What specific conditions must be met for a LUA script AppLocker bypass to work?
The bypass requires that Lua for Windows is installed on the system, and that AppLocker rules do not block lua.exe or wlua.exe. Even if scripts are prohibited by AppLocker, if these executables are allowed, scripts can run. This is similar to other bypass techniques like Bypassing Firewalls Using IIS Module Functionality in that it exploits trusted binaries.
LUA bypass conditionsAppLocker ruleslua.exewlua.exe