cbr>        reinterpret_cast\u003Clpstartupinfoa>(&amp;si),\u003Cbr>        &amp;pi\u003Cbr>    );\u003Cbr>}\u003C\u002Flpstartupinfoa>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Specified the security policy for creating a child process through the STARTUPINFOEX structure (enabling PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON), which prevents loading non-Microsoft signed DLLs.\u003C\u002Fp>\u003Cp>After generating the child process, using ProcessHacker shows a prompt indicating the blockdlls feature is enabled, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016715605_0_72467bf0f8.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016721030_1_9d3d933fb8.jpeg\">\u003C\u002Fp>\u003Cp>After enabling the blockdlls feature, attempting DLL injection into this process, the injection code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>An error occurs during injection, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016727611_2_8b38997ff1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully reproduced the blockdlls feature in Cobalt Strike.\u003C\u002Fp>\u003Cp>Next, the details related to this feature need to be found.\u003C\u002Fp>\u003Cp>After some searching, the relevant API GetProcessMitigationPolicy() was found, which can be used to read the security policy of a process.\u003C\u002Fp>\u003Cp>Reference materials are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fprocessthreadsapi\u002Fnf-processthreadsapi-getprocessmitigationpolicy\u003C\u002Fp>\u003Cp>The structure corresponding to the signature policy is PROCESS_MITIGATION_BINARY_SIGNATURE_POLICY, with reference materials as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fwindows\u002Fwin32\u002Fapi\u002Fwinnt\u002Fns-winnt-process_mitigation_binary_signature_policy\u003C\u002Fp>\u003Cp>Documentation indicates the minimum supported system for this API is Windows 8. It is speculated that the API GetProcessMitigationPolicy() should support the same operating system versions as blockdlls.\u003C\u002Fp>\u003Cp>Testing reveals that the minimum system supported by blockdlls in Cobalt Strike is Windows 8.\u003C\u002Fp>\u003Ch2>0x03 Method to check if a process has blockdlls enabled\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enabling blockdlls is equivalent to the process enabling the security policy ProcessSignaturePolicy (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>The API GetProcessMitigationPolicy() can be used to retrieve the process's security policies and determine if the blockdlls feature is enabled.\u003C\u002Fp>\u003Cp>The API GetProcessMitigationPolicy() can query multiple security policies of a process. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fprocessthreadsapi\u002Fnf-processthreadsapi-getprocessmitigationpolicy\u003C\u002Fp>\u003Cp>Attempted to write code according to the API's calling format. The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can query all security policies of a specified process.\u003C\u002Fp>\u003Cp>Tested without issues on Windows 10, as shown in the image below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016731620_3_532c59b07d.jpeg\">\u003C\u002Fp>\u003Cp>Testing on Windows 8 (same for Server 2012) shows that information for the security policy ProcessSignaturePolicy cannot be retrieved, whereas ProcessHacker does not have this issue on Windows 8.\u003C\u002Fp>\u003Cp>By examining the source code of ProcessHacker, a solution was found:\u003C\u002Fp>\u003Cp>This requires implementation via NtQueryInformationProcess().\u003C\u002Fp>\u003Cp>The complete code usable on Windows 8 has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can query all security policies for a specified process on Windows 8. Note that Windows 8 does not support the following security policies:\u003C\u002Fp>\u003Cul>\u003Cli>ControlFlowGuardPolicy\u003C\u002Fli>\u003Cli>FontDisablePolicy\u003C\u002Fli>\u003Cli>ImageLoadPolicy\u003C\u002Fli>\u003Cli>SystemCallFilterPolicy\u003C\u002Fli>\u003Cli>PayloadRestrictionPolicy\u003C\u002Fli>\u003Cli>ChildProcessPolicy\u003C\u002Fli>\u003Cli>SideChannelIsolationPolicy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Tested on Windows 8 without issues, as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016735517_4_8d86248913.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Modifying the current process to enable blockdlls method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Modifying the current process to enable blockdlls is equivalent to modifying the security policy ProcessSignaturePolicy of the current process (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>First, use the API GetProcessMitigationPolicy() to obtain the process's security policy, then modify the security policy ProcessSignaturePolicy via the API SetProcessMitigationPolicy() (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>Attempt to write code according to the API calling format; the code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project) ForWin10_CurrentProcess.cpp\u003C\u002Fp>\u003Cp>The code can modify the security policy of the current process and enable the MicrosoftSignedOnly feature.\u003C\u002Fp>\u003Cp>Tested without issues on Windows 10 systems.\u003C\u002Fp>\u003Cp>Tested on Windows 8 systems (same for Server 2012), issues occurred and modifications failed.\u003C\u002Fp>\u003Cp>The solution is the same as above:\u003C\u002Fp>\u003Cp>Implement via NtSetInformationProcess().\u003C\u002Fp>\u003Cp>The complete code usable on Windows 8 systems has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project) ForWin8_CurrentProcess.cpp\u003C\u002Fp>\u003Cp>The code can modify the security policy of the current process on Windows 8 systems, enabling blockdlls.\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enabling blockdlls is equivalent to enabling the ProcessSignaturePolicy security policy (with MicrosoftSignedOnly functionality) for a process, which can be applied not only to child processes but also to the current process.\u003C\u002Fp>\u003Cp>Supported systems: Windows 8 to Windows 10\u003C\u002Fp>\u003Cp>After enabling blockdlls, it can prevent third-party security software from injecting DLLs into this process, thereby preventing hooks on the process and ultimately protecting it.\u003C\u002Fp>\u003Cp>On Windows 8 systems, NtQueryInformationProcess() and NtSetInformationProcess() must be used to view and modify the security policy.\u003C\u002Fp>\u003Cp>Cannot use NtSetInformationProcess() to modify the security policy of a remote process, error code c000000d (STATUS_ILLEGAL_INSTRUCTION).\u003C\u002Fp>\u003Cp>Cannot bypass blockdlls protection using 'Authenticode Signature Forgery—Forging Signatures of PE Files and Hijacking Signature Verification'\u003C\u002Fp>\u003Cp>and 'Catalog Signature Forgery—Long UNC Filename Spoofing'.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article expands on the utilization methods of blockdlls, detailing how to check if a process has blockdlls enabled and how to enable it for the current process, compares the differences in usage between Windows 8 and Windows 10 systems, provides open-source C code, shares details on script writing, and summarizes exploitation ideas.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Cobalt Strike 3.14 added the blockdlls feature, restricting child processes to only load DLLs signed by Microsoft.\u003C\u002Fp>\u003Cp>This feature prevents third-party security software from injecting DLLs into child processes, thereby disabling hooks on child processes and ultimately protecting them.\u003C\u002Fp>\u003Cp>XPN also covered related content in his blog at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fprotecting-your-malware\u002F\u003C\u002Fp>\u003Cp>This article will expand on the exploitation methods of blockdlls, covering how to check if a process has blockdlls enabled and how to modify the current process to enable blockdlls, comparing differences in usage between Win8 and Win10 systems, providing open-source C code, and sharing script development details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>blockdlls in Cobalt Strike\u003C\u002Fli>\u003Cli>Methods to check if a process has blockdlls enabled\u003C\u002Fli>\u003Cli>Methods to modify the current process to enable blockdlls\u003C\u002Fli>\u003Cli>Differences in usage between Win8 and Win10 systems\u003C\u002Fli>\u003Cli>Utilization Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 blockdlls in Cobalt Strike\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>blockdlls in Cobalt Strike will create a child process and enable the blockdlls functionality\u003C\u002Fp>\u003Cp>XPN shared C code to achieve the same functionality in a blog post, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fprotecting-your-malware\u002F\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>int main()\u003Cbr>{\u003Cbr>    STARTUPINFOEXA si;\u003Cbr>    PROCESS_INFORMATION pi;\u003Cbr>    SIZE_T size = 0;\u003Cbr>    BOOL ret;\u003Cbr>\u003Cbr>    \u002F\u002F Required for a STARTUPINFOEXA\u003Cbr>    ZeroMemory(&amp;si, sizeof(si));\u003Cbr>    si.StartupInfo.cb = sizeof(STARTUPINFOEXA);\u003Cbr>    si.StartupInfo.dwFlags = EXTENDED_STARTUPINFO_PRESENT;\u003Cbr>\u003Cbr>    \u002F\u002F Get the size of our PROC_THREAD_ATTRIBUTE_LIST to be allocated\u003Cbr>    InitializeProcThreadAttributeList(NULL, 1, 0, &amp;size);\u003Cbr>\u003Cbr>    \u002F\u002F Allocate memory for PROC_THREAD_ATTRIBUTE_LIST\u003Cbr>    si.lpAttributeList = (LPPROC_THREAD_ATTRIBUTE_LIST)HeapAlloc(\u003Cbr>        GetProcessHeap(),\u003Cbr>        0,\u003Cbr>        size\u003Cbr>    );\u003Cbr>\u003Cbr>    \u002F\u002F Initialise our list \u003Cbr>    InitializeProcThreadAttributeList(si.lpAttributeList, 1, 0, &amp;size);\u003Cbr>\u003Cbr>    \u002F\u002F Enable blocking of non-Microsoft signed DLLs\u003Cbr>    DWORD64 policy = PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON;\u003Cbr>\u003Cbr>    \u002F\u002F Assign our attribute\u003Cbr>    UpdateProcThreadAttribute(si.lpAttributeList, 0, PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY, &amp;policy, sizeof(policy), NULL, NULL);\u003Cbr>\u003Cbr>    \u002F\u002F Finally, create the process\u003Cbr>    ret = CreateProcessA(\u003Cbr>        NULL,\u003Cbr>        (LPSTR)\"C:\\\\Windows\\\\System32\\\\cmd.exe\",\u003Cbr>        NULL,\u003Cbr>        NULL,\u003Cbr>        true,\u003Cbr>        EXTENDED_STARTUPINFO_PRESENT,\u003Cbr>        NULL,\u003Cbr>        NULL,\u003Cbr>        reinterpret_cast\u003Clpstartupinfoa>(&amp;si),\u003Cbr>        &amp;pi\u003Cbr>    );\u003Cbr>}\u003C\u002Flpstartupinfoa>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Specified the security policy for creating a child process through the STARTUPINFOEX structure (enabling PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON), which prevents loading non-Microsoft signed DLLs.\u003C\u002Fp>\u003Cp>After generating the child process, using ProcessHacker shows a prompt indicating the blockdlls feature is enabled, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016715605_0_72467bf0f8-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016721030_1_9d3d933fb8-1.jpeg\">\u003C\u002Fp>\u003Cp>After enabling the blockdlls feature, attempting DLL injection into this process, the injection code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>An error occurs during injection, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016727611_2_8b38997ff1-1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully reproduced the blockdlls feature in Cobalt Strike.\u003C\u002Fp>\u003Cp>Next, the details related to this feature need to be found.\u003C\u002Fp>\u003Cp>After some searching, the relevant API GetProcessMitigationPolicy() was found, which can be used to read the security policy of a process.\u003C\u002Fp>\u003Cp>Reference materials are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fprocessthreadsapi\u002Fnf-processthreadsapi-getprocessmitigationpolicy\u003C\u002Fp>\u003Cp>The structure corresponding to the signature policy is PROCESS_MITIGATION_BINARY_SIGNATURE_POLICY, with reference materials as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fwindows\u002Fwin32\u002Fapi\u002Fwinnt\u002Fns-winnt-process_mitigation_binary_signature_policy\u003C\u002Fp>\u003Cp>Documentation indicates the minimum supported system for this API is Windows 8. It is speculated that the API GetProcessMitigationPolicy() should support the same operating system versions as blockdlls.\u003C\u002Fp>\u003Cp>Testing reveals that the minimum system supported by blockdlls in Cobalt Strike is Windows 8.\u003C\u002Fp>\u003Ch2>0x03 Method to check if a process has blockdlls enabled\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enabling blockdlls is equivalent to the process enabling the security policy ProcessSignaturePolicy (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>The API GetProcessMitigationPolicy() can be used to retrieve the process's security policies and determine if the blockdlls feature is enabled.\u003C\u002Fp>\u003Cp>The API GetProcessMitigationPolicy() can query multiple security policies of a process. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fprocessthreadsapi\u002Fnf-processthreadsapi-getprocessmitigationpolicy\u003C\u002Fp>\u003Cp>Attempted to write code according to the API's calling format. The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can query all security policies of a specified process.\u003C\u002Fp>\u003Cp>Tested without issues on Windows 10, as shown in the image below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016731620_3_532c59b07d-1.jpeg\">\u003C\u002Fp>\u003Cp>Testing on Windows 8 (same for Server 2012) shows that information for the security policy ProcessSignaturePolicy cannot be retrieved, whereas ProcessHacker does not have this issue on Windows 8.\u003C\u002Fp>\u003Cp>By examining the source code of ProcessHacker, a solution was found:\u003C\u002Fp>\u003Cp>This requires implementation via NtQueryInformationProcess().\u003C\u002Fp>\u003Cp>The complete code usable on Windows 8 has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can query all security policies for a specified process on Windows 8. Note that Windows 8 does not support the following security policies:\u003C\u002Fp>\u003Cul>\u003Cli>ControlFlowGuardPolicy\u003C\u002Fli>\u003Cli>FontDisablePolicy\u003C\u002Fli>\u003Cli>ImageLoadPolicy\u003C\u002Fli>\u003Cli>SystemCallFilterPolicy\u003C\u002Fli>\u003Cli>PayloadRestrictionPolicy\u003C\u002Fli>\u003Cli>ChildProcessPolicy\u003C\u002Fli>\u003Cli>SideChannelIsolationPolicy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Tested on Windows 8 without issues, as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016735517_4_8d86248913-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Modifying the current process to enable blockdlls method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Modifying the current process to enable blockdlls is equivalent to modifying the security policy ProcessSignaturePolicy of the current process (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>First, use the API GetProcessMitigationPolicy() to obtain the process's security policy, then modify the security policy ProcessSignaturePolicy via the API SetProcessMitigationPolicy() (enabling the MicrosoftSignedOnly feature).\u003C\u002Fp>\u003Cp>Attempt to write code according to the API calling format; the code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project) ForWin10_CurrentProcess.cpp\u003C\u002Fp>\u003Cp>The code can modify the security policy of the current process and enable the MicrosoftSignedOnly feature.\u003C\u002Fp>\u003Cp>Tested without issues on Windows 10 systems.\u003C\u002Fp>\u003Cp>Tested on Windows 8 systems (same for Server 2012), issues occurred and modifications failed.\u003C\u002Fp>\u003Cp>The solution is the same as above:\u003C\u002Fp>\u003Cp>Implement via NtSetInformationProcess().\u003C\u002Fp>\u003Cp>The complete code usable on Windows 8 systems has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project) ForWin8_CurrentProcess.cpp\u003C\u002Fp>\u003Cp>The code can modify the security policy of the current process on Windows 8 systems, enabling blockdlls.\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enabling blockdlls is equivalent to enabling the ProcessSignaturePolicy security policy (with MicrosoftSignedOnly functionality) for a process, which can be applied not only to child processes but also to the current process.\u003C\u002Fp>\u003Cp>Supported systems: Windows 8 to Windows 10\u003C\u002Fp>\u003Cp>After enabling blockdlls, it can prevent third-party security software from injecting DLLs into this process, thereby preventing hooks on the process and ultimately protecting it.\u003C\u002Fp>\u003Cp>On Windows 8 systems, NtQueryInformationProcess() and NtSetInformationProcess() must be used to view and modify the security policy.\u003C\u002Fp>\u003Cp>Cannot use NtSetInformationProcess() to modify the security policy of a remote process, error code c000000d (STATUS_ILLEGAL_INSTRUCTION).\u003C\u002Fp>\u003Cp>Cannot bypass blockdlls protection using 'Authenticode Signature Forgery—Forging Signatures of PE Files and Hijacking Signature Verification'\u003C\u002Fp>\u003Cp>and 'Catalog Signature Forgery—Long UNC Filename Spoofing'.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article expands on the utilization methods of blockdlls, detailing how to check if a process has blockdlls enabled and how to enable it for the current process, compares the differences in usage between Windows 8 and Windows 10 systems, provides open-source C code, shares details on script writing, and summarizes exploitation ideas.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",77,"Onedaysec",5,"published","2026-02-02T07:25:19.686Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Cobalt Strike blockdlls Exploitation Analysis & Detection Methods","Cobalt Strike blockdlls, process security policy, DLL injection prevention, Windows mitigation policy, malware protection, GetProcessMitigationPolicy",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],1155,1154,1153,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.224Z","2026-07-23T16:02:36.083Z","draft","2026-07-23T16:17:03.253Z"]